Grepton

6 posts

Grepton

Grepton

@ReptonSec

Katılım Haziran 2021
55 Takip Edilen0 Takipçiler
Grepton retweetledi
🥝🏳️‍🌈 Benjamin Delpy
Want to block [MS-EFSR] / #PetitPotam calls?🤔 Use RPC filters ! 🥳 put previous Tweet in a file: `block_efsr.txt` then: > netsh -f block_efsr.txt Just tested: it blocks remote connections & not local EFS usage Thank you to @CraigKirby to remind us this RPC technology filter!
🥝🏳️‍🌈 Benjamin Delpy tweet media🥝🏳️‍🌈 Benjamin Delpy tweet media
🥝🏳️‍🌈 Benjamin Delpy@gentilkiwi

rpc filter add rule layer=um actiontype=block add condition field=if_uuid matchtype=equal data=c681d488-d850-11d0-8c52-00c04fd90f7e add filter add rule layer=um actiontype=block add condition field=if_uuid matchtype=equal data=df1941c5-fe89-4e79-bf10-463657acf44d add filter quit

English
9
285
538
0
Grepton
Grepton@ReptonSec·
@atc_project @cyb3rops Is ATC the only project organising and structuring Sigma rule detections, dependencies & playbooks etc? I don't see anyone else doing it and the ATC project seems quiet
English
1
0
0
0