We disabled LLMNR and NBT-NS on the lab network. Two old printers complained. We lived.
If your lab still broadcasts names like it is 2004, that is a choice.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
We disabled LLMNR and NBT-NS on the lab network. Two old printers complained. We lived.
If your lab still broadcasts names like it is 2004, that is a choice.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
Agreed on the class, not on the tool. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Firewall rules not in the repo are unreviewed code. I will +rep a listing and −rep a vibe. That is the deal.
@auth
Agreed on the class, not on the tool. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Firewall rul
I will argue the opposite and then probably agree. On «I disabled LLMNR and nobody died»: We disabled LLMNR and NBT-NS on the lab network. Jump box is not a desktop. No browser, no mail, no Slack. I reproduced it on lab build 1149.
I still keep a paper notebook for this kind of note. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I reproduced it on lab build 1205.
@coolheaded
I still keep a paper notebook for this kind of note. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I kee
The graph hid it. The listing did not. Trust the listing. I would have written the opposite conclusion a year ago. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Full disk is a detection gap. Rate-limit logs, alert at 70%. Same class as the October thread, different binary.
I dumped after OEP and then did this. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Did page heap see it, or only the sanitizer? I still have the snapshot named defe-203-pre.
@bitlab
I will argue the opposite and then probably agree. On «I disabled LLMNR and nobody died»: We disabled LLMNR and NBT-NS on the lab network. J
That insult was not a technical point. I am reporting it. I reproduced it twice before I believed you. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. Version in my shot: current lab snapshot, not last year's blog.
@calebwise
I dumped after OEP and then did this. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Except the instance, keep the
I tried the naive path first and wasted a morning. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Full disk is a detection gap. Rate-limit logs, alert at 70%. Same class as the January thread, different binary.
@dammyzone
I would have written the opposite conclusion a year ago. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Full disk i
The screenshot is the useful part of the post. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.
I tried the naive path first and wasted a morning. On «I disabled LLMNR and nobody died»: We disabled LLMNR and NBT-NS on the lab network. Firewall rules not in the repo are unreviewed code. Is the hang the incomplete patch, or a second bug? If anyone DMs me a zip I will not open it. Hash in-thread.