Enjoy! I am excited to see how yโall transform this into something even better. These are just the building blocks, it is up to you and your creativity ๐
https://t.co/UiAAn4rNCU
A SOC Project with N8N, Splunk, ChatGPT & Slack hmโฆ
SOC Automation Project 2.0 coming soon ๐
If you havenโt already, check out my projects playlist on YouTube. Put 2-3 of these onto your portfolio and youโll be in good shape!
Cybersecurity Analyst Projects
https://t.co/Q2y8QyydNy
๐๐ฎ๐บ๐ฝ๐ฎ๐ถ๐ด๐ป ๐๐ข๐๐ (๐ฅ๐ฒ๐บ๐ผ๐๐ฒ-๐ง๐ผ๐ผ๐น ๐๐ฒ๐น๐ถ๐๐ฒ๐ฟ๐ ๐ฃ๐ฎ๐๐ต)
Lure domain @anyrun_app observed:
๐ธ vallparty[.]de (sitting behind Cloudflare)
๐ธ Lure page: /winedine.html
๐ธ Payload served from: vallparty[.]de/ScreenConnect.ClientSetup.exe (~5 MB)
๐ธ SHA256: 66CA66CAE93C34E60A9A328B082FC7AA5396CC046BCFC5A14681D072128B9BE7
Lure HTML:
๐ธ winedine.html SHA256: D52B32EA18EEB88C7EE2EBBBECE4705D81F2EBBBB50518E765C1D84466989732
๐ธ MSI staged under %Temp%\ScreenConnect
Credential-theft variant endpoints:
๐ธ /processmail.php, /process.php, /pass.php, /mlog.php, /check_telegram_updates.php
Suricata hits worth building alerts on:
๐ธ ET REMOTE_ACCESS Observed DNS Query to Known ScreenConnect/ConnectWise Remote Desktop Service Domain
๐ธ REMOTE [https://t.co/TydYfoF5wq] ScreenConnect Server Response
One fake invite can end in a compromised mailbox, a stolen OTP, or a remote tool running as SYSTEM. And your team might not connect those dots until the foothold is already there.
This is where a sandbox earns its keep. When a suspicious link hits your queue during triage, you can detonate it somewhere safe instead of guessing. Within seconds you can see whether it is a fake invite, a credential form, an OTP prompt, or a remote tool quietly downloading itself. And as it runs, you are watching the actual behavior. The network calls, where the credentials get posted, what files drop, and whether anything reaches out for remote access.
Get special 10th anniversary offers from https://t.co/TydYfoF5wq: https://t.co/Q5SgPkNXCW
#Phishing #ANYRUN #ExploreWithANYRUN #CISO #SOCAnalyst
๐๐ฎ๐ธ๐ฒ ๐๐ป๐๐ถ๐๐ฒ๐, ๐ฅ๐ฒ๐ฎ๐น ๐๐ฐ๐ฐ๐ฒ๐๐: ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด ๐๐ฎ๐บ๐ฝ๐ฎ๐ถ๐ด๐ป
@anyrun_app researchers tracked a large campaign going after organizations with fake event invitations.
Here is the remote-tool path, detonated in the sandbox.
๐ธ User clicks the invite link
๐ธ A Cloudflare CAPTCHA loads
๐ธ Page auto-downloads a remote management installer, pulled straight from the lure domain
๐ธ In one version there is not even a button. The download just starts on its own.
๐ธ The installer runs through msiexec
๐ธ The remote client installs as a Windows service running as SYSTEM
๐ธ That service beacons out to a relay the attacker controls
That last step allows the attacker to have hands on keyboard access through a signed, legitimate allowlisted tool.
