- credentials in unattend.xml files purged
- local admin rights for regular users removed
- edr installed on EVERY host
🧵 1/2
- credentials in unattend.xml files purged
- local admin rights for regular users removed
- edr installed on EVERY host
🧵 1/2
Day 69 - Potential Terminal Server or TermService Tampering via RDPWrap
The virus I have caught up to my family yesterday and it was not possible for me to post a query. Hopefully we'll get through it soon.
#MissedStreak
github.com/SecurityAura...
Day 69 - Potential Terminal Server or TermService Tampering via RDPWrap
The virus I have caught up to my family yesterday and it was not possible for me to post a query. Hopefully we'll get through it soon.
#MissedStreak
github.com/SecurityAura...
#CopilotforSecurity #SecurityCopilot #Cybersecurity #MicrosoftSecurity #Security #GenerativeAI
With this, you can run ConvertTo-WDACCodeIntegrityPolicy to get a stripped-down human-readable XML policy.
With this, you can run ConvertTo-WDACCodeIntegrityPolicy to get a stripped-down human-readable XML policy.
Day 45 - Potentially Renamed Binaries
A bit different today where I'm giving you the base KQL recipe to accomplish something and provide an example.
Credit goes to @falconforceteam.bsky.social FalconFriday which helped me get set_has_element() right.
github.com/SecurityAura...
Day 45 - Potentially Renamed Binaries
A bit different today where I'm giving you the base KQL recipe to accomplish something and provide an example.
Credit goes to @falconforceteam.bsky.social FalconFriday which helped me get set_has_element() right.
github.com/SecurityAura...
aitour.microsoft.com/en-US/sessio...
#MSAITour
aitour.microsoft.com/en-US/sessio...
#MSAITour
www.seandeaton.com/gotta-re-em-...
#binaryninja #reverseengineering #ghidra #ida
www.seandeaton.com/gotta-re-em-...
#binaryninja #reverseengineering #ghidra #ida
Was amazing
Was amazing
Wish I had some pictures.
Wish I had some pictures.
Call for Papers (CFP) and Call for Trainings (CFT) are now open! 🎉 Submit your
proposals by January 12, 2025, and keep an eye out for responses in early
February. Head over to bsidesroc.com to submit today!
Call for Papers (CFP) and Call for Trainings (CFT) are now open! 🎉 Submit your
proposals by January 12, 2025, and keep an eye out for responses in early
February. Head over to bsidesroc.com to submit today!
Make sure your detections look at both log files!
Make sure your detections look at both log files!
Parsing additional fields works to bring decent results but, I'm still trying to find value out of it.
Parsing additional fields works to bring decent results but, I'm still trying to find value out of it.
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering #Kusto #KQL #MicrosoftSentinel
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering #Kusto #KQL #MicrosoftSentinel