Security News > 2015 > September > redblue: Empire Post-Exploitation Analysis with Rekall and PowerShell Windows Event Logs (Reddit)