A fantastic write-up (with source-code) that lays out an #EDR bypass technique for in-memory protections. Wonder how long it's going to take a #malware writer to jump on this discovery and modify/use it. #CyberSecurity#ITSecurity#DFIR#infosec https://t.co/M8gT0CRNv0
@KyleHanslovan@MichaelDunten@cyb3rops Isn't that why Security Intelligence (SI) vendors developed? To find high-quality leads in all that noise so that analysts could follow them through to a conclusion? Doing it manually is a high skill time-consuming activity; very few would be able to do it, period.
Biotech firm hit by #Ransomware uses @InfocyteInc to rapidly sweep estate, discovering #Trickbot#malware running undiscovered on 20 endpoints. https://t.co/JmYaJHcyyu
Lesson #banks keep failing to learn from: fail to control dwell time or rely on defensive tools that let #malware breach to find malware that has breached exposes you and your customers to unnecessary risk. #ITSec#ITSecurity#ThreatHunting#dfir https://t.co/6MfHNPGF2Q
#Retail merchants take note: announcing you're working with 'leading data security investigators' after the fact is a crass dismissal of your failure to protect consumer with reliance on technologies you know let #malware breach. #dfir#ThreatHunting https://t.co/n6QN2XntDp
It shouldn't be as challenging as it is to access a file write-locked by another process with #csharp - without volume shadow copy services. Two days to find a workable solution... now onto the more interesting work of tearing apart the #amcache hive. #itsec#dfir#ThreatHunting
Consumers should be demanding programs that actively look for #malware on #POS systems are in place before handing over their credit or debit cards. If merchants don't have these kinds of programs, don't risk it and stick with cash. #cybersecurity#dfir#ThreatHunting#itsec https://t.co/AHXtvDNC6y
1/3 of European #cybersecurity positions remain unfilled. Organizations are facing a cyber skills shortage. Infocyte HUNT automates the hunt for malware with #forensics automation and memory analysis techniques. #ThreatHunting#malware#dfir @InfocyteInc https://t.co/fdb2LYslSc
In case anyone missed it, ProcMonX is using the same event tracing relied on by most EDR solutions which will naturally lead to an opensource EDR product. #malware#dfir#CyberSecurity#ITSecurity#ThreatHunting https://t.co/VAOjYs1YsL
An article that looks at how the #analyst business is a racket and some basic questions everyone using their services should demand answers to when getting advice. #CyberSecurity#ITsecurity#Itsec https://t.co/NLjSLmEmio
Yet another merchant fails to control dwell time and allows a 7-month #POS breach, affecting 164 locations in 14 states. If a retailer can't show endpoints are #malware free, don't trust them with credit/debit cards #CyberSecurity#ITSec @InfocyteInc https://t.co/0AVhjtv4um
Anyone interested in #malware hunting and got suckered into a data-centric approach? Sign up for his #threathunting webinar lead by @gerritzc and learn how even juniors can do it faster, more efficiently, and at scale with @InfocyteInc #itsec#ITSecurity#CyberSecurity#dfir https://t.co/9VI8OAouSE
Be sure to join Rohit and I at @InfocyteInc’s Webinar on Challenges to Log Analysis - part of our #threathunting series dispelling some common myths (i.e. you “can’t” hunt without logs and massive infrastructure investments are a prerequisite) https://t.co/EkJyxH6JCx
The failure to control #DwellTime means #malware breaches are allowed to persist undiscovered for too long; reducing to 7 days = 76% reduction in business impact, 1 day = 96% - almost negligent not to use a tool like @InfocyteInc #CyberSecurity#ITSec#ITSecurity#DFIR https://t.co/qE3aPMyZpU
Median Dwell Time if a #hacker before discovered still hovering at 99 days. 173 in APAC. Need for @InfocyteInc & #ThreatHunting holds true. https://t.co/f5awVaEqDr
With over 360,000 variants of #malware per week being released, it's the ones that are using unknown techniques and evading modern defences that are the most concerning. #itsec#ITSecurity#CyberSecurity @InfocyteInc https://t.co/ZW6j10thdN
Cisco addicts: it looks like you have a whole new reason to throw out last years' purchases and move to (aka repurchase) the newest/latest/greatest. #networking#itsec#ITSecurity#malware https://t.co/KHpUuLEIGd