Sysmon, event forwarding, powershell and a dodgy .js file

This is a superb thread!; > "Holy crap, I just traced an infection with Sysmon and the killchain was it trying to launch a .js file with PowerShell, but we remapped .JS to notepad.exe" > Holy crap, I just traced an infection with Sysmon and the killchain was it trying to launch a .js file with PowerShell, but we remapped .JS to notepad.exe — SwiftOnSecurity (@SwiftOnSecurity) January 17, 2018 [https://twitter.com/SwiftOnSecurity/status/953655738639020033?ref_src=twsrc%5Etfw]…

Read More

The Quickstart Guide to WordPress Security

> Let's Encrypt (@letsencrypt) tweeted at 5:34 am on Sat, Oct 14, 2017:Wordpress security guide featuring our own Daniel Jeffrey > Wordpress security guide featuring our own Daniel Jeffrey via @getPantheon [https://twitter.com/getpantheon?ref_src=twsrc%5Etfw]https://t.co/26z66rmnbz — Let's Encrypt (@letsencrypt) October 14, 2017 [https://twitter.com/letsencrypt/status/919058686172991488?ref_src=twsrc%5Etfw]…

Read More

Tweet from SmartDeploy (@SmartDeploy)

> If you manage #Windows computers, join us in an hour for a full imaging product comparison hosted by @Thurrottfeed > If you manage #Windows [https://twitter.com/hashtag/Windows?src=hash&ref_src=twsrc%5Etfw] computers, join us in an hour for a full imaging product comparison hosted by @Thurrottfeed [https://twitter.com/Thurrottfeed?ref_src=twsrc%5Etfw] - https://t.co/WTqwaih5U6 pic.twitter.com/9wnXGICGIf [https://t.co/9wnXGICGIf] — SmartDeploy (@SmartDeploy) October 3, 2017 [https://twitter.…

Read More