home.social

#sysmon — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sysmon, aggregated by home.social.

fetched live
  1. Ваш парсер .evtx молча прочитал 4% журнала — и не считает это ошибкой

    Скрипт на python-evtx отработал без единой ошибки, с кодом возврата 0, и вернул 94 записи. В файле их было 2309, и вся атака — от создания админской учётки до запуска шифровальщика — оказалась в потерянных 96%. Разбираемся, почему два байта в заголовке .evtx нельзя принимать на веру и почему проверка непрерывности EventRecordID в этом случае отвечает «пропусков нет».

    habr.com/ru/articles/1063518/

    #evtx #dfir #форензика #windows_event_log #pythonevtx #sysmon #расследование_инцидентов #парсинг_логов #целостность_данных #chainsaw

  2. CVE-2026-3502 в TrueConf: как доверенный механизм обновлений превратился в вектор атаки

    Хабр, привет! На связи Алина Байрамова, аналитик-исследователь угроз кибербезопасности R-Vision. В этой статье я разберу уязвимость нулевого дня в TrueConf Server (CVE-2026-3502), связанную с механизмом обновлений, и то, как она может быть использована для компрометации изолированных инфраструктур через доверенный канал распространения ПО.

    habr.com/ru/companies/rvision/

    #изолированные_сети #уязвимости #trueconf #supply_chain_attack #soc #threat_hunting #sysmon #исследование_угроз #CVE20263502 #tampering

  3. BYOVD-атаки на ядро Windows через драйверы: разбираю механику, воспроизвожу, строю защиту

    Вы настроили Sysmon, у вас работает EDR, события летят в SIEM. Создаётся процесс, вы видите Event ID 1. Загружается DLL, Event ID 7. Всё под контролем. А теперь кто-то загружает в систему один .sys-файл. Обычный, подписанный, из прошлого века. И события пропадают. Не потому что Sysmon упал или EDR отключили. Они работают. Просто ядро Windows больше не считает нужным им что-то рассказывать. Я залез внутрь, чтобы понять, как это устроено. Поднял WinDbg, подключился к ядру, нашёл структуры, где хранятся callback'и мониторинга. Обнулил их, повторив технику руткита Lazarus. Sysmon на месте, PID живой, но лог пустой. Меня зовут Роман Мгоев, я специалист по анализу киберугроз в Альфа-Банке, в статье пройду этот путь целиком: начиная с архитектуры колец защиты Windows, byte-патчей в памяти ядра и разбора FudModule от Lazarus обеих версий, до свежих техник zerosalarium и разбора публичных тулкитов, а в конце поделюсь семью направлениями детектирования с готовыми правилами для SIEM. Отдельный блок — про аудит драйверов, которых ещё нет ни в одной базе.

    habr.com/ru/companies/alfa/art

    #BYOVD #EDR #Windows_kernel #Sysmon #SIEM #Lazarus #ransomware #reverse_engineering #SOC #detection_engineering

  4. Oh holy hell. This just shows that Microsoft need to clean up its act and get rid of such functionality to FIRMLY stand on the side of defenders. What the fuck were they thinking when they added support for custom registry hives? #registry #evasion #sysmon #edr
    deceptiq.com/blog/ntuser-man-r

  5. Oh holy hell. This just shows that Microsoft need to clean up its act and get rid of such functionality to FIRMLY stand on the side of defenders. What the fuck were they thinking when they added support for custom registry hives? #registry #evasion #sysmon #edr
    deceptiq.com/blog/ntuser-man-r

  6. RE: infosec.exchange/@suricata/115

    Suricata events enriched with #sysmon process info = #Pikksilm. Based on experiences from the #LockedShields cyber battlefield. Definitely recommended to see that tool and presentation.

    Also talk about #ICS , #modbus and datasets by @reverseics brings good ideas and examples of #suricata rules.

  7. RE: infosec.exchange/@suricata/115

    Suricata events enriched with #sysmon process info = #Pikksilm. Based on experiences from the #LockedShields cyber battlefield. Definitely recommended to see that tool and presentation.

    Also talk about #ICS , #modbus and datasets by @reverseics brings good ideas and examples of #suricata rules.

  8. Microsoft is bringing Sysmon natively into Windows 11 & Windows Server 2025 - installable via Optional Features and updated through Windows Update.

