Tactics and Techniques
Tactics and Techniques
Potentially suspicious commands
https://gist.github.com/gfoss/2b39d680badd2cad9d82
Mandiant's guide to Powershell logging
NTLM relay
https://posts.bluraven.io/detecting-ntlm-relay-attacks-d92e99e68fb9
Detecting Kerberos Relaying atttacks
https://posts.bluraven.io/detecting-kerberos-relaying-e6be66fa647c
Japan CERT guide
https://www.jpcert.or.jp/english/pub/sr/20170612ac-ir_research_en.pdf
CERT-EU guide
https://media.cert.europa.eu/static/WhitePapers/CERT-EU_SWP_17-002_Lateral_Movements.pdf
Compass Security's guide to GPO settings
Forward Defense's Analyst guide
https://www.forwarddefense.com/media/attachments/2021/05/15/lateral-movement-analyst-reference.pdf
The Lowdown on Lateral Movement from Lares