
rusty_drivers
BYOVD collection
adversarial-attackexploitationids-ips-evasion+2
252 years ago

BYOVD collection

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

CVE-2026-20685 - Draft or TODO

A slightly more fun way to disable windows defender + firewall. (through the WSC api)