
The Haag™
@m_haggis
Threat Researcher | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer | I'm Everywhere and Nowhere - BSG.
ID: 1511531
http://haggis-m.medium.com 19-03-2007 14:38:45
6,6K Tweet
8,8K Followers
2,2K Following

The Haag™ That is a great write up! IIS modules are one of my “favorite” persistence mechanisms (they can be hard to find for defenders). You mentioned it in your blog post - but for those looking additional reading on IIS modules microsoft.com/en-us/security… & microsoft.com/en-us/security…















LOLdrivers.io now has SIEM queries and a tool section for those looking to operationalize the data. Thanks to Mehmet Ergene and The Haag™ for sharing the queries with the community! Also shout out to Tenable for sharing the Nessus plugin, Oddvar Moe for the


