Securehat
search
⌘Ctrlk
@FranticTyping
Securehat
  • Blog Overview
    • Cobalt Strike Staging and Extracting Configuration Information
    • Fighting Back Against Cobalt Strike - Detection Ideas
    • Tool-Less Extraction of IOCs from an Emotet Maldoc
    • Extracting the Cobalt Strike Config from a TEARDROP Loader
    • Shellcode Execution via EnumSystemLocalA
    • Manually Implementing Inline Function Hooking
    • Detecting Process Injection using Microsoft Detour Hooks
    • Detecting Parent Process Spoofing using KrabsETW
    • Chainsaw Tool - Search and Hunt Through Event Logs
    • Hunting for C3 Activity
    • Scaling Detection and Response Operations
gitbookPowered by GitBookgitbook
  1. πŸ“˜High Level Blue Team Topics

Scaling Detection and Response Operations

A couple of blog posts that I wrote in my day job:

LogoScaling Detection and Response Operations at Coinbasecoinbasechevron-right
LogoScaling Detection and Response Operations at Coinbase Pt2coinbasechevron-right
LogoScaling Detection and Response Operations at Coinbase pt3coinbasechevron-right

PreviousHunting for C3 Activitychevron-left

Last updated 2 years ago