Jonny Johnson
@jonny-johnson.bsky.social
📤 287
📥 13
📝 11
Principal Windows Security Researcher @HuntressLabs | Windows Internals & Telemetry Research
pinned post!
I am happy to announce JonMon2.0 has been published. 2.0 offers a lot of feature updates, as well as stability. More features still to come as time goes on. Enjoy and let me know if you have any issues or questions. Link:
github.com/jsecurity101...
8 months ago
0
0
0
Have you ever wondered if there was a way to deploy a "Remote EDR"? Today I'm excited to share research I've been working on for the past couple months. This dives into DCOM Interfaces that enable remote ETW trace sessions without dropping an agent to disk. (Write-up and project link below)
loading . . .
No Agent, No Problem: Discovering Remote EDR
As the reader, I’m sure you’re thinking — “oh great, another EDR internals or bypass post”. I can fully understand that sentiment, as…
https://jonny-johnson.medium.com/no-agent-no-problem-discovering-remote-edr-8ca60596559f
4 months ago
1
3
1
I am happy to announce JonMon2.0 has been published. 2.0 offers a lot of feature updates, as well as stability. More features still to come as time goes on. Enjoy and let me know if you have any issues or questions. Link:
github.com/jsecurity101...
8 months ago
0
0
0
New EtwInspector kinda going hard đź‘€
9 months ago
0
1
0
reposted by
Jonny Johnson
Evan McBroom
9 months ago
The perfect loader library was updated this week to support changes made on Windows 11 24H2. A big thank you to Jarrod Davis (
@tinybiggames.com
) for reporting the issue and helping work on a solution! A full writeup on the issues and fixes can be found here:
github.com/EvanMcBroom/...
loading . . .
Windows 11 24H2 · Issue #1 · EvanMcBroom/perfect-loader
Hi, will this work in windows 24H2?
https://github.com/EvanMcBroom/perfect-loader/issues/1#issuecomment-2578384262
0
6
2
Converted Matt Graeber's TraceLogging PS script into C# into the new EtwInspector.
gist.github.com/mattifestati...
Working quite well. New EtwInspector coming soon...
9 months ago
0
4
1
My goal by the end of the year was to finish JonMon 2.0 and I am happy to say that I have done that....Now just to clean up the code, fix the wiki, and write a blog. Stay tuned :)
9 months ago
0
2
0
JonMon with the AMSI logs đź‘€
10 months ago
0
1
0
Microsoft's Threat-Intelligence ETW provider now supports events to identify token impersonation attacks. I wrote a blog on these events and how Microsoft is surfacing them:
jsecurity101.medium.com/behind-the-m...
loading . . .
Behind the Mask: Unpacking Impersonation Events
Introduction
https://jsecurity101.medium.com/behind-the-mask-unpacking-impersonation-events-fca909e08d00
10 months ago
0
9
3
you reached the end!!
feeds!
log in