CVE-2020-16898 – Bad Neighbor – Monitoring By SIEM

CVE-2020-16898 – Bad Neighbor SIEM Content Packages A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. An attacker would have to send specially crafted ICMPv6 Router Advertisement […]

How to prevent your SIEM from being blind

How to prevent your SIEM from being blind Getting logs from multiple systems also requires correct permissions, network settings, proper resources, and perfect KeepAlive alerts. But what happens if something goes wrong? Apparently, the logs will not arrive. We will focus on a problem that can cause peripheral blindness with minimal effort: Disable SIEM service […]