Create a Hyper-V VM with a differencing disk using PowerShell

This post cover the following: An overview of the steps to create the parent virtual disk A script to automate creation of child VMs with a differencing disk ...

August 13, 2023 · 2 min · GD

Bypassing Defender EDR using Windows Firewall - mitigations

Attackers can use Windows Firewall to block EDR telemetry leaving the endpoint. Read-on for how this is mitigated. ...

May 31, 2023 · 3 min · GD

Enable Defender Firewall event forwarding to MDE

You may notice that Windows Firewall events are not available in Defender for Endpoint Advanced Hunting. This is a quick post on the steps required to enable Firewall audit events. ...

February 2, 2023 · 3 min · GD