Mitigating CVE-2022-29072 (7-zip) with MEM

Mitigating CVE-2022-29072 (7-zip) with MEM

Just last week, a new vulnerability was identified in the 7-zip application with ID ‘CVE-2022-29072’. This vulnerability allows for local privilege escalation due to a misconfiguration of the 7z.dll file. By exploiting this vulnerability, a user can receive local...
Ollie, your personal Microsoft Sentinel assistant

Ollie, your personal Microsoft Sentinel assistant

At The Collective, we are constantly looking to innovate and push the boundaries of the existing (Microsoft) capabilities. For the 2021 Microsoft Sentinel Hackathon, we developed an assistant for Microsoft Sentinel which will ease the day-to-day management of the SIEM...
Mitigate HiveNightmare with MEM

Mitigate HiveNightmare with MEM

It’s been only three weeks since the PrintNightmare debacle, which introduced several zero-days into the world of Microsoft affecting all Windows Operating Systems. Since my blog post on this mitigation, several other zero-days related to print spoolers have also...
Mitigate Printer Nightmare with MEM

Mitigate Printer Nightmare with MEM

Unless you have been living underneath a rock these last few days, you probably have heard of the ‘Printer Nightmare’ vulnerability. This is an unpatched exploit which affects all version of Windows. On July 6th, an out-of-band update was released by Microsoft that...