<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Detection Engineering on Matthew Green | DFIR, Threat Intelligence &amp; Research</title><link>https://dfir.au/areas/detection-engineering/</link><description>Recent content in Detection Engineering on Matthew Green | DFIR, Threat Intelligence &amp; Research</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Wed, 12 Jan 2022 00:00:00 +0000</lastBuildDate><atom:link href="https://dfir.au/areas/detection-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>WMI Event Consumers: what are you missing?</title><link>https://dfir.au/posts/2022/wmi-eventing/</link><pubDate>Wed, 12 Jan 2022 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2022/wmi-eventing/</guid><description>Find WMI event consumers that common collection methods miss, including persistence in custom namespaces. Covers collection and detection with Velociraptor.</description></item><item><title>Binary Rename 2</title><link>https://dfir.au/posts/2019/binaryrename2/</link><pubDate>Wed, 29 May 2019 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2019/binaryrename2/</guid><description>Compare YARA and PowerShell approaches to finding renamed executables on disk, with code examples and detection limitations.</description></item><item><title>Blue Team Hacks - Binary Rename</title><link>https://dfir.au/posts/2019/binaryrename/</link><pubDate>Sun, 12 May 2019 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2019/binaryrename/</guid><description>Detect renamed Windows binaries by comparing executable metadata with process names and paths. Includes a proof of concept and its limitations.</description></item><item><title>Powershell Download Cradles</title><link>https://dfir.au/posts/2018/downloadcradle/</link><pubDate>Mon, 02 Apr 2018 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2018/downloadcradle/</guid><description>Compare PowerShell download cradles and their network and endpoint traces, with test scripts to help assess detection coverage.</description></item><item><title>Blue Team Hacks - WMI Eventing</title><link>https://dfir.au/posts/2017/wmi_eventing/</link><pubDate>Mon, 03 Apr 2017 00:00:00 +0000</pubDate><guid>https://dfir.au/posts/2017/wmi_eventing/</guid><description>Use WMI event subscriptions to monitor processes and trigger file collection on older Windows systems with visibility gaps.</description></item></channel></rss>