S0xbad1dea Profile Banner
super.0xbad1dea Profile
super.0xbad1dea

@S0xbad1dea

Followers
105
Following
1K
Media
38
Statuses
251

Pokemon, Digimon, Sysmon | #DFIR #Sysmon #Splunk

Joined February 2019
Don't wanna be here? Send us removal request.
@S0xbad1dea
super.0xbad1dea
1 day
RT @fabian_bader: You work with #XDR and always wanted to the process tree data outside of the Defender portal?. With XDR Story Parser you….
0
23
0
@S0xbad1dea
super.0xbad1dea
2 months
Hit me #TROOPERS25
0
1
1
@S0xbad1dea
super.0xbad1dea
1 year
Hi @GIMP_Official , why are you using in your current gimp version 2.10.38 the library liblzma-5.dll in version 5.6.1, which is a known vulnerable version of #CVE-2024-3094?.
0
0
1
@S0xbad1dea
super.0xbad1dea
1 year
Hey #MS #DfE guys. How do you deal with the fact that #Windows #DefenderForEndpoint sample events? We have several cases (True Positives!) where alarms were not triggered due to unlogged / not forwarded events. Do you take the risk, that you miss events and alarms?.
0
0
1
@S0xbad1dea
super.0xbad1dea
1 year
RT @securityfreax: We accidently built a Sysmon compatible tool with some neat features on top, like (in)direct syscall detection & more. W….
0
24
0
@S0xbad1dea
super.0xbad1dea
2 years
#Sysmon v15.14 out now.
1
0
1
@S0xbad1dea
super.0xbad1dea
2 years
RT @securityfreax: We are working on "WEASEL", a sysmon like userland application for windows security monitoring, but wihtout driver & ker….
0
28
0
@S0xbad1dea
super.0xbad1dea
2 years
Stay tuned, #Sysmon 15.1 will be released on 7th November. Hope this will fix this nasty performance bug, where systems freeze completely 🤞🥶.
1
0
6
@S0xbad1dea
super.0xbad1dea
2 years
RT @jsecurity101: Couple of issues I have found with Sysmon v15 so far: . 1. Sysmon.exe -u isn't properly uninstalling/stopping the Sysmon….
0
13
0
@S0xbad1dea
super.0xbad1dea
2 years
RT @olafhartong: #Sysmon 15 is out and brings a new event type, FileExecutableDetected, which allows for much more detection opportunities.….
Tweet card summary image
medium.com
Sysmon 15 has just been released and has received several bug fixes, one among them which could prevent a machine from booting while…
0
132
0
@S0xbad1dea
super.0xbad1dea
2 years
RT @CaptnBanana: ShhPlunk: Muting the Splunk Forwarder - /
Tweet media one
0
9
0
@S0xbad1dea
super.0xbad1dea
2 years
RT @AllForOsint: Hey 🕵️‍♂️#OSINT🕵️‍♀️ 👀, Mobility Portal by geOps combines maps of many aspects of #public #transport & mobility in genera….
0
20
0
@S0xbad1dea
super.0xbad1dea
2 years
Hey #Sysmon folks. Are you also experiencing more and more annoyed admins complaining about Sysmon performance problems since the update to 14.16? 🤔 Usually I take a look at the MS Forum, but since they changed everything, it's a mess to get an overview 🙈.
2
1
3
@S0xbad1dea
super.0xbad1dea
2 years
RT @trk_rdy: Another blog out today. I poked at another lsass dumping tool I heard about, check it out! #MDE .https….
0
7
0
@S0xbad1dea
super.0xbad1dea
2 years
RT @BSidesFRA: Checking out the location. Will be awesome in September! #bsidesfrankfurt
Tweet media one
0
3
0
@S0xbad1dea
super.0xbad1dea
2 years
Damn, what happened to the #SysInternals / #Sysmon forum? Where has the clarity gone? Is this the only way to get to the so called "forum"? This is a step backwards
0
0
0
@S0xbad1dea
super.0xbad1dea
3 years
Maybe @NathanMcNulty ?.
1
0
1
@S0xbad1dea
super.0xbad1dea
3 years
Hey IT Sec folks. If you are using #ExploitGuard in #Windows, what's the difference between "Validate image dependency integrity" and "Code integrity guard"? It looks similar to me, both check the signature of the executables (signed by MS). Thx in advance.
1
0
2
@S0xbad1dea
super.0xbad1dea
3 years
RT @malcomvetter: [INTERACTIVE BLOG] .Did you like Choose Your Own Adventure books as a kid?.Are you fascinated by Red Team adversary trade….
0
159
0