New Sliver and Metasploit EVTX files including cmd.exe writing to ADMIN$, and suspicious remote threads
This commit is contained in:
BIN
evtx/metasploit-sysmon.evtx
Normal file
BIN
evtx/metasploit-sysmon.evtx
Normal file
Binary file not shown.
BIN
evtx/sliver-security.evtx
Normal file
BIN
evtx/sliver-security.evtx
Normal file
Binary file not shown.
BIN
evtx/sliver-sysmon.evtx
Normal file
BIN
evtx/sliver-sysmon.evtx
Normal file
Binary file not shown.
Reference in New Issue
Block a user