frequent victim of nerd sniping; #PowerShell aficionado; blue teamer; black metal fanatic; (awful) drummer; ADHD galore; he/him;
#tweetsizedoneliners
Dec 17, 2020 • 14 tweets • 4 min read
No DNS logs?
Next best activity indicator seems to be file-write events to `SolarWindows.Orion.Core.BusinessLayer.dll.config` (used to track detection and modification of forensic/anti-tamper services)