Continuously observing an ongoing attack scenario where Microsoft accounts with SMS Sign-in enabled are being successfully authenticated through the Microsoft “AMC PROD” application without user interaction
#microsoft#attack
This activity is specifically being observed on user accounts that have SMS Sign-in enabled. Has anyone else observed similar unusual behavior on Microsoft accounts with SMS Sign-in enabled, such as unexpected authentication prompts or sign-in codes originating from unusual?
@HirotomoTaguchi “AMC PROD” application appears to be triggered during the BitLocker recovery process or when accessing BitLocker recovery related services. (https://t.co/nXzljeui3H)
Every IR engagement starts the same painful way:
Download KAPE. Remember the flags.
Spin up Velociraptor.
Hunt for the hashing script.
Build a chain-of-custody spreadsheet from scratch.
Write the report template on the fly.
Meanwhile, the attacker has already been in the environment for days.
We built VanGuard to kill that entire tooling nightmare.
VanGuard is a single binary (Windows + Linux) that runs from a USB drive or your local machine — no installation, no dependencies, fully air-gapped.
It consolidates triage, threat hunting, memory forensics, disk collection, remote ops, and reporting into a single, clean, professional TUI.
What makes it different:
→ 28 pre-built IR use cases (ransomware, BEC, lateral movement, credential theft, rootkits) — each with full MITRE ATT&CK mapping
→ Velociraptor as a first-class citizen (server lifecycle, agent deployment, offline collectors — all from one interface)
→ Every artifact dual-hashed (MD5 + SHA256) + HMAC-SHA256 tamper-evident chain of custody
→ One-command HTML incident reports that work completely offline
→ True cross-platform: same binary handles Windows and Linux investigations
We didn’t build this as a product.
We built it because we needed it on real engagements — and as a training aid for practitioners who want to level up their DFIR skills.
👉 Landing page + screenshots: https://t.co/QXM7lJixx9
👉 GitHub: https://t.co/dEmIuEumO6
The investigation methodology behind every VanGuard use case is taught in our Practical Incident Response course — first modules are completely free, no account required:
https://t.co/H7SfwMBpFk
Download it, run it in your lab, and let me know what you think. Star it if it helps. Issues and feedback very welcome 🔥
#DFIR #IncidentResponse #OpenSource #BlueTeam #Velociraptor
🚨 #𝗣𝗵𝗶𝘀𝗵𝗶𝗻𝗴-𝘁𝗼-𝗥𝗠𝗠 𝗔𝘁𝘁𝗮𝗰𝗸𝘀: 𝗧𝗵𝗲 𝗥𝗲𝗺𝗼𝘁𝗲 𝗔𝗰𝗰𝗲𝘀𝘀 𝗕𝗹𝗶𝗻𝗱 𝗦𝗽𝗼𝘁 𝗖𝗜𝗦𝗢𝘀 𝗖𝗮𝗻’𝘁 𝗜𝗴𝗻𝗼𝗿𝗲
Attackers are exploiting a security gap in U.S. businesses. Fake Microsoft, Adobe, and OneDrive pages deliver RMM software instead of payloads, giving attackers direct access to the environment.
⚠️ Because these tools are widely used across enterprises, attackers can establish access before activity is flagged as malicious. Combined with trusted or compromised infrastructure, this delays detection and increases attacker dwell time.
⚡️ #ANYRUN allows teams to safely validate suspicious remote access activity faster, trace the access path, and provide leadership with clearer evidence for containment and follow-up decisions.
👨💻 See the analysis session showing how attackers gain remote access through a fake Microsoft Store page delivering an RMM installer disguised as Adobe software: https://t.co/rsOduxm4ee
📌 Learn how to close the blind spot before access turns into impact: https://t.co/VHZeqKzkar
On May 5, Huntress Threat Intel Analyst Casey Smith and special guest @sherrod_im, GM of Global Threat Intel at @MsftSecIntel, are breaking down what happened, why it worked, and how defenders can fight back.
Save your spot for the live event: https://t.co/erN9CJJeXo
#MSPartner
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at https://t.co/bGCIjBfD3C. Launched with:
- Malware Analysis Crash Course
- Go Reversing Reference
- Intro to TTD
NEW LAB: NavalTech Defense Contractor ⚓
We emulated a North Korean (DPRK) cyber espionage campaign targeting a submarine contractor’s vessel-tracking systems.
Based on CISA’s reporting on DPRK operations to advance military and nuclear programs.
Contributors
@django88_@svch0st@XintraOrg
Solve it here 👇
https://t.co/3yo41LBhOh
💡 𝗛𝗼𝘄 𝘁𝗼 𝗙𝗶𝗻𝗱 𝗢𝗽𝗲𝗻 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝗶𝗲𝘀: 𝗣𝗼𝗿𝘁𝗮𝗹𝘀 𝗳𝗼𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲
https://t.co/YXTzBxmsT3
From a defensive standpoint, open directories represent both a risk and an opportunity. They are often overlooked yet incredibly informative sources of threat intelligence.
Misconfigured directories can leak sensitive material that attackers can later exploit, but they also provide threat hunters with a rich source of real artifacts and infrastructure clues when searching for malicious activity.
What makes open directories especially valuable is the variety of materials they expose:
• DDoS scripts
• PowerShell scripts
• Custom malware and malicious browser extensions
• Backdoors and exploits
• .bash_history files
• Banking trojans
• And much more!
For proactive defenders, open directories are an opportunity to understand adversary behavior and intercept attacks earlier than traditional detection would allow.
Read more on how to find and approach open directories ⬇️
#CyberSecurity #ThreatHunting #OpenDirectories #ThreatIntel