RLNetSec
banner
RLNetSec
@rlnetworksec.bsky.social
My views are my own and not of my employers.
DeviceProcessEvents
| where InitiatingProcessFileName =~ “wscript.exe”
| where FileName =~ “Powershell.exe”
| where ProcessCommandLine has_any(“invoke-webrequesr”,”iwr”)

looking for Wscript with a powershell childprocess to execute a payload

https://redcanary.com/blog/tax-season-phishing/
April 28, 2023 at 8:30 PM
Only just discovered Dark Mode, and must have totally forgot I had it on twitter. 😬
April 28, 2023 at 8:21 PM
Reposted by RLNetSec
New trailer coming at 12 PM PT for this extraordinary film.
April 25, 2023 at 3:59 PM
Reposted by RLNetSec
How to get invite codes on Blue Sky! (Unofficial community guide)

☁️ Watch for giveaways from community here & other socials
☁️ Create awesome & authentic content & engage the community & maybe you’ll get some in your box
☁️ Ask friends if they have extras
☁️ Kindly don’t ask team for them
☁️ Wait
April 24, 2023 at 10:04 PM