Full analysis: open.substack.com/pub/manishra...
#Cybersecurity #Cyberattack #Substack #ThreatHunting #DetectionEngineering #SOC #BlueTeam
Full analysis: open.substack.com/pub/manishra...
#Cybersecurity #Cyberattack #Substack #ThreatHunting #DetectionEngineering #SOC #BlueTeam
I spent an hour investigating a lsass process in the APT29 dataset this week.
1,605 events. 14 EventIDs. Every search I ran came back clean.
Full Post is on LinkedIn: www.linkedin.com/posts/manish...
#Cybersecurity #Analysis #Splunk #Research #APT #SecurityAnalyst #SOC
I spent an hour investigating a lsass process in the APT29 dataset this week.
1,605 events. 14 EventIDs. Every search I ran came back clean.
Full Post is on LinkedIn: www.linkedin.com/posts/manish...
#Cybersecurity #Analysis #Splunk #Research #APT #SecurityAnalyst #SOC
I implemented custom logging into a text file for when the api is launched NOT in docker ( ꈍᴗꈍ) file path is specified in appsettings.json btw
#dotnet #devlog #buildinpublic #devops #aspnet
📌Intune Client-Side Troubleshooting for Windows: Event IDs IME Logs and Diagnostic Insights - www.anoopcnair.com/intune-clien...
#Intune #WindowsTroubleshooting #EventIDs #IMELogs #Diagnostics #MicrosoftIntune #HTMDCommunity
📌Intune Client-Side Troubleshooting for Windows: Event IDs IME Logs and Diagnostic Insights - www.anoopcnair.com/intune-clien...
#Intune #WindowsTroubleshooting #EventIDs #IMELogs #Diagnostics #MicrosoftIntune #HTMDCommunity
* Entities how have a full causal history (coming soon: cross-event causality, bloom-filtered skip-links, remediation of complex concurrencies)
* EventIds are now content-based hashes
* Each "system" now has a well defined causal root event, and metadata across restarts
* Entities how have a full causal history (coming soon: cross-event causality, bloom-filtered skip-links, remediation of complex concurrencies)
* EventIds are now content-based hashes
* Each "system" now has a well defined causal root event, and metadata across restarts