Tracking WMI Activity with PSGumshoe
WMI (Windows Management Instrumentation) is the Microsoft implementation of the Web-Based Enterprise Management (WBEM) and Common Information Model (CIM) standards from the Distributed Management Task...
View ArticleSysmon for Linux PowerShell Module
Sysmon has been a great tool to enhance logging in Windows for many year allowing well organized teams to cover many gaps in their log and even improve their capabilities at detecting all kinds of...
View ArticleBeyond the Technical - Advise for those starting in Infosec
One question I get on a regular basis is “I want to start a career in infosec where do I start?” and when I ask in what area of infosec one of the most common answer if not the only one is “I want to...
View ArticleOperational Thoughts in Trying Times
This post is as much as a reminder to myself of where I should focus on the multiple jobs I have and also share with the community are large what I consider important and key in this trying times....
View ArticleGetting DNS Client Cached Entries with CIM/WMI
What is DNS CacheThe DNS cache maintains a database of recent DNS resolution in memory. This allows for faster resolution of hosts that have been queried in the recent past. To keep this cache fresh...
View ArticleBeing Grateful at Heilderburg
Recently while in the bar of the Crown Plaza in Heidelberg for the Troopers conference I became aware of the number of how grateful I should be for what I have in this industry. For what I’m grateful...
View ArticleOperating Offensively Against Sysmon
Sysmon is a tool written by Mark Russinovich that I have covered in multiple blog post and even wrote a PowerShell module called Posh-Sysmon to help with the generation of configuration files for it....
View ArticleRebuilding My Playbook .. Knowledge Base
I find myself in the situation where I lost my personal playbook by user error. I accidentally deleted the VM where I ran xWiki where it was kept and did not realized the mistake until days later. Even...
View ArticleOperational Look at Sysinternals Sysmon 6.20 Update
Sysmon has been a game changer for many organizations allowing their teams to fine tune their detection of malicious activity when combined with tools that aggregate and correlate events. A new...
View ArticleSome Comments and Thoughts on Tradecraft
I have been writing a series on the new Windows Defender Exploit Guard features on Attack Surface Reduction where I cover my research on it. I'm researching the controls to add the information in to my...
View ArticleWindows Defender Exploit Guard ASR Rules for Office
On this blog post I continue looking at the ASR rules, this time I'm looking at the ASR rules for Office. The ASR rules for office are:Block Office applications from creating child processesBlock...
View ArticleWindows Defender Exploit Guard ASR Obfuscated Script Rule
On this blog post I will cover my testing of the Attack Surface Reduction rule for Potentially Obfuscated Scripts. This is one of the features that intrigued me the most. One obfuscates the scripts for...
View ArticleWindows Defender Exploit Guard ASR VBScript/JS Rule
Microsoft has been adding to Windows 10 the features of the Enhanced Mitigation Experience Toolkit (EMET) in to the OS. On the 1709 release they added more features and expanded on them as part of...
View ArticleSwitching Ruby Version in RVM for Metasploit Development
If you have setup a development environment with RVM to do development in Metasploit Framework you are bound to encounter that the Metasploit team has changed preferred Ruby...
View ArticleBasics of The Metasploit Framework API - IRB Setup
Those of you who have taken my "Automating Metasploit Framework" class all this material should not be new. I have decided to start making a large portion of the class available here in the blog as a...
View ArticleUpdate to Pentest Metasploit Plugin
I recently update my Metasploit Pentest Plugin . I added 2 new commands to the plugin and fixed issues when printing information as a table. The update are small ones.Lets take a look at the changes...
View ArticleSysinternals Sysmon 6.10 Tracking of Permanent WMI Events
In my previous blog post I covered how Microsoft has enhanced WMI logging in the latest versions of their client and server operating systems. WMI Permanent event logging was also added in version 6.10...
View ArticleBasics of Tracking WMI Activity
WMI (Windows Management Instrumentation) has been part of the Windows Operating System since since Windows 2000 when it was included in the OS. The technology has been of great value to system...
View ArticleWanaCry Shows a Operational and Human Problem
This last couple of day the headline has been the WannaCry ransomeware worm. I have seen many discussion about the technical aspects of it, about the disclosure of the vulnerability and debates of who...
View ArticleHow Much Your Org Reaction to a Tweet Says?
Recently Tavis Ormandy a well known vulnerability researcher from Google made a tweet about a vulnerability he and researcher Natalie Silvanovich from Google Project Zero found on the Windows OS that...
View Article