#hack100days: day 52 : Spent more time on CRTO, got through several sections. If something talks lsass, there's a Windows Event 4656 generated. These events don't make it into Windows Defender ATH. KQL that *might* help can be found here: https://infosec.exchange/@scottlink/109922158743618879 (CS may not have like my KQL, so trying the link.) (Lsass does get started in the normal day-to-day of things, filter out it itself being the process, look for things trying to operate on it.) #redteam #blueteam #GetSmart #CoSoSec
Since we see the previous post, theory CS doesn't like KQL seems to hold up.