Was chatting with @brent_murphy about detection engineering practices at S1 and it was awesome to hear that they leverage these resources:
⭐️ Axioms of Security and Rule-Based Capabilities
and the
⭐️ Zen of Security Rules
🔗 in 🧵 ��
🔥 🟣 Purple AI is here and now generally available! To learn more about the industry’s leading AI security analyst, watch the video below.
👉 Ready to transform your security operations? Get a demo: https://t.co/oycBlmEiFL
I have been working on a pretty extensive detection engineering series for a while now. I wanted to start sharing some tidbits in the mean time.
Axioms of Security and Rule-Based Capabilities
https://t.co/yiJ4DkMnTD
I use these as a basis of truth for many things #DetectionEngineering
So, you are looking for the #AnyDesk potential compromised signing certificate but do not have the serial number details of the processes in your EDR? What can you do? Well, for #Elastic, follow the thread.
At this point, you can create the rule and provide relevant details to affected parties without a lot of noise if you were instead to just by just look at signer subject names in a given time frame.
Tracking the #MOVEit Critical vulnerability, here's a few additional Hunt queries to look for. https://t.co/MEIoJwDEc4
Also, shoutout to @_JohnHammond for his thread and research - https://t.co/Q6ZmVfTx6W
Okay I'm down a rabbit hole but I'm wracking my brain on this, desperately wanting to figure out how the #MOVEit exploit comes together.
We've got in the known IIS logs a procedure (coming disjointly from different IPs) that hits up
- moveitisapi.dll
- guestaccess.aspx
etc