https://jordanpotti.com/2017/01/20/basics-of-windows-incident-response/
A place to share links and articles that i have found helpful. This blog tends to be more offensive security minded. Basically it is a collection of notes that I will update periodically. None of this is set in stone, and I could very well be wrong on most of it. Just saying.
Showing posts with label detect. Show all posts
Showing posts with label detect. Show all posts
Quick Integration of MISP and Cuckoo
https://blog.rootshell.be/2017/01/25/quick-integration-misp-cuckoo/
Detecting Kerberoasting Activity Part 2
Creating a Kerberoast Service Account Honeypot https://adsecurity.org/?p=3513
Subscribe to:
Posts (Atom)