📢 Check out @CISAgov’s 🆕 Untitled Goose Tool developed in partnership w/ @SandiaLabs. It helps IT pros detect potentially malicious activity while conducting hunt & incident response in various Microsoft cloud services. Learn more: https://t.co/MNOBRGgSWS
Had a lot of fun playing Wingspan Asia’s flock mode for the first time in almost a year since playtesting it with @elizhargrave! Looking forward to the launch party next week!
@huettenhain In the end, your solution for 8 helped me find my error in my original RC4 key calculation.. I was adding the last command to the hash calculation when the program omits it from the string append!
@huettenhain Yep! It was a scapy DNS server sending commands in the order given by FLARE15.c xor'd with 248. It takes like 30 minutes to run against the "unfixed" binary due to all of the exception handling slowing down the run.
Thanks @nickharbour and @Mandiant for another awesome #flareon9 ! Just barely finished on the very last day. Had to leave #CYBERWARCON a bit early to reverse all night. Until next year!
@agowa338 @0xdf_@PayPal Yes, I’m referring to the fact that the PayPal invoice has the billing department email. Unsure if that’s just a user-filled description or if somehow they’ve typosquatted a PayPal email.
@AzuleOnyx@kipko85@hacks4pancakes I haven't looked into 301V/L but I'm one of the instructors for DOE Cyberfire's Malware Course. The event has an OT component taught by some colleagues of mine from INL (who also built 301V/L). It's also a free event. Feel free to DM me if you're interested!