New post by @shadowbrokerss seems to imply capability to edit event logs (EventLogEdit) - huge #DFIR implications if true!
13
99
7
105
Replying to @MalwareJake
Capability != Results. We know from the history of Unix log editing that many operators fail to do it well or completely.

Jan 8, 2017 · 12:38 PM UTC

1
1
Replying to @hal_pomeranz
isn't that the truth - and sometimes the absence of certain logs is by itself suspicious.
2
1