
Ronald T
@ronaldtran
Senior Security Analyst | Blue Team | Outdoors | Coffee | 🏋️♂️ | Previously @Recon_InfoSec
ID: 16140577
05-09-2008 04:46:47
533 Tweet
159 Followers
1,1K Following


🛡️Windows Firewall and WFP are only two ways to silence an #EDR agent. 📢In my latest blog post I discuss another network based technique to prevent data ingest and ways to detect it. cloudbrothers.info/en/edr-silence… And if you want even more, checkout part 2 released by Mehmet Ergene

[NEW BLOG] EDR Silencer and Beyond: Exploring Methods to Block EDR Communication - Part 2 In collaboration with Fabian Bader academy.bluraven.io/blog/edr-silen… #redteam












🪦 D.E.A.T.H. comes in many forms, and so does thrunting. Check out the latest THOR Collective Dispatch covering three ways to implement these in your org! dispatch.thorcollective.com/p/the-models-o… #threathunting #thrunting #detectionengineering #THORcollective #cybersecurity #DEATH #infosec

Normal is overrated. Hunt the outliers with Z-scores and standard deviation in the new THOR Collective Dispatch post. Read it here: dispatch.thorcollective.com/p/z-scoring-yo… #threathunting #thrunting #detectionengineering #infosec #cybersecurity #splunk #statistics

