DefCon Talk Your: Domain is Compromised “Now What”?
Grant Bugher with perimetergrid.com had a talk on the DEFCON101 track. “Obtaining and Detecting Domain Persistence” As the slide above states, it is not about _how_ to hack a domain. But assuming someone has – now what? 1st Process start command line logging and PowerShell logging enabled on all systems. 2nd SysMon(Sysinternals Monitoring Service) … Read more