Introducing Sift an automated treat hunting experience curating a report of new + interesting traffic observed by GreyNoise sensors daily after doing much of the analysis and triage work itself. Check it out today! https://t.co/tGSk3Fy0Ez
Ever wanted to play around in (previously unreleased) GreyNoise data? We're excited to announce that GreyNoise Labs is here to make that dream come true. Check it out: https://t.co/lhrmxlOd0x
got some beautiful new explainer graphics on how most of our customers deploy GreyNoise in their environments. hopefully this provides some foundation for how to implement other threat intel/OSINT/data feeds in your environment
https://t.co/8Cqz1ihYom
(1/3)
GreyNoise has observed scanning activity for the login page of MOVEit Transfer as early as March 3rd, 2023. While we have not observed activity directly related to exploitation, all of the 5 IPs we have observed attempting to discover the location of MOVEit installations were marked as “Malicious” by GreyNoise for prior activities.
https://t.co/P8rZaRiDEw
If you're interested in...
Seeing shit that's potentially targeting you (or networks like yours)
OR
Contributing back to the GreyNoise ecosystem so we can all catch more bad shit
OR
A no-code honeypot you can use to collect PCAP for emerging vulns
Hit us up
Hope everyone saw this 'historic' new feature in @GreyNoiseIO Enterprise. Built an App in Tines using the new IP Timeline API capability to provide a basic hunting interface for folks.
Try it out here: https://t.co/NZIs4JTKzE
Import the Tines Story here: https://t.co/EUp3IpJnWN
Not all vulnerabilities are created equal, and many of the ones garnering media attention turn out to be nothing burgers. See which ones topped our researchers' mass exploitation list in our inaugural Mass Exploitation Report, out now!
https://t.co/Ol7tWojCrP
@nathanqthai @GreyNoiseIO Why doesn't Twitter have a dislike button? You are gonna be missed. Your impact on @GreyNoiseIO has been monumental, and I know you'll make just as big an impact wherever you go next.
@0xDroogy@Andrew___Morris@GreyNoiseIO This is something we see pretty often, which is why having the two distinct datasets (NOISE and RIOT) helps. This tells you that GitHub Actions (a business service) is being used for malicious scanning purposes. Happy to provide any other clarity needed.
We are continuing to monitor for indications of CVE-2022-41040/CVE-2022-41082 Exchange "ProxyNotShell" attempts until auth requirement details become clear.
The original 2021 ProxyShell exploit chain involved leaking an auth token: https://t.co/i7wgG2ejSy
Our 'ProxyNotShell Vulnerability Check' tag is now live: https://t.co/5WOwvoOHLI
You can also access a raw list of IPs for the tag here: https://t.co/57geGBIvlY
We're hitting the road! 🚌
Come learn more about how to quickly identify threats, prioritize alerts, and pinpoint trending internet attacks targeting specific vulnerabilities and CVEs
Free & open to all GreyNoise users! Join our community and request your invite today!
@ImposeCost@GreyNoiseIO Thanks! We try to make sure it is as useful as possible, but if there is anything we can do to move from "mad-decent" to "f'ing phenomenal" let us know!