As part of our commitment to keeping our customers/community protected & informed, we are releasing a blog that shines light on transition between Stage 1 and 2 of #Solorigate/#SUNBURST campaign, custom Cobalt Strike loaders, post-exploit. artifacts, IOCs: https://t.co/b0ReHMa63u
We just released Cutter v1.9 on #r2con2019 with a HUGE surprise -
a full integration of Ghidra decompiler in Cutter! 🥳
Download v1.9 with the Decompiler from https://t.co/BTHs8EYTKs
For more info, keep reading >>
5 Things ICS Operators and Critical Infrastructure Must Do in the Face of Cyber Escalation https://t.co/DtSsqO1Mvt > new blog given increased tensions and an upcoming webinar this week with advise by @cnoanalysis
This research is a good example of why memory forensics is so important.
@volatility 's ldrmodules plugin automatically reports such manipulation due to its comparison of data in the VAD vs the PEB
1/2
This malicious #Python script downloads a cross-compiler for 14 different CPU architectures to compile its backdoor!
▪️https://t.co/4pdNmemKE1
▪️https://t.co/y9cRI5qiAE
@SANSNetWars For DFIR NetWars: If (when) you get stuck on a question, don’t spend too much time banging your head against a wall. Go to a different question/domain, get some wins, and come back to the problem question later. Rabbit holes will kill you
While us slackers were sleeping, @EricRZimmerman added locked file / live response support to to AmcacheParser, AppCompatCacheParser, MFTECmd, ShellBags Explorer, SBECmd, Registry Explorer, and RECmd https://t.co/1GUT6ShsMc