#IncidentResponder

David Longeneckerdnlongen@infosec.exchange
2022-11-24

Most of us in this field are aware that some types of administrative tools and administrative logons leave behind credentials in a manner that can be reused by an actor on a compromised host, and some do not. I've been looking for a #sysadmin and #incidentresponder cheat sheet for a while - @reprise_99 brought this one to my attention. Nice! learn.microsoft.com/en-us/wind #dfir #toolbox

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst