Skip Navigation
m8urn m8urn @infosec.pub

Infosec SME and writer.

Posts 8
Comments 0

How to manage the Kerberos protocol changes related to CVE-2022-37966

0

Sysinternals updates: Sysmon v15.0, Autoruns v14.1, and Process Monitor v3.95

techcommunity.microsoft.com Sysmon v15.0, Autoruns v14.1, and Process Monitor v3.95

Sysmon v15.0 This update to Sysmon, an advanced host security monitoring tool, sets the service to run as a protected process, hardening it against tampering, adds a new event, FileExecutableDetected, for when new executable images are saved to files, and fixes a system hang occurring in certain sit...

Sysmon v15.0, Autoruns v14.1, and Process Monitor v3.95
0
github.com GitHub - CMEPW/BypassAV: This map lists the essential techniques to bypass anti-virus and EDR

This map lists the essential techniques to bypass anti-virus and EDR - GitHub - CMEPW/BypassAV: This map lists the essential techniques to bypass anti-virus and EDR

GitHub - CMEPW/BypassAV: This map lists the essential techniques to bypass anti-virus and EDR
0
github.com GitHub - LaresLLC/SysmonConfigPusher: Pushes Sysmon Configs

Pushes Sysmon Configs. Contribute to LaresLLC/SysmonConfigPusher development by creating an account on GitHub.

GitHub - LaresLLC/SysmonConfigPusher: Pushes Sysmon Configs
0
techcommunity.microsoft.com Latest Windows hardening guidance and key dates

Hardening is a key element of our ongoing security strategy to help keep your estate protected while you focus on your job. Increasingly creative cyberthreats target weaknesses anywhere possible, from the chip to the cloud. Have you seen our publications on hardening on the Windows message center? S...

Latest Windows hardening guidance and key dates
0

Alternative Ways to Detect Mimikatz by Balazs Bucsay

0
github.com GitHub - Kudaes/EPI: Process injection through entry points hijacking.

Process injection through entry points hijacking. Contribute to Kudaes/EPI development by creating an account on GitHub.

GitHub - Kudaes/EPI: Process injection through entry points hijacking.
0

SMB signing and guest authentication becoming default settings

techcommunity.microsoft.com SMB Signing and Guest Authentication

Heya folks, Ned here again. We recently made SMB signing the default in Windows Insider Enterprise client builds. In doing so, we were quickly reminded of a consequence from an old unsafe SMB behavior that some folks still use: guest authentication. Today I'll explain all this and give you the steps...

SMB Signing and Guest Authentication
0