Operations | Monitoring | ITSM | DevOps | Cloud

Latest News

Mr. Robot, Mimikatz and Lateral Movement

In Mr. Robot‘s episode 9 of season 2 (13:53), Angela Moss needs to obtain the Windows domain password of her superior, Joseph Green, in order to download sensitive documents that would potentially incriminate EvilCorp. Since her attack requires physical access to his computer, she starts with a good old-fashioned social engineering attack to get the only currently present employee in the office to leave.

Securing Exchange Server OWA & ActiveSync - Proactive Security with EventSentry

With the proper auditing enabled (Logon/Logoff – Logon (Failure)) and EventSentry installed however, we can permanently block remote users / hosts who attempt to log on too many times with a wrong password. Setting this up is surprisingly simple.

5 Things You Need to Know About Business Continuity Management

If business professionals ignore network and system issues, the consequences could be dire. For instance, imagine what might happen if your company suffers a cyberattack, flood or supply chain failure. In this scenario, your critical networks and systems may slow down or stop working. And if you lack an effective business continuity management (BCM) strategy, you risk downtime and outages that could put a significant dent in your business’ bottom line.

Auditing DNS Server Changes on Windows 2008/2008R2/2012 with EventSentry

If you’re running Windows 2008 (R2) or 2012 then setting up DNS auditing requires a few steps. Thankfully it’s a one-time process and shouldn’t take more than a few minutes. On the EventSentry side a pre-built package with all the necessary rules is available for download and included with the latest installer.