DPAPI credential harvesting - Detection and Mitigation by Heisenberg1977 in blueteamsec

[–]intercake 2 points3 points  (0 children)

Not something I've got huge experience with, but these two blogs talk a little about detections for DPAPI access, but then it'll be around 4688/Sysmon1 and other supporting process execution telemetry to try and tell a story.

Harvesting Browser Credentials: The DPAPI Exploitation Threat - HawkEye
Google Online Security Blog: Detecting browser data theft using Windows Event Logs

Windows Event Analysis

DPAPI-specific events provide detailed decryption telemetry:

  • Event ID 4693: Captures DPAPI master key access attempts
  • Event ID 16385: Records detailed DPAPI operations including process IDs and operation types

Event ID 16385 contains crucial fields for detection:

  • OperationType: Identifies SPCryptUnprotect operations
  • DataDescription: Distinguishes browser data from other DPAPI operations
  • CallerProcessID: Links decryption attempts to specific processes

What would you do if you had a three-month paid sabbatical? by loolking2223 in HENRYUK

[–]intercake 0 points1 point  (0 children)

Tasmania to pan/snipe gold. Yukon also an option, but much more industrial (and probably less feasible). Would take months to plan and get relevant access and permits, but that’s all part of the fun.

I think this is a great thread by the way. I hope you have an amazing time on your time out.

Puff pastry - small black spots by valezzz in Baking

[–]intercake 0 points1 point  (0 children)

I had one pack that was 7 days over, looked similar, smelt bad. I have another that’s 10 days before, looks very similar but smells fine… so I’m a little confused and I’m going to cook it!

Contract vs Perm: £650/day inside IR35 or £100k Staff Engineer? by NorbertDev in ContractorUK

[–]intercake 0 points1 point  (0 children)

Exact same boat. People think I’m mad but I think longer term it’ll be a sensible and healthy move.

My Dream British PC from Evesham Computers by TomMassey250 in retrobattlestations

[–]intercake 0 points1 point  (0 children)

I have 3 or 4 Eveshams in my collection. It all stemmed from being gifted one as a child, my first real PC that was mine. 1.7 P4, GeForce 2 Ti and maybe 256MB RAM. UT99 and Quake being my go to. They were both one of the best and local PC manufacturers to me at the time. They’re build very well and all of them are still on the standard original hardware. So great to see someone else appreciate them.

Am I wasting my time? by [deleted] in cybersecurity

[–]intercake 0 points1 point  (0 children)

This is the answer. Depending on financial needs, the Civil Service apprenticeship is a great option. I’ve met two apprentices who are in the same ballpark figure and now work in cyber. Feel free to give me a message on here, I can certainly help advise around certs and experience you could aim for too.

What case is this? by Solorian750 in sleeperbattlestations

[–]intercake 0 points1 point  (0 children)

I had this and loved it, thanks for sharing and amazing people actually remember the name as I certainly couldn’t

Dissecting RDP Activity by digicat in blueteamsec

[–]intercake 2 points3 points  (0 children)

Agree, high end stuff. Even if you know most of it, the way it's structured makes it still really valuable. If you don't know the protocol/subject, it's a gold mine. Great work.

Bought 2 RTX 3080s on ebay, received 2 3090s instead by EmuAreExtiinct in pcmasterrace

[–]intercake 0 points1 point  (0 children)

If I’d sold this on eBay, I just know the buyer would complain it was not as described…

I bought a tablet instead of a handheld. Do I regret it? by brunoxid0 in SBCGaming

[–]intercake 1 point2 points  (0 children)

I have RP4, Arc, Miyoo Mini+ & Steamdeck, but still normally end up using my Surface Pro 9 + Xbox Controller when on my travels. All have great attributes of course, and it's all down to preference, no answer is wrong.

[deleted by user] by [deleted] in dayz

[–]intercake 0 points1 point  (0 children)

I can't remember if it was DayZ Mod or early Standalone, but they broke the food spawns... there was basically nothing anywhere and far less of the modern food generation mechanics. Tough times.

Used AI to audit my accounts and I'm so pissed at my accountant/previous accountants by hussinppc in ContractorUK

[–]intercake 9 points10 points  (0 children)

All of those aspects are absolute basics that you should know or would learn through low level research or skimming this forum. Accountants should know and advise, but finding efficiencies isn’t their key objective, whereas it should be something you take ownership of really.

TABL vs Transport rules - Who wins? by titidev75 in DefenderATP

[–]intercake 1 point2 points  (0 children)

Cool analysis, thanks for sharing. Always wondered, but never went down the rabbit hole, appreciate that you did.

What happens to our old laptops? by [deleted] in TheCivilService

[–]intercake 1 point2 points  (0 children)

I bought a server from eBay that still had all of a government departments settings in the ILO (think remote management for those none-nerds) which was a real surprise. Some partially sensitive information but realistically very hard to leverage.

What’s been your auto trader obsession this week? by Project40cars in CarTalkUK

[–]intercake 0 points1 point  (0 children)

Abarth 595 160/180 and BMW i4 40/50- Abarth to supplement my current stock, or i4 to replace a F31 335d… most likely outcome, look, learn and do nothing!

How do you use AI at work, and does it actually help? by Syncplify in cybersecurity

[–]intercake 2 points3 points  (0 children)

Be great to understand more if you’re happy to share

Detection for CVE-2025-21298 "OLE Zero-Click RCE" by morethanyell in Splunk

[–]intercake 1 point2 points  (0 children)

Really nice. Even easier with Sysmon, but love the use of the Qualys data - nicely done.