June 19, 2022, 5:33 p.m. | /u/PhoenixOfStyx

cybersecurity www.reddit.com

So, we had an incident where a Cobalt Strike Beacon was detected for one of our clients. The clean up was a serious mess, so much so that my MSP had to hire out a different company specializing in IR.

That said, the initial discovery was due to a credential dump on lsass.exe.

Afterwards, I, (an L1 Analyst) found that there was an extremely simple method to harden lsass.exe with minimal--if not 0--impact to business functioning: turning on LSA protection …

companies cybersecurity hardening

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Information Security Manager & ISSO

@ Federal Reserve System | Minneapolis, MN

Forensic Lead

@ Arete | Hyderabad

Lead Security Risk Analyst (GRC)

@ Justworks, Inc. | New York City

Consultant Senior en Gestion de Crise Cyber et Continuité d’Activité H/F

@ Hifield | Sèvres, France