Hey There,
Bit of a long shot but are there dedicated guides for hunting specific red team tools? I'm thinking of tools like PingCastle, Empire etc. Ideally, it would cover things like the artefacts which they may generate on the machine (event IDs, sysmon events, named pipes etc) and other file events to look out for.
I've seen guides around PSExec and also Cobalt strike but has this been created for other tools?