Windows Event Logs & Finding Evil











Sysmon Basics
Unexpected error with integration github-files: Integration is not installed on this space
Unexpected error with integration github-files: Integration is not installed on this space

Unexpected error with integration github-files: Integration is not installed on this space
Detect a DLL hijack




Detecting Unmanaged PowerShell/C-Sharp Injection



powershell.exe, by right-clicking on powershell.exe, clicking "Properties", and navigating to "Modules", we can find relevant information. The presence of "Microsoft .NET Runtime...", clr.dll, and clrjit.dll should attract our attention. Last updated






