Gábor Lázár
Monthly Adversary Tradecraft Spotlight – April 2026

Monthly Adversary Tradecraft Spotlight – April 2026

Powershell LocalAccount Manipulation The manipulation of local user accounts with PowerShell commands (related to account management operations) can occur during legitimate administrative tasks but become suspicious when they appear unexpectedly or in an unusual...

Monthly Adversary Tradecraft Spotlight – March 2026

Monthly Adversary Tradecraft Spotlight – March 2026

PowerShell Logging Disabled Via Registry Key Tampering Disabling PowerShell logging is one of the most effective ways to reduce defender visibility during an intrusion. Attackers may inspect registry keys, test execution to see what appears in the event logs, and...