I'm happy to announce the release of 2 useful tools:
1/https://t.co/JR6SK2sS2T it process the raw Falcon Crowdstrike logs in a human readable format (authentication and process tree)
2/https://t.co/QBZGYHEea0 it shows a graphical searchable process tree
#edr#CyberSecurity#tool
I'm thrilled to share my entire research parts on one of the most notorious banking Trojans out there - Qakbot, titled "The Heist: Unmasking the Qakbot Banking Trojan" I've delved deep into the complexities of this malware's operations.
https://t.co/RWLqax6JCT
Thread [1/3]
Creatde a "cheat sheet" of sorts for Windows log sources and some of the event IDs. Credit to @SecurityYamato and @keydet89 for their awesome work in this space and their tools.
Hope this helps someone. https://t.co/1fIZOMcLZz
I’m excited to kick the morning off by announcing the release of 🍎 Living Off the Orchard: macOS Binaries (LOOBins)!
https://t.co/7WQjNCQFQv
You can find more details about the LOOBins project in my “Introducing LOOBins” Medium post here:
https://t.co/MHQjpEXuaN
@GoogleTranslatr is getting abused for credentials theft phishing emails
The rewritten URL splits the target URLs between the subdomain part of https://t.co/BQdCnx3hPm and the URL path which is convenient to hide the real URL
Example: https://t.co/RD3JAdw2PB
#phishing#DocuSign
👉New Blog: I have attempted to track what happened to Conti this year after the leaks and collapse of the group. Here are my findings, largely based on #OSINT. Enjoy!
https://t.co/0jSd1ZFkLf #Conti#Quantum#BlackBasta#Royal#WizardSpider#CTI
@NOP_0x90v1 showed me a fantastic way to audit breached passwords in a Compromise Assessment using the HIBP passwords (hashes). [1]
The result of the audit is a CSV file with users in the AD using a password from the HIBP DB (sorted by pwdLastSet).
[1] https://t.co/VtyvnFULjS
Emotet asks targets to copy the spreadsheet to these folders as they are 'trusted' by Microsoft Office.
When a file is launched from these folders it bypasses the Microsoft Office Protected View security feature, allowing macros to automatically execute without warning.