Phishing remains the most common method for compromising accounts. However, phishing through Google Workspace emails in a more stealthy and sophisticated manner is a story worth mentioning.
Read the story : https://t.co/cF0sGnyJY8
Following the Trail of Threat Actors in Google Workspace Audit Logs by @megan_roddie https://t.co/nxVOSwBOdI >> A great intro to the cheat sheet: https://t.co/ocpyiqiPIe
CAPA provides insights into the potential actions the program can perform. For instance, it may indicate if the file behaves as a backdoor, can install services, or communicates via HTTP.
https://t.co/Yh3uObwhWZ
#malwareanalysis#reverseengineering
The sample mentioned in the @CISACyber report AA23-339A on attacks against Adobe ColdFusion CVE-2023-26360 is ForkDump by @BillDemirkapi
- only ESET gets it right
Sample
https://t.co/dojObhUwLo
CISA report
https://t.co/neT9tchHmF
Thank you for joining us #blackhatmea2023 !
It was an absolute pleasure meeting all of you in person, and we can't wait to welcome you at more exciting events in the future.
Stay tuned for what's to come!
#CognnaAtBlackHatMEA#ThankYou
I will be one of the exhibiter for @cognna at #blackhatmea.
Visit us to explore our comprehensive range of threat management, threat detection, rapid response, and compliance assurance solutions to safeguard your organization against evolving cyber threats.
Great start to the first day of #BlackHatMEA2023! Looking forward to seeing you tomorrow for another exciting day!
ุงูุทูุงูุฉ ุฑุงุฆุนุฉ ูุฃูู ููู ูู ุจูุงู ูุงุช 2023
ููุชุธุฑูู ุจุดูู ุบุฏุง ูู ููู ุฌุฏูุฏ
You can either hunt for it or check and apply our Sigma rules
If you're unsure whether a detection idea is already covered by an existing rule, you can use the https://t.co/OnIQos7jOe, which was developed by my team member @ph_t__
We've also integrated the API of that service into the Sigma VSCode extension
If you want to test the EDR detections and correlation rules used by Blue Teams, you may need to create custom events in a specific event log.
To do this, you can use Microsoft's eventcreate utility, which lets you create specific logs at APPLICATION or SYSTEM; for Sysmon logs,