Sysmon, event forwarding, powershell and a dodgy .js file

This is a superb thread!; > "Holy crap, I just traced an infection with Sysmon and the killchain was it trying to launch a .js file with PowerShell, but we remapped .JS to notepad.exe" > Holy crap, I just traced an infection with Sysmon and the killchain was it trying to launch a .js file with PowerShell, but we remapped .JS to notepad.exe — SwiftOnSecurity (@SwiftOnSecurity) January 17, 2018 [https://twitter.com/SwiftOnSecurity/status/953655738639020033?ref_src=twsrc%5Etfw]…

Read More

The Quickstart Guide to WordPress Security

> Let's Encrypt (@letsencrypt) tweeted at 5:34 am on Sat, Oct 14, 2017:Wordpress security guide featuring our own Daniel Jeffrey > Wordpress security guide featuring our own Daniel Jeffrey via @getPantheon [https://twitter.com/getpantheon?ref_src=twsrc%5Etfw]https://t.co/26z66rmnbz — Let's Encrypt (@letsencrypt) October 14, 2017 [https://twitter.com/letsencrypt/status/919058686172991488?ref_src=twsrc%5Etfw]…

Read More

Your attacker thinks like my attacker: A common threat model to create better defense

> The session I did at Ignite with Elia Florio is now online. Learn how attackers think to build better defenses > The session I did at Ignite with Elia Florio is now online. Learn how attackers think to build better defenses: https://t.co/qhqCUpGSYL — Jessica Payne (@jepayneMSFT) October 1, 2017 [https://twitter.com/jepayneMSFT/status/914318763637448704?ref_src=twsrc%5Etfw]…

Read More

Protect Remote Desktop credentials with Windows Defender Remote Credential Guard (Windows 10) | Microsoft Docs

> Introduced in Windows 10, version 1607, Windows Defender Remote Credential Guard helps you protect your credentials over a Remote Desktop connection by redirecting Kerberos requests back to the device that's requesting the connection. It also provides single sign-on experiences for Remote Desktop sessions. Protect Remote Desktop credentials with Windows Defender Remote Credential Guard (Windows 10) - Microsoft 365 SecurityWindows Defender Remote Credential Guard helps to secure your Remote Des…

Read More

Reminder; WMF 5 is out of support - 01/07/17!

> Reminder: Are all of your WMF5 machines running 5.1? 5.0 is out of support as of the 1st of June 2017! #powerShell > Reminder: Are all of your WMF5 machines running 5.1? 5.0 is out of support as of the 1st of june 2017! #powerShell [https://twitter.com/hashtag/powerShell?src=hash&ref_src=twsrc%5Etfw] https://t.co/b16O8y6cNJ — Ben Gelens (@bgelens) August 27, 2017 [https://twitter.com/bgelens/status/901803745318752256?ref_src=twsrc%5Etfw]…

Read More