Professional SOC Monkey and herder of cats @redcanaryco, gamer, volunteer firefighter, blah blah wavy hands things and stuff
Opinions are from some monkey
One of the things that makes Blue Mockingbird so interesting is the way it uses the COR_PROFILER environment variable to achieve persistence: https://t.co/8ocDsQ5OUD
We're monitoring a threat we've dubbed "Blue Mockingbird" that is deploying Monero cryptocurrency-mining payloads on Windows machines at multiple organizations. https://t.co/EIkLEu1LuJ
Invoke-AtomicRedTeam started as a framework for executing atomic tests. Now it's much more than that, so we spun it out as its own open source project. Here are some key new features: https://t.co/9jEjTb54T3
Our VP of #securityoperations@FlyingMonkey127 and Twitter #CISO @mikeconvertino will host a conversation over beers and appetizers at Optimism Brewing Company in Seattle on September 19. Register to join us! https://t.co/Bi2RhFtPBq
Join @FlyingMonkey127 and Twitter #CISO @mikeconvertino at Optimism Brewing Company in Seattle on September 19 for a technical discussion on how you can use @MITREattack to improve your #security program: https://t.co/UrGwkKS2G2
The Local Security Authority Subsystem Service (lsass.exe) doesn’t typically spawn other services, so it was particularly suspicious when we recently observed it launching rundll32.exe. https://t.co/6q7ZRYJvel
A good tipoff to Trickbot activity is the use of PowerShell to manipulate Windows Defender. 90% of the times we saw this command in the last 30 days the parent process was malicious:
"powershell.exe Set-MpPreference -DisableRealtimeMonitoring $true"
As a longtime @CarbonBlack_Inc partner, we're excited to be among the first MDR vendors to deploy CB ThreatHunter to customers: https://t.co/gzpSX0DT2g
@rockyd@redcanaryco If you ever want to chat about what we have done, lessons learned, or just compare notes, hit me up with a DM. Building teams and people is a favorite topic of mine.
OSX/Shlayer infections are widespread, and the macOS #malware delivers a couple #adware strains with varying persistence mechanisms that make the threat difficult to mitigate. Here's our guidance: https://t.co/6u5uKe1NGT
Keisha Levan of @redcanaryco will demonstrate how to optimize team resources, allowing time for more fulfilling and proactive work.
#SANSBlueTeam Summit agenda: https://t.co/8v9sebGjFV
#Security tools—no matter how costly—have limitations. The trick is to compensate for these with controls that reduce the impact of blind spots. @ForensicITGuy on detecting threats with limited data: https://t.co/XBgXSNNXcV