blog category

Research & Tradecraft

image for Hunting With Active Directory Replication Metadata

Research & Tradecraft

Hunting With Active Directory Replication Metadata

Sep 6, 2017 • 15 min read
Read Post
image for Randomized Malleable C2 Profiles Made Easy

Research & Tradecraft

Randomized Malleable C2 Profiles Made Easy

Aug 29, 2017 • 6 min read
Read Post
image for UMCI vs Internet Explorer: Exploring CVE-2017–8625

Research & Tradecraft

UMCI vs Internet Explorer: Exploring CVE-2017–8625

Aug 24, 2017 • 3 min read
Read Post
image for The PowerView PowerUsage Series #2

Research & Tradecraft

The PowerView PowerUsage Series #2

Aug 16, 2017 • 2 min read
Read Post
image for Attack Infrastructure Log Aggregation and Monitoring

Research & Tradecraft

Attack Infrastructure Log Aggregation and Monitoring

Aug 7, 2017 • 9 min read
Read Post
image for WSH Injection: A Case Study

Research & Tradecraft

WSH Injection: A Case Study

Aug 3, 2017 • 4 min read
Read Post
image for Offensive Encrypted Data Storage (DPAPI edition)

Research & Tradecraft

Offensive Encrypted Data Storage (DPAPI edition)

Jul 31, 2017 • 5 min read
Read Post
image for Bypassing AMSI via COM Server Hijacking

Research & Tradecraft

Bypassing AMSI via COM Server Hijacking

Jul 19, 2017 • 6 min read
Read Post
image for Host-based Threat Modeling & Indicator Design

Research & Tradecraft

Host-based Threat Modeling & Indicator Design

Jul 18, 2017 • 18 min read
Read Post