VeloCON REWIND!
Phalgun Kulkarni and Kostya Ilioukevitch of AON show off a new Velociraptor plugin that goes deeper into a broader set of lateral movement artifacts to better detect threat actor movement during investigations.
https://t.co/Jf0kn21bhU
📺 SANS #DFIRSummit Talks are live! ️
🗣Featured Experts: Shane McCulley, Senior Software Developer, Aon & Kimberly Stone, Director, Aon
👏 Windows Registry Forensics: There’s Always Something New
➡️ Watch Now: https://t.co/mQEK35Qye9
FYI - if you have been exploited by CVE-2023-22515, be aware webshells may have been installed! The admin rights allow uploading of plugins which can be used to drop webshells. #DFIR#confluence
The threat actor from September has a fairly unique shell which hijacks TomCat servlets dynamically via the confluence plugin. This lets them use their webshell on any page, including the login page. #DFIR
📺 SANS #DFIRSummit Talks are live!
🗣Featured Experts: Phalgun Kulkarni, DFIR Consultant, Aon & Julia Paluch, DFIR Consultant, Aon
👏 Windows Search Index: The Forensic Artifact You’ve Been Searching For
➡️ Watch Now: https://t.co/pgf19L8MsS
Join me on Sept. 30th at @BSidesCT where I'll be presenting on the significance of the Windows Search Index artifact in #DFIR investigations. I look forward to the wonderful event.
Excited to share that Julia Paluch, Kostya Ilioukevitch, and mine presentations won 2 "Best Presentation" awards at #VeloCon2023. Thank you to everyone who attended and made it such a successful event. #Velociraptor#DFIR#StrozFriedberg#Aon
👨💻 #ScatteredSpider#UNC3944 has been targeting organizations across multiple sectors. The latest target being #MGMResorts.
🕵♂️ #StrozFriedberg has responded to multiple incidents involving this threat actor. We've published a client advisory that provides details into attacker techniques, recommendations and countermeasures.
Link: https://t.co/gb2x6aApw4
📄 Here are some highlights from the report:
1. A common thread across several investigations has been the utilization of social engineering tactics to gain access to privileged accounts.
2. This threat actor has demonstrated a significant level of knowledge and skillset when operating within an organization's cloud environment.
3. This threat actor has been observed sending personalized and threatening messages over email, phone, and SMS to gain attention from victim organizations. In some instances, they have contacted the media to add pressure and extract payment from companies.
4. This threat actor has been observed deploying ransomware on ESXi servers. This threat actor has loosely affiliated itself with the #ALPHV or #BlackCat ransomware group in some instances and has used the ransomware group’s negotiations and leak site infrastructure to post information about victim organizations.
This is a group that is very skilled and persistent. Please review the recommendations in our report to better protect your organization from this threat.
#StrozFriedberg #DFIR #IncidentResponse #CyberSecurity
🕵️♂️My colleagues @Fal_Forensics and Kostya gave an excellent talk on lateral movement at #VeloCon2023 today.
🚀 They also released a Velociraptor plugin that processes multiple lateral movement artifacts and gives you a normalized output.
👨💻 Check it out here: https://t.co/5tugoswiDB
#StrozFriedberg #DFIR #IncidentResponse
I will be presenting alongside my colleague Julia at #VeloCON2023 about how you can utilize Velociraptor to parse an amazing Windows forensic artifact, Windows Search Index, at scale and enhance #DFIR investigations.
#Velociraptor#digitalforensics#incidentresponse
Hey folks! I'll be going on a conference tour in the next couple of months and presenting some research at the following cons:
- BSides ABQ (Sept 8-9)
- BSides KC (Oct 6-7)
- BSides Bloomington (Oct 13-14)
I'm honored to speak at these locations to represent Aon's Testing services team, particularly our red team, and really looking forward to seeing my old Depth Security crew in my favorite city (KC) in October. :)
I made a 4-minute teaser video regarding my research ("DUALITY") - it can be found here: https://t.co/9jMXWftFXf
You can find the talk's abstract in BSides Bloomington's schedule here: https://t.co/VFfl6uNm9M
There is a blog post coming soon as well.
tl;dr - we're simultaneously backdooring multiple DLLs on the fly with custom logic for init access and persistence (to keep each infected DLL alive) via a pipelines, C2 scripts, and a somewhat custom shellcode compilation (carefully written C->ASM) methodology. I'm hoping to take DLL proxying / sideloading to the next level, or at least provide an interesting alternative.
My LinkedIn: https://t.co/6NI9sBxMI7
And that is all for this year's #DFIRSummit. We would like to thank our attendees, advisory board and speakers for making the 16th DFIR Summit a success!
We will see you next year 8/22-23 in #SALTLAKECITY!
#DFIR
A few more days left for #Sans#DFIRSummit. Join me and Julia for an amazing journey where we talk about a not so famous but very important artifact "Windows Search Index," and learn how W.S.I can enhance your #DFIR investigations. We also showcase an awesome tool to parse W.S.I
Join us at #DFIRSummit when Phalgun Kulkarni and Julia Paluch discuss how the Windows Search Index can be used as a source of evidence in DFIR investigations.
Register here: https://t.co/wdW6548UmX
#DFIR#IR#IncidentResponse
Join us at #DFIRSummit when Shane McCulley and Kimberly dive deep into Shellbags and uncommon extension blocks, and dispel some dangerous myths about what they say about user behavior.
Register here: https://t.co/wdW6548mxp
#DFIR#IR#IncidentResponse
Join us at #DFIRSummit when Phalgun Kulkarni and Julia Paluch discuss how the Windows Search Index can be used as a source of evidence in DFIR investigations.
Register here: https://t.co/wdW6548UmX
#DFIR#IR#IncidentResponse
Recently, Julia Paluch and I worked on researching the Windows Search Index artifact. I'm excited to share our research in our latest blog: https://t.co/nZw5ad8SRl
We also release "SIDR" tool which parses the WSI at scale: https://t.co/ItqVdkfVza
#DFIR#Windows11#SIDR#Aon