{"id":1356,"date":"2021-01-12T05:01:16","date_gmt":"2021-01-12T05:01:16","guid":{"rendered":"http:\/\/people.utm.my\/azhari\/?p=1356"},"modified":"2021-01-12T05:01:17","modified_gmt":"2021-01-12T05:01:17","slug":"combatting-ransomware-and-apt-activity-with-process-level-monitoring","status":"publish","type":"post","link":"https:\/\/people.utm.my\/azhari\/2021\/01\/12\/combatting-ransomware-and-apt-activity-with-process-level-monitoring\/","title":{"rendered":"Combatting ransomware and APT activity with process-level monitoring"},"content":{"rendered":"\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Dan Crossley, Sales Engineering Manager, LogRhythm and Imran Hafeez, LogRhythm Analytic Co-Pilot Consultant<br>Live online January 13 at 10:00 a.m<\/td><\/tr><tr><td><a href=\"http:\/\/links.brighttalk.com\/ls\/click?upn=F9a1AJELHycUugtazuN-2B5QbIPoHJK11l4HsukfvOw5PTqdZ1mLDj6foUcrIVQgqjR6vtjegUmIKOBIeV82OcMOwC3KFSx8t4ih-2BURJwZOx2d-2BBcXlRQbC1zfkkab9CAci-2F27WTr54-2Fl50lZJCjiM6js4mxiFbWPJ4f7R23NGieFEj9XbBpradjsPC1KB4YrbDk0y9EvmEc26mAjS5UTs55sf66s-2BQRRKIBAGx4bH4F101qWYodEHWnzdNtSDDULvsQXh-2FFIcB-2FwjmtLKw1fRJYauZ6TNri51URuLMrFVMn5JKLpkra4Hu7-2BXl1WoAkK2Iz4X_nMamZx30p576MaBj2xurswHhkbrsxOMQCMIS8IxdFc1ifiBH6pzSFxOUNBLHYedvn71SwSweaehANIHDcQ-2FUcoBY2bU8hRNFFj7DK3cUdv9rdKEt3UlsGiTX1P5wv7w5j5htccgEbzboNu9oewL0lO2eZPKn-2Fp-2FL-2BN9tg3jTYgdahUrK5r42DJELZaIz9KOnFLlB7I63OXh-2Fz9fnpfeNF4qj9SbSabdpGcmuBLcKgA8eJwrEou6MT4C-2BXl4HqXHKdOaMXJl63KDuqKXLEddn7JtQPV-2BJgimic7esn9Ev2pWLPzV7jRSdg7DY26k58s-2Ba2h2gFdcNyJekSajjhxxhuiV6MBSnNpDTpnW8P0Vscp7TQL1Oxzn0gQgI9PKMyMSmv23AQ6eqjeem2BFj3EvQcPymYNNCNvaeJKVQnjpmaa-2FS-2FiUWp76jXfO3GFrpCO8nh0lF5qTUzEfXTH09tkcS2Q-3D-3D\" target=\"_blank\" rel=\"noreferrer noopener\">Click here to register<\/a><\/td><\/tr><tr><td>Ransomware has evolved from a commodity malware strain primarily targeting home users, to a devastating and effective tool in the arsenal of advanced threat groups. As these human-operated cyberattacks continue to be a lucrative source of income for threat actors, ransomware will continue to pose a major threat to many organisations.<br><br>Dan Crossley, Sales Engineering Manager, LogRhythm and Imran Hafeez, LogRhythm Analytic Co-Pilot Consultant, discuss:<br><br>\u2022 The anatomy of a human operated ransomware attack<br>\u2022 What additional log data can be enabled within a Windows environment to allow better tracing of threat actor activity, including:<br>o Process creation with command-line execution<br>o PowerShell logging<br>o Microsoft Sysmon<\/td><\/tr><\/tbody><\/table><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Dan Crossley, Sales Engineering Manager, LogRhythm and Imran Hafeez, LogRhythm Analytic Co-Pilot ConsultantLive online January 13 at 10:00 a.m Click here to register Ransomware has evolved from a commodity malware strain primarily targeting home users, to a devastating and effective tool in the arsenal of advanced threat groups. As these human-operated cyberattacks continue to be [&hellip;]<\/p>\n","protected":false},"author":14428,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[10],"tags":[],"class_list":["post-1356","post","type-post","status-publish","format-standard","hentry","category-gallery"],"_links":{"self":[{"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/posts\/1356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/users\/14428"}],"replies":[{"embeddable":true,"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/comments?post=1356"}],"version-history":[{"count":1,"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/posts\/1356\/revisions"}],"predecessor-version":[{"id":1357,"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/posts\/1356\/revisions\/1357"}],"wp:attachment":[{"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/media?parent=1356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/categories?post=1356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/people.utm.my\/azhari\/wp-json\/wp\/v2\/tags?post=1356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}