Tools: mimikatz
video
mimikatz RPC Mode
Tools: mimikatz
mimikatz & Protected Processes
Tools: mimikatz
Select Parent Process From VBA
Blog post: Select Parent Process from VBA
mimikatz & minesweeper
Tools: mimikatz
mimikatz & !bsod
Tools: mimikatz
Ransomware: Very Simple IOC Extraction
xor-kpa.py Version 0.0.5
Tools: xor-kpa.py
WannaCry: Simple File Analysis
Malicious Documents: The Matryoshka Edition
Blog post: Malicious Documents: The Matryoshka Edition
Tools: pdf tools, oledump.py, re-search.py
Sample: 98a727a32fee7115d9599b4df9b6b433