Update 3 out now: https://t.co/yjREfLSDGS
- Event Tracing for Windows - Introduction
- Event Tracing For Windows - ETW Tools
- Event Tracing For Windows - ETW Bypass Via Byte Patching
- Event Tracing for Windows - Better Patching
- Event Tracing for Windows - Patchless ETW Bypass Via HBPs
- Event Tracing For Windows - ETW Provider Session Hijacking
If you collect detailed file share events and have not seen or used this search before, I highly recommend that you run it on Monday morning. Low FP rate and it will find much more than PetitPotam. Ben0xA/Random_Splunk_Detections · GitHub https://t.co/CYQARQddUh
Unable to extract credentials via DPAPI or Mimikatz? Don't worry. Microsoft got your back. Just use 'rundll32 keymgr.dll, KRShowKeyMgr' to extract all the stored passwords on the host, be it a target server, FTP or chrome's HTTP creds, microsoft has you covered. #redteam
a ProcessAccess GrantedAccess value (0x1/PROCESS_TERMINATE ) you may want to add to your sysmon config to detect suspicious process termination of "security/sensitive" processes (correlate sysmon 10 with 5)
https://t.co/9zeqE7dRwL
One thing that continues to add complexity to #log4j discussions is that the external-facing server receiving the exploit attempt is NOT NECESSARILY the server exploited depending on remote logging, etc.
Procdump dump lsass
Defender: Threat detected!
Sqldumper dump lsass
Defender: Sure, go right ahead!
btw dumping lsass with sqldumper.exe is not new, actually its quite old. https://t.co/Q6HCfHeDJX