endgameinc / eqllib

MIT License
158 stars 46 forks source link

Analytic for domain trust discovery with nltest #8

Closed ForensicITGuy closed 5 years ago

ForensicITGuy commented 5 years ago

Analytic for domain trust discovery using nltest.exe. This has been observed in Trickbot infections.