Election day app exposes data on over 6.4 million Israelis: https://t.co/QQ4kR3N0wG
@barzik wrote a detailed technical article about the security flaws (Hebrew): https://t.co/Dc9axgVN7p
Blue teamers, if you're interested in hearing more about using #AzureSentinel in threat hunting, check out this video from #MSIgnite by @MSSPete
👉https://t.co/Rd2q90XKxW
Tools I recommend to Windows users - reply with your secret tip / tool
Setup:
Ninite
https://t.co/YFu5FP1Lff
Personal FW:
GlassWire @GlassWire
https://t.co/JBP9gz9i01
Anti-Spy:
ShutUp 10 @OOSoftware
https://t.co/aoWAZgYsek
For those that want a quick and short answer on Sentinel cost:
$2/Gb on top of storage costs
For 10 Gb/day, that's $29.44 for storage, $20 for Sentinel and a bit for others like Logic Apps. For a month, that's about $1500 (East US Azure region). Well worth it!
#azuresentinel
Releasing a new tool to aide in Sysmon evasion, Shhmon (https://t.co/ydLxxl4REW) with an associated blog post including defensive recommendations https://t.co/AD8Pe7LPUM
Azure Sentinel latest new features:
* Rule wizard with validation
* Rule templates
* Rule mapping to MITRE tactics
* Workbooks (replacing dashboards)
* Time range in alerts extended to days
#AzureSentinel
Exclusive: How Secret Dutch Mole Aided U.S.-Israeli Stuxnet Cyber Attack on Iran. For yrs an enduring mystery has surrounded the Stuxnet attack: How did US/Israel get the malware onto computers at the highly secured uranium enrichment plant? Now we know. https://t.co/iZs0pvRr71
Microsoft Office Flow is a powerful orchestration tool (attractive to attackers) that enables user workflows to upload documents to external services or do forwarding of emails - security teams may not know this is available or how to find the logs: https://t.co/UDh9vuEw5K
Azure ATP can integrate with MCAS and enable you to see on-premises activities and alerts in MCAS/Azure Sentinel, cool ! https://t.co/jWqGt6I2FE #AzureATP#AzureSentinel
Sandboxing is now available for Windows Defender (opt-in for now)! Tons of credit to the @WDSecurity team for their work on this (it wasn't easy), and thanks to @taviso, @natashenka, and other researchers who have helped make Defender even more secure https://t.co/dDYd581f6K
Just released: a testing framework for mail security and filtering solutions. Includes tests for:
• Sending spam and malware samples
• Bad file attachments
• Shellshock in headers
• Evasion with manipulated Content-Disposition headers
• ...many more
https://t.co/eyglCKI6ZZ
Exciting news - Defenders just got an awesome tool to stop macro-threats. We shipped detection mechanisms that expose macro behavior through runtime instrumentation. Built directly into O365 client apps and adopted by Windows Defender ATP via AMSI
https://t.co/XI5ho9a4bL