Skip to content
CyberSecThreat_logo
  • Home
  • Our ServicesExpand
    • Free Degaussing & Data Destruction of Magnetic-Only Hard Disk Drive Program
    • NextGen IT Asset Disposition (ITAD)
    • Data Destruction Service – APJ
    • Data Disposal Service – Taiwan
    • vCISO (Virtual CISO) Services
    • Data Recovery
    • OSCP
  • ProductsExpand
      • CYBERSECURITY
      • DATA DISPOSAL
      • DIGITAL FORENSICS

      CYBERSECURITY


      Mobile App Security

      Appdome Logo
      Appdome Logo

      Security Awareness Training

      AKO Labs CyberSecurity Training
      AKO Labs

      SOAR

      Swimlane-Incident-Dashboard
      Swimlane Turbine – AI Enabled Automation Platform

      Cyber Threat Intelligence

      Recorded Future Intelligence Cloud
      Recorded Future Intelligence Cloud – GPT Powered CTI

      DATA DISPOSAL


      Media Shredder/Destroyer

      Server Hard Disk Shredder
      Server Hard Disk Shredder

      Degauss Verification

      Patented Degauss Verification Magnetic Sticker
      Patented Degauss Verification Magnetic Sticker

      Degausser

      NSA Degausser
      NSA Degausser

      Duplicator & Wiper

      YEC Demi
      YEC Demi

      DIGITAL FORENSICS


      Computer Forensics

      TALINO Forensic Workstation
      TALINO Forensic Workstation

      Mobile Forensics

      MD-NEXT
      MD-NEXT

      CyberSecurity

      Cryptocurrency Intelligence Platform
      Cryptocurrency Intelligence Platform

      Public Security & Intelligence Solutions

      BTS Tracker
      BTS Tracker
  • ResourcesExpand
    • Blog
    • Vulnerability Research
    • Free ToolsExpand
      • Splunk
  • CompanyExpand
    • About CyberSecThreat
    • News
    • Contact Us
    • About Founder
    • ISO27001 ISMS Policy
  • zh_TW繁體中文
CyberSecThreat_logo
  • forward rules powershell IncludeHidden
    Blue Team | Incident Response | PowerShell | Red Team | Splunk | Threat Hunting

    Detect hidden inbox forward rule in On-Premise Exchange

    ByKelvin Yip July 8, 2020April 1, 2024

    In many of exchange email account compromise case investigation, attacker trends to add an inbox rule and forward victims’s email to an email account under attacker’s control. In order to make the victim(s) even harder to detect the forward rules, attacker use some more advance technique to hide the forward rules.
    There are different research articles discussing hidden inbox forward rule on O365 including Compass Security, Matthew Green and GCITS. That’s why we will discuss it for On-Premise Exchange such as Exchange 2013, 2016 & 2019.

    Read More Detect hidden inbox forward rule in On-Premise ExchangeContinue

  • MSSQL EventCode 18453
    Privileged Account Monitoring | Splunk

    Monitor MSSQL authentication with Splunk

    ByKelvin Yip July 8, 2020April 1, 2024

    Some MSSQL instance by default using “Network Service” to start MSSQL service. It will automatically generate both successful and failure logon from this account. It is advise not to explicit grant database permission to this service account, and monitoring other privilege account with database access.

    Read More Monitor MSSQL authentication with SplunkContinue

  • Splunk EventCode 4662 with ms-Mcs-AdmPwd
    Splunk

    LAPS logging and Splunk

    ByKelvin Yip July 8, 2020February 25, 2024

    When I try to search it in Splunk, nothing comes out!! According to Splunk, Event Code 4662 is too noisy, and Splunk gives an example to filter all Event Code 4662. I realize I use the sample inputs.conf from Splunk. Below is snippet of default inputs.conf.

    It took me a couple of days trying many combination of inputs.conf, and finally I figure out the correct syntax.

    Read More LAPS logging and SplunkContinue

Page navigation

Previous PagePrevious 1 … 3 4 5 6 7 Next PageNext
CyberSecThreat Logo

ISO/IEC 27001:2013 (ARES/TW/I2208053I)

Twitter Linkedin Github YouTube Facebook Email
  • zh_TW繁體中文

Products

  • CyberSecThreat website logo S/N Scanner: OCR & Barcode
  • Intezer Logo Intezer - AI Powered Autonomous SOC Platform
  • AUTOCRYPT Logo AUTOCRYPT
  • Appdome Logo Appdome
  • Kount - an Equifax Company Logo Kount
  • AKO Labs CyberSecurity Training AKO Labs NT$9,999,999.00
  • Photo that demonstrates our Patented Degauss Verification Magnetic Sticker Patented Degauss Verification Magnetic Sticker NT$65.00 Original price was: NT$65.00.NT$58.00Current price is: NT$58.00.
  • CyberSecThreat Swimlane Logo Swimlane Turbine - AI Enabled Automation Platform

Services

  • Free Degaussing & Data Destruction of Magnetic-Only Hard Disk Drive Program
  • NextGen IT Asset Disposition (ITAD)
  • Data Destruction Service – APJ
  • Data Disposal Service – Taiwan
  • vCISO (Virtual CISO) Services
  • Data Recovery
  • OSCP

Resources

  • Blog
  • Vulnerability Research
  • Free Splunk Apps

Company

  • About CyberSecThreat
  • News
  • Contact Us
  • About Founder
  • ISO27001 ISMS Policy

© COPYRIGHT 2026 - CYBERSECTHREAT CORPORATION LIMITED. ALL RIGHTS RESERVED.

Scroll to top
  • Home
  • Services
    • Free Degaussing & Data Destruction of Magnetic-Only Hard Disk Drive Program
    • NextGen IT Asset Disposition (ITAD)
    • Data Destruction Service – APJ
    • Data Disposal Service – Taiwan
    • vCISO (Virtual CISO) Services
    • Data Recovery
    • OSCP
  • Products
    • CyberSecurity
      • Cyber Threat Intelligence
      • SOAR
      • Security Awareness Training
      • Visionary Defense
    • DATA DISPOSAL
      • Media Shredder/Destroyer
      • Degauss Verification
      • Degaussers
      • Duplicator & Wiper
    • DIGITAL FORENSIC
      • Computer Forensics
      • Mobile Forensics
      • Cyber Security
      • Public Security & Intelligence Solutions
  • Resources
    • Blog
    • Vulnerability Research
    • Free Tools
      • Splunk Apps
  • Company
    • About Us
    • News
    • Contact Us
    • About Founder
    • ISO27001 ISMS Policy
  • zh_TW繁體中文
Search