It is possible as a low privileged user to parse the Windows event logs for any ASR exclusionhttps://primusinterp.com/posts/WindowsASR/#infosec #cybersecurity #redteam #pentest
The Live Terminal feature of Cortex XDR can be abused by attackers as a pre-installed, EDR-trusted C2 channelhttps://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2#infosec #cybersecurity #redteam #pentest