Loading...

SOCpedia Blog

Security Log Event 4741. How to Detect Suspicious Computer Account Creation in Active Directory
Aug 17, 2026 AI

Security Log Event 4741. How to Detect Suspicious Computer Account Creation in Active Directory

1. Legitimate activity. Event «A computer account was created» (A computer account was created) is generated on the domain controller each time a new computer object is created in…

ShieldBreak – description of the exploitation mechanism for a SOC analyst
Aug 12, 2026 AI AI

ShieldBreak – description of the exploitation mechanism for a SOC analyst

ShieldBreak is a local privilege escalation chain to NT AUTHORITY\SYSTEM, claimed by the author to be a bypass of the fix for CVE-2026-50656 (RoguePlanet) in Microsoft Defender. F…

Show

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.