Showing posts with label detect. Show all posts
Showing posts with label detect. Show all posts

Basics of Windows Incident Response

https://jordanpotti.com/2017/01/20/basics-of-windows-incident-response/

Quick Integration of MISP and Cuckoo

https://blog.rootshell.be/2017/01/25/quick-integration-misp-cuckoo/

Detecting Kerberoasting Activity Part 2

Creating a Kerberoast Service Account Honeypot https://adsecurity.org/?p=3513

Detecting Kerberoasting Activity

https://adsecurity.org/?p=3458