Let's Begin

I hope to publish some techniques and methods of detection that have worked for me. These are not original to me necessarily but adopted and adapted from many sources. Some will be broadly focused such as C2 detection and others might be a quick TTP pulled from Twitter. As I have recently switched from using Arcsight to using Splunk I have had to rethink and relearn many things, hopefully you might gain from my pain.

Comments

Popular posts from this blog

Misleading extensions Xls.exe Doc.exe Pdf.exe

Netconn from suspicious directories

Powershell DNS C2 Notes