Holy crap, I just traced an infection with Sysmon and the killchain was it trying to launch a .js file with PowerShell, but we remapped .JS to notepad.exe
-
Show this thread
-
I detected the beginning of the infection with centralized PowerShell logging that puts the transcripts in a fileshare. I go through it time to time seeing what our systems are doing.
4 replies 23 retweets 175 likesShow this thread -
A REAL-LIFE threat against a user, traced from inception with Sysmon (free), detected with PowerShell logging with Win7 WMF5 upgrade (free), ultimately defeated with simple defense-in-depth computer configuration in Group Policy (free).
@markrussinovich@jsnover@Lee_Holmespic.twitter.com/8yGOoPx8HB
20 replies 416 retweets 1,120 likesShow this thread
This is Kovter, fileless malware - nice catch! Great read also by @kafeine on the gang behind it:https://www.proofpoint.com/us/threat-insight/post/kovter-group-malvertising-campaign-exposes-millions-potential-malware-and-fraud …
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.