41dfd8ff0c
chore: Suspicious CLR Logs Creation chore: Remote Task Creation via ATSVC Named Pipe - Zeek chore: Possible Impacket SecretDump Remote Activity - Zeek chore: Suspicious PsExec Execution - Zeek chore: AD Privileged Users or Groups Reconnaissance chore: Remote Task Creation via ATSVC Named Pipe chore: Impacket PsExec Execution chore: Possible Impacket SecretDump Remote Activity chore: Suspicious PsExec Execution chore: Remote Service Activity via SVCCTL Named Pipe chore: Suspicious DotNET CLR Usage Log Artifact chore: DotNet CLR DLL Loaded By Scripting Applications chore: Potential Credential Dumping Activity Via LSASS chore: DNS RCE CVE-2020-1350 --------- thanks: @fukusuket
TBD