Posts

Live forensic collection and triage using CyLR, CDQR and Skadi

Reversing shellcode using blobrunner and Olly

Hunting for malicious DCSync operations

Hunting for Privilege Escalation Done with Invoke-TokenManipulation