BHIS | Offensive Windows Event Logs | Tim Fowler | 1 Hour

Поделиться
HTML-код
  • Опубликовано: 7 сен 2024

Комментарии • 11

  • @ReQuiem_2099
    @ReQuiem_2099 2 года назад

    Caught you guys live, but of course, work called. Glad you are reposting this valuable training to RUclips!

  • @kartikswamy3494
    @kartikswamy3494 2 года назад

    I love soft soft so so so so much!

  • @mihajlodizajn4752
    @mihajlodizajn4752 2 года назад

    with it in a few weeks or months if I pour enough ti and effort into it. I'll be watcNice tutorialng many more of your videos for tips and inspiration.

  • @StoryWaves28
    @StoryWaves28 2 года назад

    Thank you

  • @goosemobile8
    @goosemobile8 2 года назад +2

    Very cool, thanks for the presentation. As a strictly blue team guy, this really reminds how threats can come from practically anywhere--even event logs, wtf?! I'd also be curious if you have found any reliable detection methods for this kind of behavior.

  • @NetworkITguy
    @NetworkITguy 2 года назад

    The category can be one and is common for windows services.

  • @neetech3716
    @neetech3716 2 года назад

    nice

  • @Designsy-wl9nr
    @Designsy-wl9nr 2 года назад

    Nice job!

  • @richardh9071
    @richardh9071 2 года назад +1

    Great presentation! From a blue team perspective it'll be interesting to find ways of detecting this. Have you done any post mortem on devices where this methodology was utilised? Presumably the parent process would be the 'BHIS3.exe', or is some other process used? Are there any interesting command line parameters available that could be used for identifying this execution method?
    Also, does BHIS3.exe compile the malicious EXE then save it to disk (potentially triggering an AV detection), or does it load it right into memory, effectively a 'file less' malware?

  • @kemal9633
    @kemal9633 2 года назад

    Okay, okay yes, I get tNice tutorials and I get that-

  • @greekz8750
    @greekz8750 2 года назад

    I ain't got exams per say, but I'm tryna study for an IT certification... TNice tutorials is more important tho