PCAParse

I was doing some research recently regarding what’s new to Windows 11, and ran across an interesting artifact, which seems to be referred to as “PCA”. I found a couple of interesting references regarding this artifact, such as this one from Sygnia, and… Continue reading PCAParse

Posted in Uncategorized

Lists of Images

There’re a lot of discussions out there on social media regarding how to get started or improve yourself or set yourself apart in cybersecurity, and lot of the advice centers around doing things yourself; setting up a home lab, using various tools, etc… Continue reading Lists of Images

Posted in Uncategorized

EDRSilencer

There’s been a good bit of discussion in the cybersecurity community regarding “EDR bypasses”, and most of these discussions have been centered around technical means a threat actor can use to “bypass” EDR. Many of these discussions do not seem to take… Continue reading EDRSilencer

Posted in Uncategorized

2023 Wrap-up

Another trip around the sun is in the books. Looking back over the year, I thought I’d tie a bow on some of the things I’d done, and share a bit about what to expect in the coming year.In August, I released RegRipper 4.0. Among the updates are some plu… Continue reading 2023 Wrap-up

Posted in Uncategorized

Round Up

MSSQL is still a thingTheDFIRReport recently posted an article regarding BlueSky ransomware being deployed following MSSQL being brute forced. I’m always interested in things like this because it’s possible that the author will provide clear observable… Continue reading Round Up

Posted in Uncategorized