May 11, 2023, 12:49 p.m. | /u/Powershillx86

cybersecurity www.reddit.com

Hello,
I am in charge of cybersecurity for a small business. lets say one of my hosts has malware on it.
The current situation: For hids I have Wazuh, sysmon and osquery all centralized in Security Onion.
I found a very suspicious named pipe, corresponding scheduled task and then finally I found a suspicious Javascript file. I want to extract this file from the host to analyze..
RDP is off the table, as I believe this would store my (hash/creds) …

analysis artifacts business current cybersecurity hello hids malware onion osquery scheduled task security sysmon task wazuh

Senior Security Engineer - Detection and Response

@ Fastly, Inc. | US (Remote)

Application Security Engineer

@ Solidigm | Zapopan, Mexico

Defensive Cyber Operations Engineer-Mid

@ ISYS Technologies | Aurora, CO, United States

Manager, Information Security GRC

@ OneTrust | Atlanta, Georgia

Senior Information Security Analyst | IAM

@ EBANX | Curitiba or São Paulo

Senior Information Security Engineer, Cloud Vulnerability Research

@ Google | New York City, USA; New York, USA