Open in app

Sign in

Write

Sign in

Sina Mohebi
Sina Mohebi

31 Followers

Home

About

Pinned

How to Use MITRE ATT&CK in SOC

Using MITRE ATT&CK in a Security Operations Center (SOC) can greatly enhance threat detection and response capabilities. Here are the steps to effectively utilize MITRE ATT&CK framework in a SOC Familiarize Yourself with MITRE ATT&CK Understand the purpose and structure of the MITRE ATT&CK framework. Explore the ATT&CK website (https://attack.mitre.org/)…

Soc

3 min read

How to Use MITRE ATT&CK in SOC
How to Use MITRE ATT&CK in SOC
Soc

3 min read


Nov 9

Defending Against Mail Spoofing: Technical Solutions for Enhanced Email Security & Disabling SMTP Relaying

Introduction: In today’s digital landscape, mail spoofing poses a significant threat to individuals and organizations. It allows malicious actors to forge email headers, deceiving recipients into believing the messages are legitimate. To safeguard against such attacks, implementing technical solutions becomes crucial. In this article, we will explore several measures that…

Mail

3 min read

Defending Against Mail Spoofing: Technical Solutions for Enhanced Email Security & Disabling SMTP…
Defending Against Mail Spoofing: Technical Solutions for Enhanced Email Security & Disabling SMTP…
Mail

3 min read


Nov 5

Detecting Webshells with Sysmon: A Technical Analysis

Introduction: Webshells are malicious scripts or programs that attackers deploy on web servers to gain unauthorized access and control. Detecting these webshells is crucial for maintaining the security of web applications and protecting sensitive data. In this article, we will explore how Sysmon, a powerful Windows system monitoring tool, can…

Webshell

4 min read

Detecting Webshells with Sysmon: A Technical Analysis
Detecting Webshells with Sysmon: A Technical Analysis
Webshell

4 min read


Aug 2

RDP Event logs tracking 4624 / 4625

Event ID 4624 is generated in the Windows Security Log when a successful logon occurs on a local computer. This event is generated on the computer that was accessed, meaning that it is the computer where the logon session was created. A related event, Event ID 4625, is generated when…

Soc

3 min read

Soc

3 min read

Sina Mohebi

Sina Mohebi

31 Followers

Security analyst & OSINT Researcher

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams