ottoto · @ottoto2017
70 followers · 1122 posts · Server prattohome.com

「Microsoft Sysmon が実行可能ファイルの作成を検出するようになりました」: BLEEPINGCOMPUTER

「Microsoft は Sysmon 15 をリリースし、保護されたプロセスに変換し、実行可能ファイルの作成時にログを記録する新しい「FileExecutableDetected」オプションを追加しました。 」

bleepingcomputer.com/news/micr

#prattohome #microsoft #windows #sysmon #更新

Last updated 1 year ago

Eric Capuano · @eric_capuano
2479 followers · 727 posts · Server infosec.exchange

Humbled by the overwhelming response to my latest blog series, "So you want to be a SOC analyst?"

I had a lot of fun building this hands-on lab guide to help folks get some practical experience with tools like , , and @limacharlieio EDR.

Part 1 - Set up a small virtualization environment (2 small VMs)
Part 2 - Put on your adversary hat, it's time to make (and observe) some noise
Part 3 - Emulating an adversary for crafting detections

#sliver #sysmon

Last updated 2 years ago

Whitney Champion · @shortstack
5493 followers · 704 posts · Server infosec.exchange

for any other @limacharlieio nerds out there, example D&R rule for deploying sysmon to windows systems 🌈

this assumes you have already uploaded 2 payloads to the org--the sysmon exe and the xml config file

gist.github.com/shortstack/185

#sysmon #sysinternals #limacharlie

Last updated 2 years ago

Security Onion 🧅​ · @securityonion
1154 followers · 73 posts · Server infosec.exchange

Need help getting started with ?

Check out our Youtube video at:
youtube.com/watch?v=Xz-7oDrZdQ

#sysmon

Last updated 2 years ago

Christian Greiner · @cgreiner
8 followers · 41 posts · Server academiccloud.social

Zwar auf der Sysinternals-Webseite noch nicht ersichtlicht, aber hat einige neue Versionen seiner Tools veröffentlich, u.a. , mit dem ich mich gerade täglich beschäftigte.

live.sysinternals.com/

#sysmon #microsoft

Last updated 2 years ago

Johnny :antiverified: · @JohnnyCiocca
186 followers · 13223 posts · Server hachyderm.io

RT @securityonion@twitter.com

ICYMI last week we released 2.3.200!

It's a great way to collect, visualize, and hunt through the logs in your environment!

As always, thanks to @markrussinovich@twitter.com and team for !





twitter.com/securityonion/stat

🐦🔗: twitter.com/securityonion/stat

#securityonion #sysmon #infosec #infosecurity #cybersecurity #threathunting #dfir

Last updated 2 years ago

Antonio Sanz · @antoniosanzalc
284 followers · 280 posts · Server infosec.exchange

Nota mental para mi yo del futuro: cuando estás toqueteando varias versiones de , NO renombres el binario para diferenciar las versiones, pq Windows creará un servicio con el nombre del binario, y luego para desinstalar se/te/nos volveremos todos locos! 🤪

#sysmon

Last updated 2 years ago

Johnny :antiverified: · @JohnnyCiocca
189 followers · 12101 posts · Server hachyderm.io

RT @securityonion@twitter.com

2.3.200 now available including Sysmon Improvements, Dashboard Updates, and Elastic 8.5.3!
blog.securityonion.net/2023/01

Thanks to @markrussinovich@twitter.com and team for !

🐦🔗: twitter.com/securityonion/stat

#securityonion #sysmon

Last updated 2 years ago

Security Onion 🧅​ · @securityonion
1108 followers · 57 posts · Server infosec.exchange

2.3.200 now available including Improvements, Dashboard Updates, and Elastic 8.5.3!

blog.securityonion.net/2023/01

#securityonion #sysmon

Last updated 2 years ago

Abdullah Baghuth · @0xCyberY
8 followers · 7 posts · Server infosec.exchange

We often use Sysmon to log system activity on Windows, but what if we are using Linux?

You can use:
1. SysmonForLinux: github.com/Sysinternals/Sysmon
2. Audiod: linux.die.net/man/8/auditd

Unfortunately, SysmonForLinux is still limited to a few events and they can not log all activities such as DNSEvent (EventID 22).
Let me know what you're using for Linux.

