CYBERWARCON is coming!!! Registration and CFP are now open for this year’s #CYBERWARCON! This year’s keynote will be given by the NSA’s @adamski_morgan. The in-person event is in Arlington, VA on Nov. 22nd and virtual tickets are available. 1/x https://t.co/MTEL4utvgM
Cobalt Strike continues to keep blue teams on their toes. GuidePoint Security investigates an unconventional #cobaltstrike stager that utilizes GUIDs to assemble and execute shellcode for retrieving a beacon payload from C2 infrastructure. https://t.co/Tb9UzP8nRj #BlueTeam@5ynax
Ever found malware by seeing something weird in a network capture? First time for me: https://t.co/FoMpGEToZI . This is what I have been busy doing the last few weeks. Enjoy!
"These slides are almost done, I should be able to finish them up in 10 minutes!" 2 hours later: "WHY ARE THERE 18 DIFFERENT SHADES OF BLUE TEXT??!???"
#UNC2452#Dark Halo
The most detailed analysis report of the #SolarWinds Supply Chain Attacks so far, produced by Qi AnXin CERT:
https://t.co/neRKASRj0W
@JPoForenso@likethecoins@PyroTek3@ItsReallyNick No snark taken, and I hope I didn't come of snarky. The changes to the attribution don't really affect much until we start to model the attack which feeds into our threat hunts. Whether the webshell was used or not can help us understand the context & help us hunt effectively.
@likethecoins@PyroTek3 While classy, it was still part of the original IOCs for the campaign and this tweet does little to explain why it’s removed. I appreciate @ItsReallyNick by letting us know but I want to know why it was there and then why it was removed.
@likethecoins@PyroTek3 Always something tough. @ItsReallyNick was awesome in letting @GuidePointSec know that it wasn’t related. My biggest thing is context, it’d be awesome to know why I’m looking for something or why I should remove it after the fact.
@likethecoins@PyroTek3 Not unusual at all, and a fantastic response. Didn’t mean to cause a fuss, but with as much speculation as there is out there right now a clear explanation is all that is needed when IOCs are released then changed and ppl are doing their best to keep up with the information given
Joe is one of the best tech reporters out there.
While there isn’t a lot of detail here, I’m sure there is more coming soon.
If he says Microsoft was hacked, this isn’t a small thing or an individual tenant.
I really hope this isn’t as bad as it’s sounding.
So let’s talk about the future of https://t.co/8aVBWvkf1x…tldr: I’ve just made it my full time job, and I expect to be working on it for the next 10+ years!
"Some" SIEM vendors should include a case of bourbon every month as part of their support contract. It is only fair due to some of their custom and overly complex "query" languages. It should not be complicated, or impossible, to build/customize detections for basic TTPs.
Been a long day but thanks to @gentilkiwi's awesome new mimikatz CloudAP support we managed to put together tooling that can sign arbitrary PRT cookies! Secrets from lsass + DPAPI + crypto magic + horrible C code = working POC of session key extraction.
There are a number of C2 frameworks on #C2Matrix with the capability of using DNS-over-HTTPS (DoH) for command and control. You do not have to wait for a TTP to be added to @MITREattack to test if you have visibility of these protocol in your organization
https://t.co/BpPsQzZCZT