#OneNote has become a fixture of recent malware delivery campaigns, with Initial Access Broker kingpins such as #Qakbot, #IcedID, and more getting in on the action.
Get up to speed: Who's abusing it and how to mitigate them - it's all here: https://t.co/bWY0GjXAQJ
#malware#soc
Kevin Mandia was reversing Turla malware when I was in high school. Lots of us cut our teeth on them in the early 2000s. These guys operate low and slow and they always seem to be in the background grinding away.
🚨Malware Tips 🚨 - Resolving API Hashes Using Conditional Breakpoints.
By adding breakpoints and log conditions to a function that resolves api hashes, it's possible to quickly resolve api hashes in bulk.
Thread
[1/11] 👇
#Malware#AgentTesla#Ghidra#Debugging
Death by a thousand PaperCuts, China's APT41 uses new tricks to skirt EDR, and a pair of no-patch vulnerabilities take the front page in this weeks newsletter:
https://t.co/WkuA34p4jL
#cyber#infosec#news#newsletter#hacking#malware#vulnerability
@elasticseclabs have also outdone themselves last week, releasing a suite of tools to decrypt, decompress, recompile, extract and/or parse various #malware payloads distributed in recent #IcedID campaigns.
@Kostastsale@ateixei Amazing work guys, thanks so much for sharing this with the community 🙏🏻
Have you thought about using Mitre Data Sources as the framework to map telemetry coverage, especially if integration with D3FEND and ATT&CK is on the cards?
https://t.co/GEExIsnuwU
The #blueteam have a script to help tweak VM settings to circumvent malware anti-analysis checks; Procmon for macOS, and a lightweight bastion host to help redirect and record traffic sent to #honeypots in your network.
Get amongst it!
https://t.co/c09RZB9sDB
The #redteam have a new port of the SharpHound AD enumeration tool for #CobaltStrike; a great reference piece on leveraging stolen Office tokens to bypass #MFA and access cloud workloads, and a list of keywords to avoid when crafting stealthy #PowerShell scripts.