    Custom configs, advanced filtering, and the familiar event set (proc creation, file creation, tampering, WMI, network activity) all remain.

    Docs + new enterprise management features are coming next year.

    What’s your take on native Sysmon for enterprise visibility?

    #Sysmon #infosec #windows11 #microsoftsecurity #blueteam #cybersecurity #threathunting #endpointsecurity

  9. #Microsoft wird das #Admin-#Tool #Sysmon ab 2026 fest in #Windows11 integrieren. Der System-#Monitor soll dann offiziellen Support erhalten und einfach über die Windows-Funktionsverwaltung aktivierbar sein. winfuture.de/news,155054.html?

  10. #Microsoft wird das #Admin-#Tool #Sysmon ab 2026 fest in #Windows11 integrieren. Der System-#Monitor soll dann offiziellen Support erhalten und einfach über die Windows-Funktionsverwaltung aktivierbar sein. winfuture.de/news,155054.html?

  11. I'm not sure how accurate this is, but The Verge is reporting that #SysMon will be integrated into Windows 11 early next year.

    This will be a massive win for #DFIR and #SecOps people everywhere if it's correct.

    theverge.com/news/821948/micro

  12. I'm not sure how accurate this is, but The Verge is reporting that #SysMon will be integrated into Windows 11 early next year.

    This will be a massive win for #DFIR and #SecOps people everywhere if it's correct.

    theverge.com/news/821948/micro

  13. When a breach occurs, it’s too late to wish you’d configured your logs...

    Incident responders can only work with what’s there. Our latest blog post, written by Nicole, breaks down which logs provide the best chance of understanding what really happened and how to configure them before you need them, so you can get back to business as usual swiftly.

    📌Read here: pentestpartners.com/security-b

    #cybersecurity #incidentresponse #digitalforensics #sysmon #windowssecurity #infosec

  14. When a breach occurs, it’s too late to wish you’d configured your logs...

    Incident responders can only work with what’s there. Our latest blog post, written by Nicole, breaks down which logs provide the best chance of understanding what really happened and how to configure them before you need them, so you can get back to business as usual swiftly.

    📌Read here: pentestpartners.com/security-b

    #cybersecurity #incidentresponse #digitalforensics #sysmon #windowssecurity #infosec

  15. RID Hijacking

    Всем привет! Сегодня мы рассмотрим один из способов пост-эксплуатации Rid hijacking и посмотрим его артефакты.

    habr.com/ru/articles/931990/

    #RID_Hijacking #безопасность #windows #sysmon #event_viewer #poc #артефакты #blue_team #cybersecurity #rid

  16. Три слона, на которых держится логирование в Windows

    Продолжаем наш цикл статей о типах и методах работы сборщиков данных с конечных точек, или, как принято их называть – агентов. В первой статье мы познакомились с этой сущностью и изучили основные нюансы сбора данных с их помощью. Так как мы в рамках разработки своих продуктов занимаемся и лог-менеджментом, и сбором событий, то хочется поделиться продолжением нашей обширной аналитики в quickstart формате. Поэтому в этом выпуске подробнее разберем функционал и используемые инструменты источников на ОС Windows.

    habr.com/ru/companies/security

    #Логирование #сбор_событий #eventlog #журналы_windows #журналы_событий #sysmon #event_tracing_for_windows #event_logging #event_log #etw

  17. Использование портативного клиента Telegram, так ли незаметно?

    Приветствую, Хабр! Мессенджеры являются незаменимым инструментом для общения в корпоративной среде, поскольку это быстро и удобно. Зачастую во многих компаниях сотрудники взаимодействуют не через корпоративные, а через общедоступные мессенджеры. Это увеличивает риски утечки информации , так как влечет за собой преднамеренное или непреднамеренное разглашение данных. В качестве меры предотвращения такой утечки компании, как правило, используют DLP системы (Data Loss Prevention) и другие способы мониторинга переписки. Одним из самых популярных мессенджеров, используемых в России и СНГ, является Telegram . Как показывает практика компаний, работающих с DLP, алгоритм определения клиента Telegram в системе несовершенен и обойти механизмы контроля, используя портативную версию, достаточно просто. Оценивая стоимость внедрения механизмов контроля и простоту их обхода, давайте попробуем ответить на вопрос: "По каким признакам можно понять, что используется Portable клиент Telegram?". Для анализа мы возьмем штатные средства мониторинга системы, а также журналы Sysmon . События журналов будем рассматривать в R-Vision SIEM, так как продукт позволяет обрабатывать все события в одном месте с удобными фильтрами и высокой производительностью.

    habr.com/ru/companies/rvision/

    #Telegram #portable #конфиденциальность #siem #sysmon #wineventlog #dlpсистемы #desktop

  18. If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from @kostastsale that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging.

