What's the greatest method of improving the signal to noise ratio of detection logic? Prevention
-
Show this thread
-
For example, a week doesn't go by where there isn't a new variation of an LSASS dumping utility. Want to wrap your head around detection of this technique (LSASS Memory - T1003.001)? This prevention guidance from MSFT is
.https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection …1 reply 12 retweets 63 likesShow this thread -
Replying to @mattifestation
Forever hitting it home with great tweets
@mattifestation...1 reply 0 retweets 1 like -
Replying to @DCSecuritydk @mattifestation
yarh- that dont help much when there is fine signed ms driver to dump with. the whql requirement is only if driver gets installed with .infhttps://docs.microsoft.com/en-us/sysinternals/downloads/livekd …
2 replies 0 retweets 4 likes
also doable without a driver :)pic.twitter.com/yUpNj2rmhb
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.