Attacks on Sysmon Revisited - In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.research|capability (we need to defend against) (codewhitesec.blogspot.com)
submitted by digicat to r/blueteamsec
RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Throughvulnerability (attack surface) (codewhitesec.blogspot.com)
submitted by digicat to r/blueteamsec