



Rob Winchester
427 posts

@robwinchester3
Vice President @SpecterOps | Former USAF | Problem Solver





















For the past 6-7 months I have been diving into one of Windows core components - RPC. During my research, I found how to utilize RPC telemetry from a defensive perspective. I’ve compiled my findings in the following paper- ipc-research.readthedocs.io/en/latest/subp…



Despite its incredible security enhancements, PowerShell continues to be abused by adversaries. A strong knowledge of PowerShell enables defenders to effectively manage and respond to its abuse. (1/4)
