
Wes Lambert
Principal Engineer at Security Onion Solutions
Open source security advocate and platform integration.

I've updated the wlambert/velociraptor
@velocidex@infosec.exchange
#velociraptor Docker image to the latest release version.
https://github.com/weslambert/velociraptor-docker
This refers to the pre-built image.
If building locally, you'll always use the latest version.
Enjoy, and please let me know of any issues!
@cR0w@infosec.exchange Unfortunately, I don't think that would work for this individual, but I appreciate your response! Thanks!
What do y'all think about a #C2 detection series including #SecurityOnion and #Velociraptor, illustrating the compliments and differences of host and network-based detection and response?
#BruteRatel
#CobaltStrike
#DFIR
#ESM
#Havoc
#Infosec
#NSM
#Sliver
#Sysmon
Did anyone else play '"Pass the Pigs" as a child, or should I just go crawl into a corner 😅? https://www.amazon.com/Winning-Moves-Games-Pass-Pigs/dp/B00005JG3Y
With regard to enterprise security monitoring, many folks agree that it's best to be able to monitor from the top down, passively gathering network telemetry from a SPAN port or network TAP.
While there is ETW, Sysmon DNS and network connection logs, and more, how much of an impact has it been to not have more verbose network telemetry available during your investigations?