The National Operations Department (NOA) of the Swedish police has visited Mullvad VPN with a search warrant, with the intention to seize computers with customer data. No customer data was compromised. https://t.co/bMpPRNz88N
Happy to share my first blog as part of @wiz_io 🪄🧙
Cloud is complex and so it's attack surface. If you are interested in learning about #cloudforensics I recommend reading this!
https://t.co/NcbGTkPtlQ
More car hacking!
Earlier this year, we were able to remotely unlock, start, locate, flash, and honk any remotely connected Honda, Nissan, Infiniti, and Acura vehicles, completely unauthorized, knowing only the VIN number of the car.
Here's how we found it, and how it works:
GIVEAWAY: y’all are always asking for technical training to upscale your digital forensics skills - well now’s your chance! i’m giving away 5 FREE windows forensics courses. just follow @bluecapesec and retweet this to enter! winners announced the 28th!
https://t.co/7N25aAk4R1
Here is our technical deep dive for the #Fortinet CVE-2022-40684 Auth Bypass. POC within.
This year has been filled with interesting HTTP header abuse!
https://t.co/gkg6F7vh2n
With reports of #Fortinet CVE-2022-40684 being exploited in the wild, we have detailed some early Indicators of Compromise in the following blog to help organizations assess their environments.
https://t.co/If9AJzubqg
We just released a new version of DeTT&CT including ATT&CK Mobile support! Thanks to the Dutch National Police who sponsored this!
Checkout this new version! https://t.co/ItfEnz6x12
Fox-IT just open sourced their enterprise forensics tooling dissect. This is a big project that some of the smartest people I know have worked on. It supports many filesystems and file formats, all as Python libraries. Docs: https://t.co/M6YAygmW3E / code: https://t.co/HKT4eYIm1a
Attacker recently gained access to a victim's external DNS provider, changed passwords and deleted all records. Account recovery failed because....there were no MX records anymore to be able to receive the recovery emails...
5⃣ - Anatomy of a SIGMA rule - Sigma is another great tool that will help you hunt your logs. While Yara is for file, Sigma is for logs. ⚒️ #sigmarule#infosec
4⃣ - Anatomy of a YARA rule - Once you have gained more knowledge of threat intelligence concepts and methodologies, learning to use YARA rules can be very powerful for your threat hunting abilities!🛠️ #yararules#threathunting
15 members of REvil has been arrested by the Russian authorities.
REvil, once dubbed the "Crown prince of Ransomware", was responsible for the Kaseya supply chain attack, and many other high-profile breaches.
Footage courtesy of the FSB.
If you rename procdump.exe to dump64.exe and place it in the "C:\Program Files (x86)\Microsoft Visual Studio\*" folder, you can bypass Defender and dump LSASS.