Using Sysmon to Block Unwanted Files and Send Notifications to Slack via Scheduled Task Event Filter

Поділитися
Вставка
  • Опубліковано 18 лис 2024

КОМЕНТАРІ • 16

  • @domiflichi
    @domiflichi Рік тому

    Thanks for the video! I love how you don't edit out the problems you run into - it's very helpful to see how you work through them. Thanks again, and keep them coming!

  • @ich3aa
    @ich3aa Рік тому

    "Wait a second, it worked! It shouldn't happen !" That sums it all for me

  • @podavu7044
    @podavu7044 2 роки тому +1

    i m watching all your videos and your content is just amazing !
    thank you for the efforts that you are putting u re really helping a lot of people out there.

  • @ShahabSheikhzadeh
    @ShahabSheikhzadeh 2 роки тому

    This is the most beautiful thing I've ever seen. I love You

  • @DJ-rr7cj
    @DJ-rr7cj 2 роки тому

    This is SO COOL!

  • @kristeinsalmath1959
    @kristeinsalmath1959 2 роки тому

    This is amazing.

  • @inhhoanghai5263
    @inhhoanghai5263 2 роки тому +1

    Good Content !!!

  • @dolbysuper8563
    @dolbysuper8563 2 роки тому

    wo! thanx

  • @SomeGuyInSandy
    @SomeGuyInSandy 2 роки тому

    Awesome! Thanks!

  • @MoisheHalberstam
    @MoisheHalberstam 2 роки тому +1

    Can you Please upload the script for the slack webhook and a export from the task scheduler to GitHub?
    Id love to not have to retype the whole thing ;-}

  • @RomainRollot
    @RomainRollot 2 роки тому

    Top ! Thanks

  • @anonymoususer6801
    @anonymoususer6801 2 роки тому

    You can send any message from any user with the token not sure if that's a risk.

    • @ippsec
      @ippsec  2 роки тому

      There's no way to really get around that, it's limited to sending messages and to the channel.

  • @ratchy1231
    @ratchy1231 2 роки тому

    Is this approach vulnerable to command injection? If an attacker is capable of controlling the filename they could attempt to write to: "&& malicious_command && exit", which should also prevent the Slack notification from coming through.

    • @ippsec
      @ippsec  2 роки тому

      You should try it out. I did try it briefly and it didn't work but I didn't spend a lot of time on it.

  • @marcpascualsole7677
    @marcpascualsole7677 2 роки тому

    If YMS was a hacker, you'd have Ippsec