But they aren't removing the underlying WMI framework, so threat actors will have to use PowerShell to access WMI.
🔗 techcommunity.microsoft.com/blog/windows...
#IncidentResponse #ThreatDetection #ThreatIntel #CSIRT #CERT
But they aren't removing the underlying WMI framework, so threat actors will have to use PowerShell to access WMI.
🔗 techcommunity.microsoft.com/blog/windows...
#IncidentResponse #ThreatDetection #ThreatIntel #CSIRT #CERT
You think they might also let the victim use it for responding to the compromise as well? 😂
news.sophos.com/en-us/2025/0...
#DFIR #IncidentResponse #ThreatDetection #ThreatIntel
You think they might also let the victim use it for responding to the compromise as well? 😂
news.sophos.com/en-us/2025/0...
#DFIR #IncidentResponse #ThreatDetection #ThreatIntel
Datadog's Security Labs identified an abuse of Office 365 Exchange Online service principal (SP) allowing escalation to Global Admin. MSRC considers it "expected misconfiguration" so don't expect a fix.
🔗 securitylabs.datadoghq.com/articles/i-s...
Datadog's Security Labs identified an abuse of Office 365 Exchange Online service principal (SP) allowing escalation to Global Admin. MSRC considers it "expected misconfiguration" so don't expect a fix.
🔗 securitylabs.datadoghq.com/articles/i-s...
🔗 www.darktrace.com/blog/obfusca...
🔗 www.darktrace.com/blog/obfusca...
🔎 Of particular note, this attack is aided with a .LNK file pulling in a .HTA via a remote location.
🔎 Of particular note, this attack is aided with a .LNK file pulling in a .HTA via a remote location.
🔗 cloud.google.com/blog/topics/...
🔗 cloud.google.com/blog/topics/...
Make sure you're #ThreatHunting for new Vulnerable Drivers!
#IncidentResponse #ransomware #ThreatDetection
Make sure you're #ThreatHunting for new Vulnerable Drivers!
#IncidentResponse #ransomware #ThreatDetection
📋 Registration
Thurs, 13 Feb 2025
5:30pm – 6pm
🎤 Presentation
6pm – 7pm
Register Here: https://www.sans.org/mlp/community-night-perth-february-2025/
📍The Pan Pacific Perth Hotel, 207 Adelaide Terrace, Perth WA 6000
📋 Registration
Thurs, 13 Feb 2025
5:30pm – 6pm
🎤 Presentation
6pm – 7pm
Register Here: https://www.sans.org/mlp/community-night-perth-february-2025/
📍The Pan Pacific Perth Hotel, 207 Adelaide Terrace, Perth WA 6000