Rezultati pretraživanja
  1. 5. velj

    Some very cool updates coming in a future release of

  2. 2. velj
  3. 2. velj
  4. 30. sij

    We will again be running a purple team workshop at the next OWASP Aarhus chapter event. Tools featured from my side: , , , plus and plus a short piece on Sigma rules!

  5. 30. sij
    Prikaži ovu nit
  6. 27. sij

    What issues do people have with a rollout in an enterprise? Log volume? I’ve seen orgs worried about 20GB of daily Sysmon log data, while at the same time spending a 6 figure sum on a license to process 500GB of daily firewall log data. (which is mostly useless)

  7. 14. sij
  8. 21. pro 2019.

    Updated the Sysmon Visual Studio Code extension to support the new 4.23 schema with exclude all and exclude any conditions

  9. 21. lis 2019.

    Last month has been me going deep in to Sysmon, to help write configs I wrote a VSCode extension for Sysmon Config files

  10. 30. ruj 2019.

    Do you miss output in your reports - e.g. to write rules Try my PoC wrapper "ExoTron" - wraps samples - activates logging - installs Sysmon - exports Eventlog entries (downloadable in dropped files)

  11. 24. ruj 2019.

    October 7th 1PM will be doing a live on leveraging for enhanced . Reserve your seat today.

  12. 23. ruj 2019.

    With 10.4x being stable now, I'd love to enable everyone to utilize it's great new features. I've merged my 10.4 branch to the master branch, making it the default one I'll be maintaining;

  13. 6. ruj 2019.

    10.4 TLDR: This version adds new filter options "contains any" & "contains all" & most significantly, the option to add sub-rules to a rule group allowing you to make multiple AND/OR statement. Read the rest in ⁦⁩’s feature brief.

  14. 6. ruj 2019.

    Sysmon 10.4 has been released by this is a fantastic upgrade, go check it out! I wrote a small blog outlining the added features,

  15. 28. srp 2019.

    just pushed a good update to panache_sysmon config, now events config are separated by event type and also ImageLoad rule names updated (covers now 48 DLL Side Loads plus other important stuff)

  16. 6. srp 2019.

    Sysmon Internals slides of talk at are now online!   

  17. 29. lip 2019.

    + Packet Capture + the new Sysmon Box utility

  18. 27. lip 2019.

    Great post from with explanation about using and configuring to detect various activities. Also love the fact that he is linking to the LOLBAS-project🔥

  19. 26. lip 2019.

    put together an excellent piece on . Examples and screenshots included. Check it out.

  20. 19. lip 2019.

    Added PCAP/NG import feature to View: - Currently Only TCP/UDP are imported - Every network event is mapped to an extracted matching conversation, Wireshark can be used then to follow stream or investigate payload 🙂 - Wireshark + tshark are needed

    Prikaži ovu nit

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.