All new posts are published on: https://www.devilreef.netWant to read new blog posts? Check them out over on my personal site.Sep 24, 2022Sep 24, 2022
Detecting Windows Endpoint Compromise with SACLsThis post is going to focus on using the system access control list (SACL) functionality to detect endpoint compromise on Windows hosts…Jul 16, 20181Jul 16, 20181
DARKSURGEON: A Windows 10 Packer Project for DefendersI’m happy to announce the alpha release of DARKSURGEON, a Windows 10 packer project to empower incident response, digital forensics…May 14, 20182May 14, 20182
Endpoint Isolation with the Windows FirewallOver the last few weeks, I’ve had conversations with several individuals around mitigating lateral movement in a Windows environment. In…Apr 22, 20183Apr 22, 20183