ELITE OFFENSIVE SECURITY COMPANYTOSHKENT / UZBEKISTAN

System administrator · IT security · DFIR

01

Configuration audit

Firewall, audit policy, GPO, Registry, PowerShell and user privileges.

02

Updates

Microsoft KB, Patch Tuesday and Windows support lifecycle.

03

Activity analysis

Services, startup entries, scheduled tasks and device events.

04

Advanced checks

Processes, network activity, suspicious memory and signs of beacon activity.

Practical outcome

Streamline repetitive manual checks and assess device health systematically.

Technical details and official links

Version 2.0.0 areas: suspicious memory regions, per-process network activity via ETW, and indicators of RDP/SMB/WinRM sessions. Findings are assessed as investigation indicators. Downloads require a registered and verified account.

  • PATH directories and environment variables; indicators associated with LOLBAS and LOLDriver/BYOVD.
  • Step-by-step GUI remediation guidance and a final security summary.
  • File and folder changes through Recurse Monitor; copy, move and delete events from the USN Journal.
  • USB device history; history clearing with confirmation and a local audit record.
Release history
CYBER-BRO / INCIDENT RESPONSE

Experiencing an incident?

Briefly describe the situation. We will review your request and contact you to agree the next steps.

Do not submit passwords or confidential files. We will agree a secure way to exchange evidence separately.

Privacy policy