The Wifydra Lives!
-Each of the 14 ESP8266 continuously scans for wifi beacons
-Each ESP checks the MAC of every network it just saw against the last 500 it's seen
-Then sends new ones to the Dom ESP, which also connected to the screen, gps, and SD card reader(it's on the back)
1/ #DFIRTip: Another example from a real IR case.
We investigated a breached Linux web server where the attackers used https://t.co/YpRUsQdxbT (Impacket Suite) to dump the hashes from the DC (at this point, the TA already had the necessary permissions for this action).
🧵
Last night a friend asked if I could help decoding the payload URL from a LNK file (not base64 encoded).
While VT is often able to show the payload URL, it isn't always possible to upload files in a corporate environment.
So how can we decode the target data from the LNK file?
If defense is hard, you're doing it wrongly.
Last week I wrapped up an interesting coaching type engagement for a defense crew.
I'm not ever going to violate NDAs, but I can share with you some interesting themes.
Let's dig in!
1
If you’re still in schooling for or thinking about more school for cybersecurity, take those legal, contract, psych, and writing classes.
They will do far more service to you and be extreme resume builders over learning granularly about how encryption algorithms work.
One of the bigger initial barriers for newer analysts to break through is understanding exactly where investigative work happens. Much of it happens in the web browser and search engine rather than the SIEM or command line. 1/