Full https://t.co/TydYfoF5wq analysis #1: https://t.co/lFUfOsETJq
Full https://t.co/TydYfoF5wq analysis #2:
https://t.co/KPWMbbahu1
Targeting, what to hunt for, and IOCs๐
#Phishing #ANYRUN #ExploreWithANYRUN #SOCAnalyst #DFIR #CISO #ad
๐ช๐ต๐ผ ๐ง๐ต๐ฒ๐ ๐๐ฟ๐ฒ ๐๐ผ๐ถ๐ป๐ด ๐๐ณ๐๐ฒ๐ฟ, ๐ฎ๐ป๐ฑ ๐๐ผ๐ ๐๐ผ ๐๐ฎ๐๐ฐ๐ต ๐๐
Most of the https://t.co/TydYfoF5wq submissions for this campaign came out of the United States. And the industries getting hit are the ones you would expect:
๐ธ Education
๐ธ Banking
๐ธ Government
๐ธ Technology
๐ธ Healthcare
Look at what those have in common. Email, identity, and remote administration are just part of the normal workday. A remote management tool showing up on a machine in a hospital IT shop or a university help desk does not look strange.
As of late April, around 160 suspicious links were analyzed and around 80 phishing domains were observed. Most sat on .de TLDs, which is a little odd for a campaign aimed at US orgs and worth watching for on its own. A lot of them were built from the same phish kit and some sessions even had instructions left in for the operator on how to edit the page.
That reused infrastructure is good news for us. When attackers mass produce lure sites from one kit, they leave similar fingerprints everywhere.
Here is what to hunt for and be sure to baseline your environment first.
๐ธ An RMM (Remote Monitoring and Management) client install (ScreenConnect, ConnectWise, ITarian, Datto, LogMeIn, etc.)
๐ธ An RMM service reaching out to a relay you do not recognize as your own
๐ธPOST requests to /processmail.php, /process.php, /pass.php, /mlog.php (likely noisy which is why baseline is important here)
A quick win is to find every RMM in your environment and note the ones that belong. After that, any new RMM install should get flagged for a closer look.
Pivot from this campaign's lure signature in https://t.co/TydYfoF5wq TI Lookup:
https://t.co/HH5tHPPbV0
IOCs in 3/3 ๐
I broke down a #socanalyst job posting and showed you exactly what they expect + how you can start learning each skill so youโre actually prepared when applying.
If youโve ever looked at a #soc posting and thought:
โWhere do I even start learning all of this?โ
This video is for you.
https://t.co/8oSVDwEzLT
#cybersecurity
Can you spot the suspicious activity?
This is a snippet of the MFT (Master File Table) artifact data from a forensic investigation scenario. Been building this out as part of the DFIR course for the MYDFIR Forge. Total of 14 modules with a mix of Windows, Linux, network, memory and cloud (Azure) forensics including a capstone investigation. This is a big course and will include a lot of theory + labs!
Can't wait to release it.
I'll be providing more details in the free SOC community as we get closer to the release!
https://t.co/yBCytV7Eig
I kept getting messages from beginners saying they wanted to become SOC analysts but not sure where to start so I built a free community thatโll give them a good starting point called The MYDFIR SOC Community:
Inside has 4 structured modules (fundamentals โ portfolio projects)
No paywall. No catch.
https://t.co/tXYoqEbnbn
ICYMI: Here is one of many walkthroughs from our monthly capture the flag events in the MYDFIR SOC Community.
Learn how to investigate and build your own investigative methodology!
WATCH: SOC Analyst Full Compromise Investigation | MYDFIR SOC Community
https://t.co/5PSYSSrG36
While building a lab for the community, I ran into something weird.
Setup:
Attacker PC: Windows 10 22H2 (UTC):
1) Created a timestomped LNK file (Year 2028)
2) Zipped it with password-protected 7-Zip
Target PC: Windows 11 24H2 (PST)
1) Extracted the file
2) Examined the MFT
- SI records 2028 && FN records 2026 (so far so good)
3) Shift + Right-Click LNK > Run as Administrator
The weird part:
After running it as Administrator, the FN timestamp, what use to be 2026 is now blank which if I am not mistaken would indicate it is the same time as SI.
Has anyone else seen this behavior? Not sure if this is a known thing or something new with 24H2.
Anyways, another reason to be sure to correlate with other artifacts!
#DFIR