Got the logs and need to know what to do with them? @neu5ron and @acalarch have you covered➡️irongeek.com/i.php?page=vid…
Need to send those logs to a SIEM of some kind? My man @InvokeThreatGuy show's you how ➡️invokethreat.actor/2018/09/levera…
➡️fireeye.com/blog/threat-re…
WEF Broken? Check out this post by @Centurion ➡️hackernoon.com/the-windows-ev…
Want to know more about application whitelisting, advanced PowerShell / .NET tradecraft? ➡️exploit-monday.com, also by @mattifestation
➡️github.com/hunters-forge/… by @Cyb3rWard0g
➡️github.com/sbousseaden/EV… by @SBousseaden
➡️jpcertcc.github.io/ToolAnalysisRe… by @jpcert_en
➡️adsecurity.org
➡️ @SwiftOnSecurity 's config: github.com/SwiftOnSecurit…
➡️Check out @c_APT_ure 's various talks
➡️ @olafhartong 's Sysmon Modular config: github.com/olafhartong/sy…
@curi0usJack 's talk ➡️
@FuzzySec 's GitHub repo: github.com/FuzzySecurity
@_xpn_ 's blog: blog.xpnsec.com
@TheRealWover ➡️thewover.github.io
➡️github.com/fireeye/SilkETW
➡️fireeye.com/blog/threat-re…
➡️medium.com/threat-hunters… by @cyb3rops
➡️github.com/Neo23x0/sigma
@ItsReallyNick 's feed and #DailyScriptlet tag are also illuminating.
➡️kroll.com/en/insights/pu…
➡️engineering.salesforce.com/tls-fingerprin…
Check out Moloch full packet capture (my blog) ➡️haveyousecured.blogspot.com/2018/10/moloch…