@cyb3rops You can find some Log line from a fortigate in a reddit post. I'm not 100% sure about this IoC ... seems to be an IoC for a logon?! https://t.co/53SnAAGph7
@cyb3rops@malmoeb@TheDFIRReport I need your help for my master thesis. I currently looking for resources on detection opportunities besides the windows event log on windows. Any Hints/Papers/Projects (something like @OSSEM_Project would be awesome).
@0sm0s1z I think a future vuln scanner should enable users to measure or guide the effectiveness. The new EPSS model might be worth reading: https://t.co/yzsl6rvjLD
I would like to define my risk acceptance and have EPSS to guide my patch efforts on found vulnerabilities.
15 members of REvil has been arrested by the Russian authorities.
REvil, once dubbed the "Crown prince of Ransomware", was responsible for the Kaseya supply chain attack, and many other high-profile breaches.
Footage courtesy of the FSB.
@cyb3rops@certbund@CERT_at how do you size your windows client event log files?
Would you agree with the (old) microsoft calculation? https://t.co/j67zVL7Arr
@GossiTheDog LPE and lateral movement on beachhead hosts; for sure.
Is a standard user able to authenticate against a domain controllers RPC Print Spooler Service?