    #DFIR #LinuxForensics #SIEM #CSIRT

    kostas-ts.medium.com/telemetry

  19. If you're interested in getting into #Linux #logging and evidence collection, this is an excellent write-up from @kostastsale that compares #EVTX logs on Windows with #Auditd, #SysMon for Linux, and native Linux logging.

    #DFIR #LinuxForensics #SIEM #CSIRT

    kostas-ts.medium.com/telemetry

  20. Given Sysmon is as configurable as a Baulders Gate 3 character, what config do you prefer for homelab use? I've been using the sysmon-modular repo but have also used SwitfOnSecurity's before that.

    I've been wondering if I'm gathering enough telemetry when running atomic tests.

    medium.com/@swathitadepalli/im

    #Sysmon #Bluteam

  21. Given Sysmon is as configurable as a Baulders Gate 3 character, what config do you prefer for homelab use? I've been using the sysmon-modular repo but have also used SwitfOnSecurity's before that.

    I've been wondering if I'm gathering enough telemetry when running atomic tests.

    medium.com/@swathitadepalli/im

    #Sysmon #Bluteam

  22. Today is the third day of @passthesaltcon. I'm learning about @kunai_project :

    cfp.pass-the-salt.org/pts2024/

    It's a alternative for targeted at , however I plant to use it to debug syslog-ng :-)

  23. Today is the third day of @passthesaltcon. I'm learning about @kunai_project :

    cfp.pass-the-salt.org/pts2024/

    It's a #sysmon alternative for #Linux targeted at #infosec, however I plant to use it to debug syslog-ng :-)

  24. Listening to Quentin JEROME at @passthesaltcon talking about:

    Kunai Updates

    cfp.pass-the-salt.org/pts2024/

    Kunai is a alternative for

  25. Today I made the lights behind my monitor turn brighter automatically, when an app on my PC is accessing the webcam.

    Windows shows you in the settings app which app is currently accessing your webcam, and it turns out you can read those values from the registry.

    Using Sysmon I can watch for changes in the registry that indicate that an app's started / stopped accessing my webcam and fire Events into the Windows eventlog, and then I attached a Task to those events that forwards the new registry key to #HomeAssistant through a webhook.

    Depending on the value sent, HomeAssistant can then turn my lights bright to act as a key light, or reactivate the adaptive lighting that continuously adjusts the light's color based on the time of day :3

    #Windows #Sysmon #Powershell

    Edit: part 1.5 is here, the threading broke: corteximplant.com/@Sirs0ri/110

  26. Today I made the lights behind my monitor turn brighter automatically, when an app on my PC is accessing the webcam.

    Windows shows you in the settings app which app is currently accessing your webcam, and it turns out you can read those values from the registry.

    Using Sysmon I can watch for changes in the registry that indicate that an app's started / stopped accessing my webcam and fire Events into the Windows eventlog, and then I attached a Task to those events that forwards the new registry key to #HomeAssistant through a webhook.

    Depending on the value sent, HomeAssistant can then turn my lights bright to act as a key light, or reactivate the adaptive lighting that continuously adjusts the light's color based on the time of day :3

    #Windows #Sysmon #Powershell

    Edit: part 1.5 is here, the threading broke: corteximplant.com/@Sirs0ri/110

  27. New updates to #SysMon and #Autoruns from Sysinternals are available.
    If you're using Autoruns for #DFIR persistence discovery, make sure you switch to this update as it fixes a bug for non-shortcut files in startup folders aren't.

    #CSIRT #TheatHunting #ThreatDetection

    techcommunity.microsoft.com/t5

  28. New updates to #SysMon and #Autoruns from Sysinternals are available.
    If you're using Autoruns for #DFIR persistence discovery, make sure you switch to this update as it fixes a bug for non-shortcut files in startup folders aren't.

    #CSIRT #TheatHunting #ThreatDetection

    techcommunity.microsoft.com/t5