Exports Critical Registry Keys To a File The Windows Registry stores a significant amount of operating system and security information. The SAM (Security Account Manager) hive contains local account password hashes, the SYSTEM hive contains the boot key required to...
Monthly Adversary Tradecraft Spotlight – July
Potential MSTSC Shadowing Activity MSTSC shadowing is an attractive technique because it allows attackers to interact with an already authenticated user session without needing to steal credentials or create a new login event. Once an attacker has gained sufficient...
Monthly Adversary Tradecraft Spotlight – June
OpenWith.exe Executes Specified Binary This technique leverages OpenWith.exe as a proxy execution mechanism to run arbitrary code while blending in with legitimate system activity. It is a trusted Windows binary that is typically used when a user selects “Open with…”...
Monthly Adversary Tradecraft Spotlight – May 2026
Windows Recovery Environment Disabled Via Reagentc WinRE exists specifically to help users repair boot problems, restore previous system states, and troubleshoot failures when Windows can no longer start normally. Disabling the Windows Recovery Environment (WinRE) is...
Monthly Adversary Tradecraft Spotlight – April 2026
Powershell LocalAccount Manipulation The manipulation of local user accounts with PowerShell commands (related to account management operations) can occur during legitimate administrative tasks but become suspicious when they appear unexpectedly or in an unusual...






