Thanks to tremendous dev work by Fukusuke Takahashi and DustInDark, we have our first alpha version release of Suzaku - "Hayabusa for cloud logs". Still lots to implement but the basic sigma detection is working for AWS CloudTrail logs so try it out and give us feedback on how we can improve it for those of you who do DFIR in the cloud. Enjoy!
https://t.co/5WRxnmNvS8
高橋福助さんとDustInDarkさんによる素晴らしい開発のおかげで、Suzaku(Hayabusaをクラウドログ用にしたもの)の最初のアルファ版をリリースすることができました!
まだ実装したい機能はたくさんありますが、AWS CloudTrailログに対する基本的なSigma検出は動作しています!
クラウドでDFIRを行っている皆さん、ぜひ使ってみて、改善点やご意見をフィードバックしてください。
エンジョイ〜
''GitHub - pushsecurity/saas-attacks: Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown''
#infosec#pentest#redteam#blueteam
https://t.co/QrrtMJWF9l
How the NSA (Equation Group) allegedly hacked into China's Polytechnical University 👀
I analysed intelligence reports from Chinese cyber firms (360, Pangu, CVERC) to aggregate TTPs attributed to Equation Group.
🔗https://t.co/2dQuwx0lxN
🚨 Fortinet CVE-2024-23113 - actively exploited by state-sponsored hackers - is now being exploited by cybercriminals who have reverse-engineered it and are selling access to compromised devices
If you haven't patched, restrict port 541 to approved IPs or enforce cert auth.
🇨🇳 We're excited to announce the publication of the latest Sekoia #TDR team report, « A Three Beats Waltz: The ecosystem behind Chinese state-sponsored cyber threats."
https://t.co/sU2qCjUKHq
On Monday February 3 to Thursday February 6, 2025 we'll be facilitating our Advanced Detection Engineering training in the beautiful Brisbane. Come join us!
Hosting and registration kindly facilitated by @Division5io
https://t.co/Si4Mi5liQk
Today @404mediaco confirmed the individual believed to be responsible for the Snowflake breach (which resulted in the Ticketmaster breach) has been apprehended by the Royal Canadian Mounted Police (RCMP).
More information: https://t.co/cYRpr8nRQE
NEW LAB RELEASE: KG Distribution 🚨
A full memory analysis lab with two key systems using MemProcFS. This lab was created and brought to you by the talented @13CubedDFIR
👇 Solve the lab here 👇
https://t.co/3yo41LBhOh
Test your memory skills on:
👀C2 Analysis & Identification
👀DLL Injection Techniques
👀Persistence Techniques
👀Exfiltration & Staging
All lab VMs for users have now been beefed up with 16 GBs of RAM and 4 CPUs 🩷
@XintraOrg
We joined @FBI@NSAGov & @NCSC to outline TTPs used by Russia's SVR (APT29) to target defense, tech & finance sectors globally. They scan for unpatched systems, gain access, and pivot to connected networks.
Read the CSA for ways to protect your networks: https://t.co/wypXPTbYm9