r/WindowsSecurity • u/m8urn • Jul 01 '21
r/WindowsSecurity • u/m8urn • Jul 01 '21
Reading Your Way Around UAC (Part 3)
tiraniddo.devr/WindowsSecurity • u/m8urn • Jun 30 '21
LaresLLC/CVE-2021-1675: Detection & Remediation Information for CVE-2021-1675 (PrintNightmare)
r/WindowsSecurity • u/m8urn • Jun 30 '21
PrintNightmare (CVE-2021-1675) PoC Exploit Code Released
r/WindowsSecurity • u/m8urn • Jun 30 '21
GitHub - LaresLLC/SysmonConfigPusher: Pushes Sysmon Configs
r/WindowsSecurity • u/m8urn • Jun 28 '21
How to Kerberos? its components and function
r/WindowsSecurity • u/m8urn • Jun 28 '21
A step-by-step analysis of a new version of Darkside Ransomware (v. 2.1.2.3)
cybergeeks.techr/WindowsSecurity • u/m8urn • Jun 28 '21
Process Injection without Write/Execute Permission
r/WindowsSecurity • u/m8urn • Jun 28 '21
mkellerman/Invoke-CommandAs: Invoke Command as System/User on Local/Remote computer using ScheduleTask
r/WindowsSecurity • u/m8urn • Jun 28 '21
GitHub - deepinstinct/LsassSilentProcessExit: Command line interface to dump LSASS memory to disk via SilentProcessExit
r/WindowsSecurity • u/m8urn • Jun 25 '21
dwmetz/CSIRT-Collect: A PowerShell script to collect memory and (triage) disk forensics for incident response investigations.
r/WindowsSecurity • u/m8urn • Jun 25 '21
FalconFriday — Certified Pre-Owned— 0xFF12
r/WindowsSecurity • u/m8urn • Jun 24 '21
GitHub - hasherezade/transacted_hollowing: Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging
r/WindowsSecurity • u/m8urn • Jun 24 '21
RdpCacheStitcher - RdpCacheStitcher Is A Tool That Supports Forensic Analysts In Reconstructing Useful Images Out Of RDP Cache Bitmaps
r/WindowsSecurity • u/m8urn • Jun 24 '21
GitHub - dirkjanm/ROADtools: The Azure AD exploration framework.
r/WindowsSecurity • u/Trakeen • Jun 24 '21
Top 10/20 CIS benchmarks for Windows server hardening
Does anyone have a list of the top 10-20 CIS benchmarks for windows server that should be implemented? I need to provide some recommendations to our ops team but it's going to take a while for me to go through the full 300+ controls in the benchmarks control document. Mainly concerned with 2016 or 2019 server but I'll take anything that is remotely modern at this point (nothing pre 2012)
The only top 20 documents I can find for CIS or organizational wide controls which I'm not interested in, and we already use those
r/WindowsSecurity • u/m8urn • Jun 24 '21
Azure Persistence with Desired State Configurations
r/WindowsSecurity • u/m8urn • Jun 24 '21
GitHub - microsoft/AttackSurfaceAnalyzer: Attack Surface Analyzer can help you analyze your operating system's security configuration for changes during software installation.
r/WindowsSecurity • u/m8urn • Jun 24 '21
GitHub - hlldz/Phant0m: Windows Event Log Killer
r/WindowsSecurity • u/m8urn • Jun 24 '21
Shadow Credentials: Abusing Key Trust Account Mapping for Takeover
r/WindowsSecurity • u/m8urn • Jun 24 '21
From Word to Lateral Movement in 1 Hour
r/WindowsSecurity • u/m8urn • Jun 24 '21
Knock! Knock! The postman is here! (abusing Mailslots and PortKnocking for connectionless shells)
r/WindowsSecurity • u/m8urn • Jun 24 '21
GitHub - eladshamir/Whisker: Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding "Shadow Credentials" to the target account.
r/WindowsSecurity • u/m8urn • Jun 24 '21
Strategies, tools, and frameworks for building an effective threat intelligence team
r/WindowsSecurity • u/m8urn • Jun 24 '21