Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Tag: Lockbit

Defender, KQL and Lockbit

Posted on August 3, 2022 By Michael Kavka No Comments on Defender, KQL and Lockbit

Recently, SentinelOne had a blog post about how Lockbit Ransomware was using Windows Defender to side load Cobalt Strike. Considering that this technique I sat down to write up a query(that is available at my Github here) for a custom detection of this procedure based off the information in the SentinelOne Blog post. Here I…

Read More “Defender, KQL and Lockbit” »

Microsoft, Security
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware September 15, 2026
  • Hackers exploit Tencent app flaw to deploy GrayRabbit malware September 13, 2026 Bill Toulas
  • Security through obscurity is dead, and AI delivered the fatal blow September 13, 2026
  • RUSTGate: A Drone-Swarm Lure Points to Potential Defence-Sector Targeting September 13, 2026 Ctrl-Alt-Intel
  • Revolut confirms customer data breach through fake government requests September 12, 2026 Jagmeet Singh
  • Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent September 12, 2026 Bill Toulas
  • Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems September 12, 2026 djohnson
  • Behind the CAPTCHA: ClickFix, WallStealer and a Hidden Miner September 12, 2026 Ctrl-Alt-Intel
  • Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal September 11, 2026 Tim Starks
  • Hackers abused Claude to extract secrets from 1.8M Android apps September 11, 2026 Bill Toulas
  • Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device September 11, 2026
  • CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026 aws@amazon.com

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware September 15, 2026
  • Hackers exploit Tencent app flaw to deploy GrayRabbit malware September 13, 2026 Bill Toulas
  • Security through obscurity is dead, and AI delivered the fatal blow September 13, 2026
  • RUSTGate: A Drone-Swarm Lure Points to Potential Defence-Sector Targeting September 13, 2026 Ctrl-Alt-Intel
  • Revolut confirms customer data breach through fake government requests September 12, 2026 Jagmeet Singh
  • Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent September 12, 2026 Bill Toulas
  • Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems September 12, 2026 djohnson
  • Behind the CAPTCHA: ClickFix, WallStealer and a Hidden Miner September 12, 2026 Ctrl-Alt-Intel
  • Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal September 11, 2026 Tim Starks
  • Hackers abused Claude to extract secrets from 1.8M Android apps September 11, 2026 Bill Toulas
  • Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device September 11, 2026
  • CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026 aws@amazon.com
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.