SOC+UEBA:从关联规则到用户实体行为分析的运营思路分享
结合腾讯SOC在客户侧的运营实践,本文首先介绍安全运营在业界落地中普遍遇到的问题,并分享腾讯SOC在解决该问题时的思路和工作。
This is a guest post DEVCORE collaborated with Zero Day Initiative (ZDI) and published at their blog, which describes the exploit chain we demonstrated at Pwn2Own 2021! Please visit the following link to read that :)
If you are interesting in more Exchange Server attacks, you can also check our series of articles:
With ProxyShell, an unauthenticated attacker can execute arbitrary commands on Microsoft Exchange Server through an exposed 443 port! Here is the demonstration video: