@cillic Sysmon, 25 event IDs, better visibility vs. traditional Windows Logging. Great blog on Sysmon Logging and EventIds, with the new Event Id 25, Process Tampering, written by @Rev10D https://t.co/KxacayLejN
Red teams / pen testers etc.
What one thing can blue teams do to make your life more difficult? What do you come across and think “Damn, they did that”?
Applied Purple Teaming will be offered only once this year, so unless you plan on waiting until 2022 to join us for APT, you'll want to register ASAP. Registration closes this Wednesday (1/27): https://t.co/vrm96qC9Bm
#infosec#purpleteam#blueteam#redteam#cybersecurity
Sysmon 13 has just been released. I’ve just published a detailed look at the new ProcessTampering feature in a blog.
https://t.co/QtWyBqm2rq
#DFIR#Infosec#Sysmon
💥😱 @tiraniddo added "named pipe RPC client transport" to NtObjectManager 🔥 Thank you very much James for all your work 👏!
I'll create PS scripts to cover a few scenarios 🍻 (Img 4)
If anyone would like to help me, let me know 😉 @OTR_Community
https://t.co/8paKivsLy9