Sysmon
Linux Detection Opportunities for CVE-2024-29510
OverviewA remote code execution (RCE) vulnerability in the Ghostscript document conversion toolkit, identified as CVE-2024–29510, is currently being exploited in the wild. Ghostscript, which comes pre-installed on many Linux distributions, is used ...
Toolsmith Release Advisory: Sysmon v6 for Securitay
Sysmon just keeps getting better.I'm thrilled to mention that @markrussinovich and @mxatone have released Sysmon v6.When I first discussed Sysmon v2 two years ago it offered users seven event types.Oh, how it's ...

