2026-04-13 01-59-34
Kelliema
Kapitoli
-
0:10Kapitolu 1: In this video, we're going to start taking a look at some specific IOCs that are associated with endpoint threat hunting. 304s · Speaker 1
In this video, we're going to start taking a look at some specific IOCs that are associated with endpoint threat hunting. Now remember, we're just looking at endpoint -specific IOCs in this video, but any IOC can be used to search on your e…
-
5:14Kapitolu 2: a value itself. 301s · Speaker 1
a value itself. And you also have Windows event ID 4657, and that's just a generic registry value was modified ID. So all of those can be useful for searching for any sort of malicious modifications to the registry. And then we have our sch…
-
10:15Kapitolu 3: it in. You can also have invoke web requests. 274s · Speaker 1
it in. You can also have invoke web requests. That is a very common one that attackers use when they're trying to download malicious payloads. It can also be abbreviated in the command line or the PowerShell prompt as IWR. And then if you s…