how2itsec
Pages
(Move to ...)
Home
▼
(Move to ...)
Startseite
▼
Showing posts with label
forensics
.
Show all posts
Showing posts with label
forensics
.
Show all posts
Windows Persistence Map v0.1
›
Mitres Att&ck framework writes about persistence TA0003 : " The adversary is trying to maintain their foothold. " There are m...
AKS Security - SIEM UseCase of Get Credentials
›
A SIEM usecase or forensic security alert for Azure Kubernetes Service AKS should be setup for az aks get-credentials as it reveals sensit...
Mitre Att&ck Micro Emulations - Test your own security
›
It is a very good idea to test your own IT-security systems and processes, if they detect something and what level of detail they provide. M...
Linux persistence techniques as a map
›
Pepe Berba has created a nice overview of linux persistence techniques as a map : https://pberba.github.io/security/2021/11/22/linux-thre...
Splunk PowerShell SIEM use cases from splunk .conf
›
Ryan Kovar and Steve Brant from Splunk released on Splunk .conf 2016 a bunch of useful PowerShell SIEM use cases: https://conf.splunk.com/f...
Real world examples of attack chains with Att&ck mapping
›
Microsoft Threat Protection Intelligence Team released in the past some great detailed articles (e.g. 2020-03 Ransomware , 2018-03 FinFishe...
Windows file or folder in use - cant be deleted or modified
›
When trying to delete files or folders, clean malware, or just modify something on your Windows system, windows won't let you, because t...
OS Credential Dumping - Att&ck T1003
›
Some places to start to monitor (e.g. for unexpected processes interacting with one of the following), collector forensics and try to protec...
Sysmon 11 released
›
Many SIEM installations use sysinternals sysmon as one of many data sources. Mark Russinovich (Microsoft Azure CTO, co-creator of sysintern...
Malware using PowerShell - PowerShell Logging "Script Block Logging"
›
More and more so called "fileless malware" uses powershell in order to execute malicious actions. In order to find possible malici...
›
Home
View web version