@DebugPrivilege
DebugPrivilege
2 years
My favorite tools: - Wireshark - ProcMon - Sysmon - IDA Network packets and API calls don't lie, but people may tho :)
11
16
160

Replies

@MalFuzzer
Uriel Kosayev
2 years
@DebugPrivilege API monitor for lazy ones 😉
1
0
2
@DebugPrivilege
DebugPrivilege
2 years
@MalFuzzer Gotta make exciting for yourself ;-)
Tweet media one
1
0
3
@rcx86
Mr. Rc
2 years
@DebugPrivilege Have you tried dtrace?
0
0
3
@simplylurking2
Clout Repellent
2 years
@DebugPrivilege Can still make those like :)
0
0
0
@p_matula
Patrick Matula
2 years
@DebugPrivilege ProcMon + Wireshark are a powerful duo.
0
0
1
@MikeDanoski
MikeDano
2 years
@DebugPrivilege They (generally) don’t lie, they just don’t realize certain bits of info are critically important. Like when the thing we’ve been troubleshooting for months doesn’t repro if they update to the latest version of a particular 3rd party client app or filter driver.
0
0
3
@under_coverAL19
peperonin
2 years
@DebugPrivilege Microsoft Network Monitor (RPC), Wireshark, procmon process hacker Ghidra, VSCode
0
0
1
@World945613118
Wallysota
2 years
@DebugPrivilege Network miner 🤷‍♂️
0
0
0
@jonasLyk
Jonas L
2 years
@DebugPrivilege sure, they all good but what we realle need is syscall logging like this:
0
0
10
@HowWeLostTheWar
...and that was how we lost the war
2 years
@DebugPrivilege The Trinity: Zeek/Bro (network) Sysmon (host) Splunk (collection & analysis)
0
0
0