Microsoft Sysmon adds support for detecting Process Herpaderping attacks
The Sysinternals package comes with more than 160 different apps, each useful for a particular task. One of the most widely used Sysinternal apps is called Sysmon, or System Monitor, which works by logging system-level events (process creations, network connections, and changes to file creation time) to the default Windows event log. Across the years, the tool has become a must-have for all security researchers, either if theyre involved in defending networks or performing digital forensics an...
Source: zdnet.com