MENASecurity
@menasec1
Applied Security Research | Threat Hunting | DFIR | [email protected] 👁🗨
ID: 1102255788251324417
https://blog.menasec.net 03-03-2019 17:13:53
81 Tweet
2,2K Takipçi
40 Takip Edilen
📌How to Design Abnormal Child Processes Rules without Telemetry by MENASecurity [BLOG]➡️ blog.menasec.net/2021/01/how-to… #ThreatHunting #BlueTeam #security #DFIR
Integrating process protection level information into all #EDR #Sysmon events. As suggested by MENASecurity in blog.menasec.net/2022/04/auditi… using Win API instead of checking RunAsPPL registry key (which seem to apply only to lsass) #dfir #threathunting github.com/0xrawsec/whids
Just pushed the code to embed process protection level in severa events of our #opensource #EDR #dfir #threathunting github.com/0xrawsec/whids thanks to MENASecurity for the idea