home.social

#dsc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dsc, aggregated by home.social.

  1. Bielefeld & coach Mitch Kniat are going separate ways as their ideas are no longer congruent.
    Kniat guided #DSC to the DFB-Pokal final in 2025 as a 3. Liga side & promotion to the 2. Bundesliga.
    They stayed up on the final day.
    Really rate Kniat. Next step interesting.

  2. Bielefeld & coach Mitch Kniat are going separate ways as their ideas are no longer congruent.
    Kniat guided #DSC to the DFB-Pokal final in 2025 as a 3. Liga side & promotion to the 2. Bundesliga.
    They stayed up on the final day.
    Really rate Kniat. Next step interesting.

  3. Bielefeld & coach Mitch Kniat are going separate ways as their ideas are no longer congruent.
    Kniat guided #DSC to the DFB-Pokal final in 2025 as a 3. Liga side & promotion to the 2. Bundesliga.
    They stayed up on the final day.
    Really rate Kniat. Next step interesting.

  4. Bielefeld & coach Mitch Kniat are going separate ways as their ideas are no longer congruent.
    Kniat guided #DSC to the DFB-Pokal final in 2025 as a 3. Liga side & promotion to the 2. Bundesliga.
    They stayed up on the final day.
    Really rate Kniat. Next step interesting.

  5. Bielefeld & coach Mitch Kniat are going separate ways as their ideas are no longer on the same wavelength. Kniat guided #DSC to the DFB-Pokal final in 2025 as a 3. Liga side & promotion to the 2. Bundesliga. They stayed up this season on the final day. Really rate Kniat. Next step interesting.

  6. ----------------

    🎯 Threat Intelligence
    ===================

    Executive summary: DSCourier describes a technique that invokes WinGet's configuration engine directly through its COM API to apply Desired State Configuration (DSC) YAML payloads, resulting in arbitrary PowerShell execution inside a Microsoft‑signed process (ConfigurationRemotingServer.exe) without winget.exe, powershell.exe or cmd.exe in the observable process tree.

    Technical details:
    • The technique targets the WinGet configure capability that consumes YAML-based DSC resources.
    • Payloads use PSDscResources/Script to run arbitrary PowerShell logic; execution occurs via the configuration host process rather than a traditional PowerShell executable.
    • The COM API interop layer is used to invoke the configuration engine directly, removing the winget.exe CLI process from the initial execution chain.
    • The author documents YAML construction, an interop wrapper that calls the COM interfaces, and the resulting process tree where the top-level trusted binary is ConfigurationRemotingServer.exe.

    Analysis:
    • Running DSC Script resources inside a Microsoft-signed binary creates a living‑off‑the‑land (LOTL) execution vector that may bypass telemetry focused on common hosts like powershell.exe.
    • Visibility loss occurs at the initiation point: no winget.exe command line is logged when using the COM API approach, reducing forensic artifacts visible in standard process creation logs.
    • The approach preserves signed‑binary provenance while enabling arbitrary code execution, increasing difficulty for EDR heuristic rules that rely on suspicious parent/child relationships or command lines.

    Detection:
    • The original winget configure method is detectable via process command line searches such as:
    process.name: "winget.exe" and process.command_line: (configure or configuration or dsc)
    • For the COM API technique, detection requires monitoring of DSC-related host processes and behavioral indicators inside ConfigurationRemotingServer.exe, such as unexpected DSC resource usage, abnormal network retrieval of YAML content, or scripted activity originating from that process.

    Mitigations / Defensive notes (as presented):
    • Instrumentation should expand visibility beyond common hosts to include signed configuration hosts and inspect invoked DSC resources and YAML content sources.
    • Correlate file retrievals of YAML payloads with subsequent activity in configuration host processes and flag atypical PSDscResources/Script usage in enterprise environments.

    References:
    • The post details YAML payload construction, the COM interop layer, and EDR bypass testing against CrowdStrike Falcon, Microsoft Defender for Endpoint, and Elastic Security. #winget #DSC #EDR

    🔗 Source: dylansec.com/DSCourier/

  7. Wir haben den Tätigkeitsbericht des #DSC veröffentlicht.
    2025 sind über 2.000 Beschwerden bei uns eingegangen. Häufigster Vorwurf waren unzureichende Begründungen bei Account- oder Inhaltsbeschränkungen sowie der Umgang mit Content-Entfernung. bundesnetzagentur.de/1104076

  8. Wir haben den Tätigkeitsbericht des #DSC veröffentlicht.
    2025 sind über 2.000 Beschwerden bei uns eingegangen. Häufigster Vorwurf waren unzureichende Begründungen bei Account- oder Inhaltsbeschränkungen sowie der Umgang mit Content-Entfernung. bundesnetzagentur.de/1104076

  9. Wir haben den Tätigkeitsbericht des #DSC veröffentlicht.
    2025 sind über 2.000 Beschwerden bei uns eingegangen. Häufigster Vorwurf waren unzureichende Begründungen bei Account- oder Inhaltsbeschränkungen sowie der Umgang mit Content-Entfernung. bundesnetzagentur.de/1104076