Securehat
search
⌘Ctrlk
@FranticTyping
Securehat
  • Blog Overview
    • Cobalt Strike Staging and Extracting Configuration Information
    • Fighting Back Against Cobalt Strike - Detection Ideas
    • Tool-Less Extraction of IOCs from an Emotet Maldoc
    • Extracting the Cobalt Strike Config from a TEARDROP Loader
    • Shellcode Execution via EnumSystemLocalA
    • Manually Implementing Inline Function Hooking
    • Detecting Process Injection using Microsoft Detour Hooks
    • Detecting Parent Process Spoofing using KrabsETW
    • Chainsaw Tool - Search and Hunt Through Event Logs
    • Hunting for C3 Activity
    • Scaling Detection and Response Operations
gitbookPowered by GitBookgitbook
  1. πŸ”Detection Experiments

Hunting for C3 Activity

LogoHunting for C3labs.withsecure.comchevron-right
PreviousChainsaw Tool - Search and Hunt Through Event Logschevron-leftNextScaling Detection and Response Operationschevron-right

Last updated 2 years ago