joshlemon's profile picture. Chief DIFR at @SoteriaSec_io | @SANSInstitute Principal Instructor & Author | Digital Forensics & Incident Response geek

Josh Lemon

@joshlemon

Chief DIFR at @SoteriaSec_io | @SANSInstitute Principal Instructor & Author | Digital Forensics & Incident Response geek

Repost di Josh Lemon

It's time to update your detections if you haven't been looking for WebShells on your #SharePoint server. 🕵‍ Make sure you're detecting w3wp.exe > cmd.exe > PowerShell.exe Although really, cmd.exe being spawned by your SharePoint server really needs a thorough review.

SoteriaSec_io's tweet image. It's time to update your detections if you haven't been looking for WebShells on your #SharePoint server. 

🕵‍ Make sure you're detecting w3wp.exe > cmd.exe > PowerShell.exe
Although really, cmd.exe being spawned by your SharePoint server really needs a thorough review.

Repost di Josh Lemon

Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. These vulnerabilities apply to on-premises SharePoint Servers only. Customers should apply these updates immediately to…


Repost di Josh Lemon

How DCOM lateral movement works. #ThreatHunting #DFIR


Repost di Josh Lemon

Windows Logon Types #ThreatHunting #DFIR

ACEResponder's tweet image. Windows Logon Types

#ThreatHunting #DFIR

Here's an update on the data breach of court documents from the NSW JusticeLink website. tl;dr - it was an individual that was able to download +9k documents over two months, it doesn't appear they were leaked anywhere publicly. theguardian.com/australia-news…


Loading...

Something went wrong.


Something went wrong.