⤷ Title: Stop Spoofing Yourself! Disabling M365 Direct Send
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #Patterson Cake #evtx #hayabusa #SOF_ELK
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #Patterson Cake #evtx #hayabusa #SOF_ELK
Black Hills Information Security, Inc.
Stop Spoofing Yourself! Disabling M365 Direct Send - Black Hills Information Security, Inc.
Remember the good ‘ol days of Zip drives, Winamp, the advent of “Office 365,” and copy machines that didn’t understand email authentication? Okay, maybe they weren’t so good! For a […]
⤷ Title: Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 1)
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 14:09:33 +0000
════════════════════════
⌗ Tags: #Blue Team #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 14:09:33 +0000
════════════════════════
⌗ Tags: #Blue Team #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
Black Hills Information Security, Inc.
Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 1) - Black Hills Information Security, Inc.
In part 1 of this post, we’ll discuss how Hayabusa and “Security Operations and Forensics ELK” (SOF-ELK) can help us wrangle EVTX files (Windows Event Log files) for maximum effect during a Windows endpoint investigation!
⤷ Title: Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2)
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #How_To #Hunt Teaming #Incident Response #Informational #InfoSec 201 #evtx #hayabusa #SOF_ELK
Black Hills Information Security, Inc.
Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2) - Black Hills Information Security, Inc.
But what if we need to wrangle Windows Event Logs for more than one system? In part 2, we’ll wrangle EVTX logs at scale by incorporating Hayabusa and SOF-ELK into my rapid endpoint investigation workflow (“REIW”)!