Windows Intrusion Investigation
Reconstructing a brute-force RDP compromise, backdoor account creation, privilege escalation, malware delivery, persistence, and command-and-control activity.
A growing collection of evidence-led investigations using Windows Event Logs and Sysmon telemetry.
Reconstructing a brute-force RDP compromise, backdoor account creation, privilege escalation, malware delivery, persistence, and command-and-control activity.