@Mandiant and @FireEye have been tracking and responding to multiple incidents involving the exploitation of Pulse Secure VPN appliances.
https://t.co/iW0t4HCMfV
Over the last several months, @PenninoPress, @Sa1jak and I have been working hard on making massive improvements to @Mandiant Managed Defense Hunting.
You can get a teaser of what we built here:
➡️ https://t.co/tcLq7dHJoj
Threat Hunting at scale is no easy task. A thread ⬇️
Don't search DNS and call it a day. There's incredible nuance to this activity, with secondary payloads and C2, VPN logins from compromised accounts, and O365 access. Start small. Be methodical. Search for "known bad" and then pivot your investigation to TTPs.
(7/7) For more info about these two vulnerabilities, check out @rapid7's blog post: https://t.co/Jh34tS3Fjd and @corelight_inc's GitHub repo: https://t.co/u6k9stH2An
(1/7) Within days of #CVE-2020-14750/#CVE-2020-14882, @Mandiant Managed Defense observed #UNC2459 exploiting them at MD customers. HTTP POSTs to /console/images/%252e%252e%252fconsole.portal with response status code 302 indicate likely successful exploitation. #blueteam#mdr
(6/7) #UNC2459 also used a simple shell script to perform DNS-based exfiltration of directory listings from exploited hosts (#T1048.003). Check your DNS logs for long subdomains with any SLD. Deconflict burpcollaborator[.]net hits with your pentesting/vuln. management team.
@Mandiant Managed Defense found this PoC in the wild as part of an active intrusion! Process execution events containing "Generic / Text Only" sourced from unknown binaries are interesting. #printdemon#MandiantHunting
@Cyb3rWard0g and @Cyb3rPandaH's talk at #ATTACKcon is jam-packed with great content that will save #blueteam members lots of time and effort - these two are constantly working to make the community stronger! Check out their talk if you get the chance. #MITREattack
Casual observation: most of the “red team training” assumes some fairly egregious lack of security prevention or detection controls.
Would the industry appreciate a “red teaming the worst case scenario” type training? Great detections, all the typical preventions?
Please RT.
Trying to find documents where user's have clicked "enabled macros" in MSFT Office?
Look at HKEY_USERS|HKCU\Software\Microsoft\Office\.*\Security\Trusted Documents\TrustRecords reg keys for values ending in FFFFFF7F
https://t.co/XmvGJkVreL
#DFIR#ThreatHunting
This is a COOL project to collect event log traces for attack tools and @MITREattack techniques! (in EVTX format). Hope it is open to contributions from the community! 🙏@SBousseaden
📢https://t.co/ezzH8yq9GU
👉https://t.co/QwYRcw2jpg