windows actually tracks everything (ft. Jonny Johnson)

MediaVideo

Check out Jonny’s work: https://github.com/jonny-jhnson/ETWInspector // https://github.com/jonny-jhnson/JonMon // https://x.com/JonnyJohnson_
He also just recently put out some AWESOME research for “Remote EDR” using this technique over DCOM: https://jonny-johnson.medium.com/no-agent-no-problem-discovering-remote-edr-8ca60596559f

Learn Cybersecurity and more with Just Hacking Training: https://jh.live/training
See what else I’m up to with: https://jh.live/newsletter
🏆Attend ContinuumCon, the practical online cybersecurity conference that never ends! Livestream begins June 20th, 2025: https://jh.live/continuumcon

ℹ️ Affiliates:
Learn how to code with CodeCrafters: https://jh.live/codecrafters
Host your own VPN with OpenVPN: https://jh.live/openvpn
Get Blue Team Training and SOC Analyst Certifications with CyberDefenders: https://jh.live/cyberdefense
Master Binary Files and Protocols with Gynvael Coldwind: https://jh.live/hackarcana (code MBF-JH-10 gives 10% off!)John HammondRead More