@techspence How would you do it if a company does not have any app control applications in place right now? List all Hashes of RMM ? But will need to do it every time a new version is available? By name..too easy to rename the tool name ?
I was playing around with the #hayabusa tool @SecurityYamato and spotted you name in it, @cyb3rops ! Awesome tool to provide a fast and thorough investigation option using #Sigma rules, and the option to update the rules is a really nice touch π
@watchtowrcyber@cyb3rops Exploiting through a management interface directly connected on the Internet? Who the hell is leaving a MGMT console on Internet!!
PingCastle now highlights when no policy is in place to prevent scripting files (such as .js) from being executed via double-click.
A simple but effective mitigation is to configure these files to open in Notepad instead. This disrupts many common first-stage infection chains. Red Canary has published a short blog post that walks through setting this up with a small Group Policy Object: https://t.co/WpUIBnXchQ
@cyb3rops Given that initial access often occurs on workstations (e.g., phishing, drive-by), Which asset types should we prioritized for enabling Event ID 4688 with command-line logging, in order of importance (e.g., Tiers,Tiers,Workstation)
@cyb3rops Be sure to enable the setting "Include command line in process creation events" by setting it to "Enabled" to capture full command-line arguments in Event ID 4688
What about 4104 - Powershell ScriptBlockText ?
@JohnHultquist Oh I just red this "These actors rely on social engineering techniques, often impersonating employees or contractors to deceive IT help desks into granting access."
@elonmusk during this time... A moratorium has been voted on wind and solar energy in France.
This means that the French government will temporarily freeze:
New applications to install solar panels or wind turbines;
Authorizations already pending for new projects.