LetsDefend
3.2K posts

LetsDefend
@LetsDefendIO
LetsDefend, now part of Hack The Box. Read more: https://t.co/jxMnGZ4Yne
Cloud انضم Temmuz 2020
1 يتبع138.5K المتابعون

⚠️ New SOC Alert: Suspicious Rundll32 Execution Detected
Attackers use suspicious Rundll32 execution to proxy malicious DLL/code via a trusted Windows process, evading detection, blending with legit activity, and bypassing app controls (e.g., for credential theft).
👥 Role: Incident Responder
🛠️ Type: Generic
💪 Difficulty: Medium
🔢 Event ID: 285

English

⚠️ New SOC Alert: Critical System File Deletion
Attackers use Critical System File Deletion to erase logs, disable defenses, or trigger privilege escalation (e.g., via Windows Installer abuse), evading detection and causing DoS. This hides tracks and disrupts recovery.
🛠️ Type: Persistence
👥 Role: Incident Responder
💪 Difficulty: Medium
🔢 Event ID: 283

English

⚠️ New SOC Alert: Event Log Cleared
Attackers clear event logs (e.g., via wevtutil cl Security) to erase traces of intrusion like logins, malware execution, or privilege escalation, evading forensics and detection.
👥 Role: Incident Responder
💪 Difficulty: Persistence
🛠️ Type: Medium
🔢 Event ID: 282

English













