Archive

BianLian GOs for PowerShell After TeamCity Exploitation

March 8, 2024 Contributors: Justin Timothy, Threat Intelligence Consultant, Gabe Renfro, DFIR Advisory Consultant, Keven Murphy, DFIR Principal Consultant Introduction Ever since Avast released a decr…

How to Peel a PowerShell Onion: A Bloodhound Case Study

Published May 2, 2022 Introduction Recently the GuidePoint Security DFIR team was called in to conduct an investigation for a Managed Service Provider (MSP).