Stephan Berger
@malmoeb
Head of Investigations @InfoGuardAG β’ #DFIR β’ Threat Hunting β’ Azure & Active Directory Fanboy β’ OSCP, GXPN, GCIA, GCFA, GSE @malmoeb@infosec.exchange
View on π2
Threads
49
views
14.3K
Followers
1.5K
Tweets
Threads
1/ "They tried to stay stealthy and used the sysinternal's procdump tool, renamed in error.log to bypass Windows Defender detection and dump lsass process memory" [1] A similar t...
Real-World #PingCastle Finding #8: Non-admin users can add computers to a domain. A customer called us because he discovered two new computer objects. Such new computer objects can...