For the past 6-7 months I have been diving into one of Windows core components - RPC. During my research, I found how to utilize RPC telemetry from a defensive perspective. I’ve compiled my findings in the following paper-
ipc-research.readthedocs.io/…
I’ve built a side project to show the functional status of the current #Sysmon version here:
sysmon.works
Note; It’s not complete yet, still adding things. There are some small manual tasks left so it will change over time, I plan to host historical info. Blog soon.
A new #Sysmon version also requires an update to my Sysmon-modular project.
The main branch now supports version 13 and has several filters as examples. (filter carefully to not cause huge blind spots)
Older versions are available in their branches.
github.com/olafhartong/sysmo…
Happy to announce what so many in the community have been waiting for so long!
A lab extension to compose dashboards from notebook cells with a drag-and-drop UI. Resulting dashboards can be published as Voilà applications!
blog.jupyter.org/dashboardin…