Ryan Watson
More by Ryan Watson
Adversary Simulation
Windows Events, Sysmon and Elk…oh my! (Part 2)
March 12, 2018
In this post, we will be working through setting up a log collector for Windows Event Forwarding, creating a GPO to support Windows Event Forwarding, creating a GPO to deploy SYSMON, creating event subscriptions, forwarding events using Winlogbeat to ELK, and generating events.
Learn More
Adversary Simulation
Windows Events, Sysmon and Elk…oh my!
February 6, 2018
This is part 1 in a multi-part blog series on helping organizations implement robust, effective Windows monitoring.
Learn More
Adversary Simulation
ESPKey + Long Range RFID Reader = A New Tastic Thief
January 26, 2018
We’re not going to document how to build another RFID Tastic-Thief. Instead, we’ve come up with a different approach to building a long-range reader that we think is worth sharing.
Learn More