Tagged: Incident Response

Cloud Chain of Custody

This post is focused on the Chain of Custody in general and some of the implications of the Cloud. If you are looking for CoC scenarios and how they affect the Cloud, the following post will discuss handling the Chain … Read the rest

Log4j INCIDENT RESPONSE with Microsoft Sentinel

Log4j INCIDENT RESPONSE

The following post will assist you with the Log4j incident response process based on the familiar tools, mitigate options, and the information from the vendors and community.

Introduction

On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache … Read the rest

Kubernetes Incident Response

Kubernetes Incident Response, How does it look like? Your ability to react quickly to a security incident can differentiate between a significant incident and a small one.

For sure, it can help minimize damage caused by some breaches. In many Read the rest

Azure Sentinel and Sysmon 4 B!ue T3amer$

Azure Sentinel and Sysmon 4 B!ue T3amer$

Recently, there have been massive cyberattacks against cloud providers and on-premises environments, the most recent of which is the attack and exploitation of vulnerabilities against Exchange servers – The HAFNIUM. This post focus on Azure Sentinel and Sysmon 4 … Read the rest