Tales of a Blue Teamer: Detecting Powershell Empire shenanigans with Sysinternals | HoldMyBeer

https://holdmybeersecurity.com/2019/02/27/sysinternals-for-windows-incident-response/