#sysmon #sysmonforlinux #cybersecurity

Last updated 2 years ago

Christian Greiner · @cgreiner
8 followers · 17 posts · Server academiccloud.social

Logging ohne adäquat konfigurierte Datenquellen ist möglich, aber sinnlos!
(Zitat: Loriot ... oder so 😉)

Da ich gerade einige entsprechende Anpassungen an unseren Servern vornehme, hier der Hinweis auf ein extrem nützliches Skript von , um Windows Event Logs so einzurichten, damit oder einfach nur Serverüberwachung wirklich Sinn macht:

github.com/Yamato-Security/Ena

#sysmon #dfir #infosec #threathunting #hayabusa #windows

Last updated 2 years ago

ok , i want to share something for about " " or "" websites how much is good/helpful for you and how you can use them to make your own tools (very fast) but always as you will have your own so you need work hard on these things , i will create article about this but in this post i will show you with very basic steps you can make your own C# or C++ tools for [Remote thread injection Detection] as you can see in "you.com", my search for monitoring event-log [ ] via c# for two EID 8,25 (but you need process creation/network connection event ids too) and our search result have two codes which both have same result, so now with you can detect these event (king of real-time) also you need Memory scanner which my simple search result was something like this pic but i did not test that (for sure, is working or not) i had my own tools and C# codes ;D , ...

note : sometimes these codes in these AI platforms which made by others is better than your own old codes so you can replace them (for example for memory scanner i will test this simple code which seems is better and faster than some of part of my own codes ;D but should test in my LAB for sure..)

and finally you can see my own Blue-teaming "SysPM2Mon2.7.exe" tools (which background of code was something like these steps in these pictures but my memory scanner is "Pe-sieve.exe" + my own C# code for Memory scanner, i had 2 memory scanners in this tool ;D)
so as you can see As and i made my own Blue-teaming tools ( which is available in my github) so you can do same things with your own IDEA , but now with these "Chatgpt" , "YOU.COM" , ... websites you can make them faster and much better...
i will create an article about this but i am working on my things and research about my new ebook also some codes for ebook, so i am very busy to make article now but i will create that ;)

#blueteamers #chatgpt #youdotcom #ai #defensive #developer #bugs #sysmon #realtime #csharp #memoryscanner #pentester #securityresearcher #opensource #blueteam #redteam #pentesting #securityresearch

Last updated 2 years ago

Wes Lambert · @weslambert
452 followers · 60 posts · Server infosec.exchange

What do y'all think about a detection series including and , illustrating the compliments and differences of host and network-based detection and response?









#c2 #securityonion #velociraptor #bruteratel #cobaltstrike #dfir #esm #havoc #infosec #nsm #sliver #sysmon

Last updated 2 years ago

Swissky :verified: · @swissky
845 followers · 161 posts · Server infosec.exchange

RT @malmoeb
If an attacker runs without the parameter "ZipFileName", the default results file is named "<timestamp>_BloodHound.zip". Defenders can use to monitor file creation events to detect potential attackers on the network.

#bloodhound #sysmon

Last updated 2 years ago

Ali Hadi | B!n@ry · @dfir
445 followers · 57 posts · Server infosec.exchange

@dwmetz Yes, I've checked these before and there is currently no such event; haven't been able to see it. The one does exist, but I want to see what else is there, because what if we don't have Sysmon on the endpoint! Thanks Doug!

#sysmon

Last updated 2 years ago

Ali Hadi | B!n@ry · @dfir
408 followers · 44 posts · Server infosec.exchange

I still have not found the answer to this and it would be great use to so many if there is an answer.

What is the Event ID for when a Volume Shadow Copy gets deleted? I know can show you this, but is there anything else?

#sysmon #dfir #digitalforensics #soc #siem #blueteam #malware

Last updated 2 years ago

Ali Hadi | B!n@ry · @dfir
445 followers · 57 posts · Server infosec.exchange

I still have not found the answer to this and it would be great use to so many if there is an answer.

What is the Event ID for when a Volume Shadow Copy gets deleted? I know can show you this, but is there anything else?

#sysmon #dfir #digitalforensics #soc #siem #blueteam #malware

Last updated 2 years ago

Stefan Beyer · @sbeyer
9 followers · 12 posts · Server ioc.exchange

Updated our sysmon-config template to System Monitor (Sysmon) v14.13 and schema v4.82:

github.com/THREATINT/sysmon-co

#sysmon #sysinternals #microsoft

Last updated 2 years ago

Dormidera · @Dormidera
89 followers · 84 posts · Server mastodon.social

SysmonEoP, Proof of Concept for arbitrary file delete/write in Sysmon.

github.com/Wh04m1001/SysmonEoP

#sysmon

Last updated 2 years ago

Antonio Sanz · @antoniosanzalc
242 followers · 159 posts · Server infosec.exchange

A lo mejor no te has enterado, pero hace un par de días salió una PoC para la vulnerabilidad de de escalada de privilegios: github.com/Wh04m1001/SysmonEoP La vulnerabilidad afecta a la capacidad de capturar el portapapeles (aka clipboard) (1/n)

#sysmon

Last updated 2 years ago