
The Haag™
@M_haggis • 9,818 subscribers
⚔️ Prevention Engineering at MagicSword | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer
Videos

I downloaded the release and tested it. I didn't observe any alerts or blocking during execution. The interesting part is that it's leveraging native Windows QoS policy functionality rather than exploiting a vulnerability. From what I observed, the tool simply creates QoS rules that throttle traffic for selected processes. In that sense, there's no single malicious API call that Windows/CS itself would block. That doesn't mean an EDR can't detect or respond to it. A vendor could alert on QoS policy creation, policy changes targeting security products, unusual command-line activity, registry modifications, or the resulting telemetry disruption. But in my testing, the execution itself wasn't prevented.
The Haag™16,829 просмотров • 3 месяцев назад

🎯 Introducing AD-ThreatHunting: ⚡ Supercharge Your AD Threat Hunting! 🛡️ Just Released: A comprehensive Active Directory PowerShell threat hunting tool that makes detecting suspicious activities easier than ever! ✨ Key Features: • Real-time attack detection • Advanced timing analysis • Pattern recognition • Multi-format reporting (CSV/JSON/HTML) • Built-in attack simulation 🔍 Detects: • Password spray attacks • Brute force attempts • Account lockouts • Off-hours activity • Geographically impossible logins • Service account misuse • Admin account abuse ⚡ Smart Analysis: • Time-based attack correlation • Activity pattern matching • User behavior analysis • Configurable business hours • Customizable thresholds 🧪 Includes Test Framework: • Simulate various attack scenarios • Validate detection capabilities • Test environment readiness • Verify audit policies 🚀 Get started: Made with ❤️ by defenders for defenders Hunt smarter, hunt harder #ActiveDirectory #InfoSec #BlueTeam #ThreatHunting #CyberSecurity
The Haag™16,660 просмотров • 1 год назад
Больше нет контента для загрузки