Check out this awesome report by Sophos on Chinese APT threat actors. There is much to learn from this technical breakdown; it's not your ordinary threat actor.
Reading this report, you will notice that they used tools like impacket for lateral movement, which provides an opportunity for detection.
➡️Interesting use of Living-Off-the-Land binaries that I personally haven't seen before - instsrv.exe and srvany.exe.
➡️Multiple defense evasion methods to hide their tracks and evade detection, including a clever way to read DNS traffic and block AV/EDR-related domains. (but still uses impacket 🤷♂️🤦♂️)
➡️Interesting choice of data being staged for exfiltration.
Overall, this prolonged intrusion had everything, and the authors did an incredible job of laying out all the details for the rest of the community. 🙏👏
Check it out here 🔗: https://t.co/1ZieUUd6w2
Cado Security is honored to be named in the Gartner® Emerging Tech: Emergence Cycle for Cloud Security as a Sample Vendor for Cloud Forensics
Download a free copy of the report here: https://t.co/fZDMD2nPTM
@eric_capuano made a great beginner lab to learn Prefetch Analysis for #DFIR work.
I made a simple walkthrough video showing you how to setup the lab and get started, so no need to feel overwhelmed.
Get in there and start learning!
https://t.co/7t1tQHxNG3
ATTN NERDS 🤓
this week we released our new @limacharlieio plaso extension! 🔥
it will take a forensic artifact from an endpoint, or a zip of artifacts (like a KAPE triage from the @velocidex extension) and make a timeline of the data that can be imported into @TimesketchProj
In 2014, @JohnHultquist named a Russian hacking group "Sandworm".
Today, Mandiant graduates it to APT44 & reveals the online persona they created, CyberArmyofRussia, disrupted U.S. and Polish water utilities, as well as a dam in France.
Full report: https://t.co/VnECP2GGgz
🎁 Today I'm giving away 3 of our DFIR Labs! 🎁
To enter:
✅Follow me
✅RT & Like this post
✅Reply with which case you'd like to take
The winners will be selected in 24 hours. #Giveaway
@tazwake I'd lean benign true positive, but I accept that it's not the most ideal detection.
As a detection engineer I'd be looking to tweak the detection somewhat to reduce this from firing in this scenario.