Conventions regarding Sysmon rules
Recently, I started researching the Blind Eagle attack and was also able to emulate it properly with the appended documentation.
I would like to view data about it in my Splunk and Wazuh dashboards. What configuration should I use? Are the… Continue reading Conventions regarding Sysmon rules