Date Author Title
2024-12-20Xavier MertensChristmas "Gift" Delivered Through SSH
2023-06-29Brad DuncanGuLoader- or DBatLoader/ModiLoader-style infection for Remcos RAT
2023-03-22Didier StevensWindows 11 Snipping Tool Privacy Bug: Inspecting PNG Files
2023-02-19Didier Stevens"Unsupported 16-bit Application" or HTML?
2023-02-09Xavier MertensA Backdoor with Smart Screenshot Capability
2022-11-05Guy BruneauWindows Malware with VHD Extension
2022-06-26Didier StevensMy Paste Command
2022-06-24Xavier MertensPython (ab)using The Windows GUI
2022-04-28Johannes UllrichA Day of SMB: What does our SMB/RPC Honeypot see? CVE-2022-26809
2022-04-14Johannes UllrichAn Update on CVE-2022-26809 - MSRPC Vulnerabliity - PATCH NOW
2022-04-06Brad DuncanWindows MetaStealer Malware
2022-02-25Didier StevensWindows, Fixed IPv4 Addresses and APIPA
2021-10-14Xavier MertensPort-Forwarding with Windows for the Win
2021-07-21Johannes Ullrich"Summer of SAM": Microsoft Releases Guidance for CVE-2021-36934
2021-07-19Rick WannerNew Windows Print Spooler Vulnerability - CVE-2021-34481
2021-05-02Didier StevensPuTTY And FileZilla Use The Same Fingerprint Registry Keys
2020-09-30Johannes UllrichScans for FPURL.xml: Reconnaissance or Not?
2020-09-02Xavier MertensPython and Risky Windows API Calls
2020-09-01Johannes UllrichExposed Windows Domain Controllers Used in CLDAP DDoS Attacks
2020-08-25Xavier MertensKeep An Eye on LOLBins
2020-06-24Jan KoprivaUsing Shell Links as zero-touch downloaders and to initiate network connections
2020-03-30Jan KoprivaCrashing explorer.exe with(out) a click
2020-03-23Didier StevensWindows Zeroday Actively Exploited: Type 1 Font Parsing Remote Code Execution Vulnerability
2020-03-16Jan KoprivaDesktop.ini as a post-exploitation tool
2020-02-18Jan KoprivaDiscovering contents of folders in Windows without permissions
2020-02-17Didier Stevenscurl and SSPI
2020-02-15Didier Stevensbsdtar on Windows 10
2020-01-09Kevin ShorttWindows 7 - End of Life
2019-06-27Rob VandenBrinkFinding the Gold in a Pile of Pennies - Long Tail Analysis in PowerShell
2019-06-06Xavier MertensKeep an Eye on Your WMI Logs
2019-05-22Johannes UllrichAn Update on the Microsoft Windows RDP "Bluekeep" Vulnerability (CVE-2019-0708) [now with pcaps]
2019-03-05Rob VandenBrinkPowershell, Active Directory and the Windows Host Firewall
2019-01-14Rob VandenBrinkStill Running Windows 7? Time to think about that upgrade project!
2018-12-19Xavier MertensRestricting PowerShell Capabilities with NetSh
2018-12-19Xavier MertensMicrosoft OOB Patch for Internet Explorer: Scripting Engine Memory Corruption Vulnerability
2018-06-05Xavier MertensMalicious Post-Exploitation Batch File
2018-05-07Xavier MertensAdding Persistence Via Scheduled Tasks
2018-05-02Russ McReeWindows Commands Reference - An InfoSec Must Have
2017-11-15Xavier MertensIf you want something done right, do it yourself!
2017-11-11Xavier MertensKeep An Eye on your Root Certificates
2017-01-18Rob VandenBrinkMaking Windows 10 a bit less "Creepy" - Common Privacy Settings
2017-01-12Mark BaggettSystem Resource Utilization Monitor
2016-11-18Didier StevensVBA Shellcode and Windows 10
2016-08-29Russ McReeRecommended Reading: Intrusion Detection Using Indicators of Compromise Based on Best Practices and Windows Event Logs
2016-08-02Tom WebbWindows 10 Anniversary Update Available
2016-07-12Xavier MertensHunting for Malicious Files with MISP + OSSEC
2016-05-22Pasquale StirparoThe strange case of WinZip MRU Registry key
2016-05-18Russ McReeResources: Windows Auditing & Monitoring, Linux 2FA
2016-04-15Xavier MertensWindows Command Line Persistence?
2016-03-30Xavier MertensWhat to watch with your FIM?
