[{"id":4205,"link":"https:\/\/modware.blue\/?p=4205","name":"ecir-review-%d8%aa%d8%ac%d8%b1%d8%a8%d8%aa%d9%8a-%d8%a7%d9%84%d8%b4%d8%ae%d8%b5%d9%8a","thumbnail":{"url":"https:\/\/modware.blue\/wp-content\/uploads\/2022\/12\/eCIR-pdf.jpg","alt":""},"title":"eCIR Review | \u062a\u062c\u0631\u0628\u062a\u064a \u0627\u0644\u0634\u062e\u0635\u064a\u0629","excerpt":"","content":"\u0627\u0644\u0645\u0642\u062f\u0645\u0629 \u0645\u0627\u0647\u064a \u0634\u0647\u0627\u062f\u0629 \u0627\u0644\u0640eCIR \u061f \u0627\u0644\u062f\u0648\u0631\u0629 \u062a\u0642\u0633\u064a\u0645 \u0627\u0644\u062f\u0648\u0631\u0629 \u0637\u0631\u064a\u0642\u062a\u064a \u0641\u064a \u0627\u0644\u062f\u0631\u0627\u0633\u0629 \u0647\u0644 \u0627\u0644\u062f\u0648\u0631\u0629 \u062a\u0643\u0641\u064a\u061f \u0627\u0644\u0627\u062e\u062a\u0628\u0627\u0631 \u0637\u0631\u064a\u0642\u0629 \u0627\u0644\u0627\u062e\u062a\u0628\u0627\u0631 \u0637\u0631\u064a\u0642\u062a\u064a \u0644\u0644\u062a\u062c\u0647\u064a\u0632 \u0644\u0644\u0625\u062e\u062a\u0628\u0627\u0631 \u0646\u0635\u0627\u0626\u062d \u0644\u0644\u0627\u062e\u062a\u0628\u0627\u0631 \u062a\u0645\u0628\u0644\u062a \u0627\u0644\u0627\u062e\u062a\u0628\u0627\u0631 \u0627\u0644\u062e\u0627\u062a\u0645\u0629","author":{"name":"Modware","link":"https:\/\/modware.blue\/?author=2"},"date":"Dec 20, 2022","dateGMT":"2022-12-20 13:28:30","modifiedDate":"2022-12-26 13:45:02","modifiedDateGMT":"2022-12-26 13:45:02","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/modware.blue\/?cat=33\" rel=\"category\">Review<\/a>","space":"<a href=\"https:\/\/modware.blue\/?cat=33\" rel=\"category\">Review<\/a>"},"taxonomies":{"post_tag":""},"readTime":{"min":3,"sec":54},"status":"publish"},{"id":4162,"link":"https:\/\/modware.blue\/?p=4162","name":"command-and-scripting-interpreter-powershell-t1059-001","thumbnail":{"url":"https:\/\/modware.blue\/wp-content\/uploads\/2022\/12\/Command-and-Scripting-Interpreter-PowerShell-\u2013-T1059.001-1.png","alt":""},"title":"Command and Scripting Interpreter: PowerShell \u2013 (T1059.001)","excerpt":"","content":"\u0627\u0644\u062a\u0643\u0646\u064a\u0643 \u0627\u0644\u0623\u0643\u062b\u0631 \u0634\u064a\u0648\u0639\u064b\u0627 \u0641\u064a \u0627\u0644\u0639\u0627\u0644\u0645 \u0648 \u0644\u0644\u0639\u0627\u0645 \u0627\u0644\u062b\u0627\u0646\u064a \u0639\u0644\u0649 \u0627\u0644\u062a\u0648\u0627\u0644\u064a \u062d\u0633\u0628 \u062a\u0642\u0631\u064a\u0631 \"RedCanary\" \u0627\u0644\u0633\u0646\u0648\u064a 2022\u0648\u0630\u0644\u0643 \u0644\u0633\u0647\u0648\u0644\u062a\u0647 \u0641\u064a \u062a\u062e\u0637\u064a \u0627\u0644\u062d\u0645\u0627\u064a\u0627\u062a \u0628\u0633\u0628\u0628 \u0627\u0646\u062f\u0645\u0627\u062c\u0647 \u0645\u0639 \u0646\u0634\u0627\u0637 \u0627\u0644\u0646\u0638\u0627\u0645 \u0627\u0644\u0637\u0628\u064a\u0639\u064a","author":{"name":"Modware","link":"https:\/\/modware.blue\/?author=2"},"date":"Dec 17, 2022","dateGMT":"2022-12-17 10:52:54","modifiedDate":"2022-12-30 10:26:37","modifiedDateGMT":"2022-12-30 10:26:37","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/modware.blue\/?cat=34\" rel=\"category\">APT<\/a>, <a href=\"https:\/\/modware.blue\/?cat=35\" rel=\"category\">Technique<\/a>","space":"<a href=\"https:\/\/modware.blue\/?cat=34\" rel=\"category\">APT<\/a> <a href=\"https:\/\/modware.blue\/?cat=35\" rel=\"category\">Technique<\/a>"},"taxonomies":{"post_tag":""},"readTime":{"min":4,"sec":16},"status":"publish"},{"id":4117,"link":"https:\/\/modware.blue\/?p=4117","name":"%d8%aa%d8%ac%d8%b1%d8%a8%d8%aa%d9%8a-%d8%a7%d9%84%d8%b4%d8%ae%d8%b5%d9%8a%d8%a9-ecthpv2","thumbnail":{"url":"https:\/\/modware.blue\/wp-content\/uploads\/2022\/09\/New-Project.png","alt":""},"title":"\u062a\u062c\u0631\u0628\u062a\u064a \u0627\u0644\u0634\u062e\u0635\u064a\u0629 | eCTHPv2","excerpt":"","content":"\u0641\u064a \u0647\u0630\u0647 \u0627\u0644\u0645\u0642\u0627\u0644\u0629 \u0631\u0627\u062d \u0627\u062c\u0627\u0648\u0628 \u0639\u0644\u0649 \u0627\u0643\u062b\u0631 \u0627\u0644\u0623\u0633\u0626\u0644\u0629 \u0627\u0644\u064a \u0648\u0635\u0644\u062a\u0646\u064a \u0639\u0646 \u0627\u062e\u062a\u0628\u0627\u0631 \u0634\u0647\u0627\u062f\u0629 eCTHPv2 \u0645\u0627\u0647\u064a \u0634\u0647\u0627\u062f\u0629 \u0627\u0644\u0640eCTHPv2 \u061f \u062a\u0642\u0633\u064a\u0645 \u0627\u0644\u0643\u0648\u0631\u0633 \u0647\u0644 \u0627\u0644\u062f\u0648\u0631\u0629 \u062a\u0643\u0641\u064a\u061f \u0648\u0643\u064a\u0641 \u0623\u062a\u062c\u0647\u0632","author":{"name":"Modware","link":"https:\/\/modware.blue\/?author=2"},"date":"Sep 23, 2022","dateGMT":"2022-09-23 10:40:07","modifiedDate":"2022-12-30 10:27:39","modifiedDateGMT":"2022-12-30 10:27:39","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/modware.blue\/?cat=33\" rel=\"category\">Review<\/a>","space":"<a href=\"https:\/\/modware.blue\/?cat=33\" rel=\"category\">Review<\/a>"},"taxonomies":{"post_tag":""},"readTime":{"min":4,"sec":9},"status":"publish"},{"id":4050,"link":"https:\/\/modware.blue\/?p=4050","name":"4050","thumbnail":{"url":"https:\/\/modware.blue\/wp-content\/uploads\/2022\/08\/New-Project3.jpg","alt":""},"title":"\u0627\u0644\u062f\u0644\u064a\u0644 \u0627\u0644\u0639\u0631\u0628\u064a \u0644\u0640 Sigma Rule","excerpt":"","content":"\u0644\u0643\u0644 SIEM Solution \u0635\u064a\u063a\u0629 \u0643\u062a\u0627\u0628\u0629 \u0645\u062e\u0635\u0635\u0629, \u0641\u0643\u064a\u0641 \u064a\u0633\u062a\u0637\u064a\u0639 \u0623\u064a \u0634\u062e\u0635 \u0623\u0633\u062a\u062e\u062f\u0627\u0645 Query \u0641\u064a \u0623\u0643\u062b\u0631 \u0645\u0646 SIEM Solution \u0628\u062f\u0648\u0646 \u0625\u0639\u0627\u062f\u0629 \u0635\u064a\u0627\u063a\u062a\u0647\u0627 \u0641\u064a \u0643\u0644 \u0645\u0631\u0647 \u061f \u0645\u0642\u0627\u0644\u0646\u0627","author":{"name":"Modware","link":"https:\/\/modware.blue\/?author=2"},"date":"Aug 14, 2022","dateGMT":"2022-08-14 16:11:23","modifiedDate":"2022-12-30 10:28:35","modifiedDateGMT":"2022-12-30 10:28:35","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/modware.blue\/?cat=36\" rel=\"category\">Tools<\/a>","space":"<a href=\"https:\/\/modware.blue\/?cat=36\" rel=\"category\">Tools<\/a>"},"taxonomies":{"post_tag":""},"readTime":{"min":2,"sec":9},"status":"publish"},{"id":223,"link":"https:\/\/modware.blue\/?p=223","name":"ads","thumbnail":{"url":"https:\/\/modware.blue\/wp-content\/uploads\/2022\/07\/My-project-1-1.png","alt":""},"title":"Alternative Data Streams (ADS)","excerpt":"","content":"\u0645\u0646\u0637\u0642\u0629 \u0645\u0648\u062c\u0648\u062f\u0629 \u0641\u064a \u062c\u0645\u064a\u0639 \u0627\u0644\u0645\u0644\u0641\u0627\u062a \u0648\u064a\u0645\u0643\u0646 \u0644\u0635\u0627\u0646\u0639\u064a \u0627\u0644\u0645\u0627\u0644\u0648\u064a\u0631 \u0627\u0644\u0627\u0633\u062a\u0641\u0627\u062f\u0629 \u0645\u0646\u0647\u0627 \u0648\u0643\u062a\u0627\u0628\u0629 \u0627\u062c\u0632\u0627\u0621 \u0645\u0646 \u0627\u0644\u0645\u0627\u0644\u0648\u064a\u0631 \u0628\u0647\u0627 \u0645\u0627\u0647\u064a\u061f \u0643\u064a\u0641\u064a\u0629 \u0627\u0644\u0643\u062a\u0627\u0628\u0629 \u0639\u0644\u064a\u0647\u0627\u061f \u0648\u0643\u064a\u0641 \u064a\u0645\u0643\u0646 \u0643\u0634\u0641\u0647\u0627\u061f \u0645\u0642\u0627\u0644\u062a\u0646\u0627 \u0627\u0644\u064a\u0648\u0645 \u0639\u0646 Alternative","author":{"name":"Modware","link":"https:\/\/modware.blue\/?author=2"},"date":"Jul 21, 2022","dateGMT":"2022-07-21 15:09:02","modifiedDate":"2022-12-30 10:29:12","modifiedDateGMT":"2022-12-30 10:29:12","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/modware.blue\/?cat=35\" rel=\"category\">Technique<\/a>","space":"<a href=\"https:\/\/modware.blue\/?cat=35\" rel=\"category\">Technique<\/a>"},"taxonomies":{"post_tag":""},"readTime":{"min":1,"sec":57},"status":"publish"}]