Today we have a special FalconFriday, covering two big events of the past week.
Our blog
In today’s edition, we’ll cover two techniques: Remote service creation over RPC and SharpRDP.
In today’s edition, we’ll cover two techniques: suspicious parent-child process relationships and impersonation with the RunAs command.
In today’s edition, we’ll cover two techniques: privilege escalation through DLL hijacking and masquerading files as unsigned processes.
This FalconFriday is focused on lateral movement. Especially lateral movement through DCOM, a technique used by many red teams.