Anything About IT

Learning, Building, Sharing

Setting up Kali in Windows 10 WSL 2.0

Since Microsoft introduced WSL (Windows Subsystem for Linux), many security professionals have started using Kali Linux on Windows.

Microsoft Defender Advanced Threat Protection – Respond Actions Events

Response Actions Events in Microsoft Defender Advanced Threat Protection and how to work with them.

How to identify orphan Group Policy content within the Sysvol folder

Today I was working on a Microsoft Security Configuration baseline implementation and browsing through the Sysvol folder for orphan GPO content.

How to generate a monthly Defender ATP Threat and Vulnerability Report

Microsoft has updated the Advanced Hunting Schema. Here is how to generate a monthly Defender ATP Threat and Vulnerability report.

Windows Defender, More than just Antivirus – Part 2

In this second part I cover ASR, Controlled Folder Access, Exploit Guard, and Network Protection in Windows Defender.

Microsoft Defender ATP Advanced Hunting – Who's logging on with local admin rights?

Use KQL Advanced Hunting in Microsoft Defender ATP to find out who is logging on with local administrator rights.