Azure VMs

Azure VM network concepts: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/network-overview Azure GitHub references: http://github.com/azure/azure-quickstart-templates Create VM: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/ Manage VM: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/vm-usage   Run PowerShell scripts in your Windows VM with Run Command: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/run-command Run Command uses the VM agent to run PowerShell scripts within an Azure Windows VM. These scripts can be used for general machine or application management and canContinue reading “Azure VMs”

Microsoft Message Analyzer resources

Basic network capture methods: https://blogs.technet.microsoft.com/askpfeplat/2016/12/27/basic-network-capture-methods/ Network Monitor 3.4 (Netmon) – https://www.microsoft.com/en-us/download/details.aspx?id=4865 (NOTE: Network Monitor is no longer under active development) Wireshark (v 2.2.2 as of 11/16/16) – https://wireshark.org/#download Netsh Trace – built-in to operating system Microsoft Message Analyzer (MMA) (v 1.4 as of 6/13/16) – https://www.microsoft.com/en-us/download/details.aspx?id=44226 Message analyzer operating guide: http://technet.microsoft.com/en-us/library/jj649776.aspx How to message analyzerContinue reading “Microsoft Message Analyzer resources”

How to manage Hyper-V server remotely ?

Tips and tricks to manage Hyper-V server remotely from another computer in a workgroup: In that example, the server and the client are in a workgroup. As a consequence there is no domain controller and by consequence kerberos is not possible. How to remotely manage hyper-V server from this client computer? Reference article: https://www.ivobeerens.nl/2015/08/28/manage-hyper-v-in-a-workgroup-remotely/ ConfigurationContinue reading “How to manage Hyper-V server remotely ?”

Microsoft hyper-V server 2012 R2 / 2016

Did you know that you can virtualize your Windows Server 2016 Essentials? Instead of hacking into Windows Server Essentials itself and using that as a Hyper-V host we go ahead and do it the official way and download Microsoft Hyper-V Server 2016 for free. Some administrators don’t like a server without a GUI (server core)Continue reading “Microsoft hyper-V server 2012 R2 / 2016”

How to clone a old computer (Physical to Virtual)

Here are list of technical ressources to clone an old physical server/computer to a VM: https://www.veeam.com/blog/fr/how-to-convert-physical-machine-hyper-v-virtual-machine-disk2vhd.html others: https://www.tutos-informatique.com/disk2vhd-transformer-ordinateur-physique-machine-virtuelle/ http://chrtophe.developpez.com/tutoriels/p2v/  

Free Tools for System and Network or DB Administrators

Free tools for Windows sysadmin   – Find string if files on Windows: using findstr /s /i findstr /s /i /C:”provider=sqloledb” d:\dir\*.* Find and replace string in file (Find and Replace == fnr) : http://findandreplace.io/download other tool requiring also JAVE: FAR https://sourceforge.net/projects/findandreplace/ – Test SSL and TLS: https://www.qualys.com/sslchecker _Well-known online tools for network engineers: https://dnschecker.org https://www.whois.net/ https://mxtoolbox.com/ https://whatismyipaddress.com/ http://ping-test.org/ https://www.portcheckers.com/Continue reading “Free Tools for System and Network or DB Administrators”

How to configure Windows Event forwarding (WEF) ?

Introduction: In summary: Windows Event Forwarding allows for event logs to be sent, either via a push or pull mechanism, to one or more centralized Windows Event Collector (WEC) servers. WEF is agent-free, and relies on native components integrated into the operating system. WEF is supported for both workstation and server builds of Windows. WEFContinue reading “How to configure Windows Event forwarding (WEF) ?”

Recommendations concerning NTFS cluster size

Microsoft’s file systems organize storage devices based on cluster size. Also known as the allocation unit size, cluster size represents the smallest amount of disk space that can be allocated to hold a file. Because ReFS and NTFS don’t reference files at a byte granularity, the cluster size is the smallest unit of size thatContinue reading “Recommendations concerning NTFS cluster size”

Windows forensic: Sysmon

Download sysmon: NEW: Sysmon 10.42 is available ! : https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon and how to use it: WMI detections: https://rawsec.lu/blog/posts/2017/Sep/19/sysmon-v610-vs-wmi-persistence/ MITRE framework – sysmon coverage: https://attack.mitre.org/ Installation and usage: https://github.com/olafhartong/sysmon-modular https://github.com/ion-storm/sysmon-config https://github.com/SwiftOnSecurity/sysmon-config List of web resources concerning Sysmon: https://github.com/MHaggis/sysmon-dfir Motiba: https://blogs.technet.microsoft.com/motiba/2017/12/07/sysinternals-sysmon-suspicious-activity-guide/ Sysmon events table: https://rawsec.lu/blog/posts/2017/Sep/19/sysmon-events-table/ Mark russinovitch’s RSA conference: https://onedrive.live.com/view.aspx?resid=D026B4699190F1E6!2843&ithint=file%2cpptx&app=PowerPoint&authkey=!AMvCRTKB_V1J5ow Sysmon config files explained: https://www.bsk-consulting.de/2015/02/04/sysmon-example-config-xml/ Hide sysmon fromContinue reading “Windows forensic: Sysmon”