Advertisement
recon-scout

Hunting for Credential Theft

Nov 13th, 2019
369
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.16 KB | None | 0 0
  1. sourcetype="WinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode=10 TargetImage="*lsass.exe" | stats count,values(TargetImage) by SourceImage | sort + count
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement