From 4b8e07eceb204ced84b7aa5f873a9a3cfeda8220 Mon Sep 17 00:00:00 2001 From: pe3zx Date: Mon, 5 Nov 2018 11:27:31 +0700 Subject: [PATCH] Update: Detecting Mimikatz & other Suspicious LSASS Access --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 3dd6cb8..d68b0e8 100644 --- a/README.md +++ b/README.md @@ -121,7 +121,7 @@ My curated list of awesome links, resources and tools - [RecentApps Registry Key](https://df-stream.com/2017/10/recentapps/) - [RegRipper & keys parsed by plugins](http://hexacorn.com/tools/3r.html) - [Some reminders about Windows file times](https://medium.com/@4n68r/some-reminders-about-windows-file-times-2debe1edb978) -- [Tales of a Threat Hunter 1](https://www.eideon.com/2017-09-09-THL01-Mimikatz/) +- [Tales of a Threat Hunter - Detecting Mimikatz & other Suspicious LSASS Access](https://www.eideon.com/2017-09-09-THL01-Mimikatz/) - [Volume Shadow Copies in forensic analysis](https://andreafortuna.org/volume-shadow-copies-in-forensics-analysis-7708adefe61c) - [Use Windows Event Forwarding to help with intrusion detection](https://docs.microsoft.com/en-us/windows/threat-protection/use-windows-event-forwarding-to-assist-in-instrusion-detection) - [Windows, Now with built in anti forensics!](http://www.hecfblog.com/2017/04/windows-now-built-in-anti-forensics.html)