Paul Masek
Paul Masek
"a PowerShell Module for Threat Hunting via Windows Event Logs" https://github.com/sans-blue-team/DeepBlueCLI
Fast Windows File Search: https://www.voidtools.com/
Regarding "z-AlphaVersion.xml": It appears that Event IDs that have both Include and Exclude filter sets are only processing one or the other filter set. For example when I run sysmon...
For this challenge: > You're getting good at this! Looks like you need more of a challenge...maybe instead of putting a name in a box, the name should be the...
I may have stumbled across a bug. Finally figured out how to use the HUD and started planning my descent soon after I crossed 1 Million feet height. Was over...