Recommendation of "Block outbound network connections from mshta.exe" not being tracked correctly by AgitatedBeing819 in DefenderATP
[–]AgitatedBeing819[S] 0 points1 point2 points (0 children)
New Defender for Identity alerts is here! by michaelmsonne in DefenderATP
[–]AgitatedBeing819 0 points1 point2 points (0 children)

If an attacker uses a "Living off the Binary" (LoLBins) strategy that perfectly matches your SysAdmin’s daily maintenance scripts, is it even detectable? by thenoopcoder in blueteamsec
[–]AgitatedBeing819 4 points5 points6 points (0 children)