notRDP - A Havoc C2 plugin that creates an invisible alternate Windows desktop, streams it to a browser-based viewer, and supports full mouse/keyboard interaction like RDP, but invisible to the target user https://t.co/AyhRjiTF2a
Monitoring privileged groups (tier 0) for changes is super important but if you can get to a point where youโre also detecting abnormal changes, thatโs better.
Eg, if somehow joe the sql guy has added an account to Domain Admins even though he shouldnโt be able to, thatโs a big red flag.
LogonTracer v2 is a tool to investigate malicious logon by visualizing and analyzing Windows Active Directory event logs. This tool associates a host name (or an IP address) and account name found in logon-related events and displays it as a graph. This way, it is possible to see in which account login attempt occurs and which host is used.
Github:- https://t.co/CplS0xdtL9
Purple Team Automation - Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK https://t.co/B7BTIJMz5E
๐ข๐ป๐ฒ ๐ฃ๐ผ๐๐ฒ๐ฟ๐ฆ๐ต๐ฒ๐น๐น ๐ฐ๐ผ๐บ๐บ๐ฎ๐ป๐ฑ turns Entra ID Protection into a clean hunting report.
Get-MgRiskDetection pulls user, IP, country + the exact risk reason straight from Microsoft Graph โ no portal digging.
https://t.co/L7ujjg3Rth
#EntraID
Four different RMMs. Cobalt Strike. SystemBC. Multiple operators.
And it all started because an administrator searching for RVTools fell victim to SEO poisoning.
This was a pretty interesting intrusion to investigate, mostly because it represents exactly what real intrusions actually look like, messy, overlapping access methods, different operators, tools failing, and activity running into EDR and other prevention controls.
Those parts donโt always make it into public intrusion reports, but I think theyโre some of the most useful things for defenders to see.
We joined forces with the amazing @PandaRE__ and @malbearlabs on this one. We focused on reconstructing the intrusion, while Anna and team did an amazing job in breaking down the payloads we came across.
Our report:
https://t.co/N0yz6pDyzN
MalBear Labs RE report:
https://t.co/m1ggfcbKLe
Common initial access attacks where phishing resistant MFA alone won't save you:
1. AITM with downgrade
2. Device Code Flow Phishing
3. Illicit Consents
4. Authorization Code Flow (aka ConsentFix)
5. Teams based phishing
6. ClickFix attacks
7. Traditional phishing attacks where you land on a device
8. Post-authentication browser session hijacks
9. Infostealers (see #8)
10. Malicious browser agents (see #8 and #9)
If you're an IT admin and you have nothing to do, check for these issues in your Active Directory environment.
I promise if you fix these issues your environment will be harder to attack.
https://t.co/FFtYjV0UZV
ScreenConnect is 74.5% of the abused remote-access tools @HuntressLabs sees.
So I detonated two real samples and hunted both on Defender and Elastic. Full hunt notes and every query in the Article.
Came across a really interesting BYOVD chain recently
The loader transitions execution from user mode to kernel mode without triggering UAC, downloads ntkrnlmp.pdb from Microsoftโs symbol server, decrypts the AMD PDFWKRNL.sys driver vulnerable to CVE-2023-20598, and zeroes kernel callbacks associated with 20 security drivers across seven vendors. This blinds EDR products before the loader deploys what we are tracking as a new information-stealing malware family called Lunex, targeting the CIS region.
Final payload after BYOVD blinds EDR: psychedeliclove.exe, full C2 agent. 7 browsers, 6 wallets, Chrome/Edge NMH persistence via com.lunex.explorer. Triple persistence. Live C2 panel at time of analysis.
I have been unable to find any documented technical analysis of the binary. However, I discovered that @btcoolteam conducted OSINT research into the Lunex panels in June, which appears to be related. I will be publishing a blog with a more detailed analysis soon.
IOCs:
hxxp[://]107[.]175[.]82[.]242[:]9000/wilow/psychedeliclove[.]exe
hxxp[://]193[.]178[.]159[.]128[:]8080
uasputnik[.]com
Loader: bf14cd6c3328ebd08e940478b5d1da04e9e5aa576d045d41950bf4f1e2456dd8
Driver: 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1
Stealer: 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90
#malware #BYOVD #threatintel
Investigation Scenario ๐
Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred.
What do you examine next to determine who added the credential and whether it was used?
#InvestigationPath#DFIR#SOC
๐จ Possible OPSEC slip in UNC6671 associated infrastructure?
A DNS change appears to expose 46.19.136[.]147 (Private Layer INC ) behind numerous myaccountapps[.]com hostnames. ๐
Misconfiguration or campaign teardown? Intent remains unclearโbut the pivot is worth watching. ๐
Your SOC vendor closes a Microsoft Defender alert within seconds via automation. Efficient? Maybe.
But hereโs the question worth asking: Could that automation prevent Microsoft Defender XDR from building the attack story?
https://t.co/MKskP7tRTt
We have discovered a massive, ongoing criminal exploitation campaign using Cairn, an autonomous penetration-testing harness, and other AI agents to target hundreds of organizations and successfully breach and impact tens of them (at least). The image below shows just a few days of activity, with up to 25 organizations being attacked simultaneously at the peak.
our intreim report: https://t.co/t9OwRe4HvW