2016-02-18Xavier MertensHunting for Executable Code in Windows Environments
2016-01-31Guy BruneauWindows 10 and System Protection for DATA Default is OFF
2015-12-09Xavier MertensEnforcing USB Storage Policy with PowerShell
2015-08-12Rob VandenBrinkWindows Service Accounts - Why They're Evil and Why Pentesters Love them!
2014-08-15Tom WebbAppLocker Event Logs with OSSEC 2.8
2014-07-05Guy BruneauJava Support ends for Windows XP
2014-04-06Basil Alawi S.Taher"Power Worm" PowerShell based Malware
2014-04-04Rob VandenBrinkWindows 8.1 Released
2014-03-24Johannes UllrichNew Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks
2014-03-04Daniel WesemannXPired!
2014-01-10Basil Alawi S.TaherWindows Autorun-3
2014-01-04Tom WebbMonitoring Windows Networks Using Syslog (Part One)
2013-10-30Russ McReeSIR v15: Five good reasons to leave Windows XP behind
2013-03-19Johannes UllrichWindows 7 SP1 and Windows Server 2008 R2 SP1 Being "pushed" today
2013-02-28Daniel WesemannParsing Windows Eventlogs in Powershell
2012-10-24Rob VandenBrinkTime to run Windows Update - - Microsoft Updates KB2755801 for Windows RT / IE10 / Flash Player - http://technet.microsoft.com/en-us/security/advisory/2755801
2012-07-19Mark BaggettDiagnosing Malware with Resource Monitor
2012-06-25Guy BruneauIssues with Windows Update Agent
2012-05-08Bojan ZdrnjaWindows Firewall Bypass Vulnerability and NetBIOS NS
2012-05-06Jim ClausingTool updates and Win 8
2012-04-10Swa FrantzenWindows Vista RIP
2011-12-21Johannes UllrichNew Vulnerability in Windows 7 64 bit
2011-07-09Chris MohanSafer Windows Incident Response
2011-06-30Rob VandenBrinkUpdate for RSA Authentication Manager
2011-06-01Johannes UllrichEnabling Privacy Enhanced Addresses for IPv6
2011-03-27Guy BruneauStrange Shockwave File with Surprising Attachments
2011-03-15Lenny ZeltserLimiting Exploit Capabilities by Using Windows Integrity Levels
2011-02-24Johannes UllrichWindows 7 / 2008 R2 Service Pack 1 Problems
2011-02-23Johannes UllrichWindows 7 Service Pack 1 out
2011-02-16Jason LamWindows 0-day SMB mrxsmb.dll vulnerability
2011-02-10Chris MohanBefriending Windows Security Log Events
2011-01-24Rob VandenBrinkWhere have all the COM Ports Gone? - How enumerating COM ports led to me finding a “misplaced” Microsoft tool
2011-01-04Johannes UllrichMicrosoft Advisory: Vulnerability in Graphics Rendering Engine
2010-11-24Bojan ZdrnjaPrivilege escalation 0-day in almost all Windows versions
2010-08-02Manuel Humberto Santander PelaezSecuring Windows Internet Kiosk
2010-06-15Manuel Humberto Santander PelaezMicrosoft Windows Help and Support Center vulnerability (CVE 2010-1885) exploit in the wild
2010-02-11Deborah HaleThe Mysterious Blue Screen
2009-11-14Adrien de BeaupreMicrosoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-12Rob VandenBrinkWindows 7 / Windows Server 2008 Remote SMB Exploit
2009-10-24Marcus SachsWindows 7 - How is it doing?
2009-09-08Guy BruneauVista/2008/Windows 7 SMB2 BSOD 0Day
2009-08-26Johannes UllrichWSUS 3.0 SP2 released
2009-07-16Guy BruneauChanges in Windows Security Center
2009-07-02Daniel WesemannTime to update updating on PCs for 3rd party apps
2009-04-16Adrien de BeaupreStrange Windows Event Log entry
2009-01-31Swa FrantzenWindows 7 - not so secure ?
2008-08-15Jim ClausingOMFW 2008 reflections
2008-06-12Bojan ZdrnjaSafari on Windows - not looking good
2008-05-17Lorna HutchesonXP SP3 Issues
2008-05-06John BambenekWindows XP Service Pack 3 Released
2008-05-01Adrien de BeaupreWindows XP SteadyState
2008-04-29Bojan ZdrnjaWindows Service Pack blocker tool
2008-04-16William StearnsWindows XP Service Pack 3 - unofficial schedule: Apr 21-28
2007-01-03Toby KohlenbergVLC Media Player udp URL handler Format String Vulnerability