Announcing the JA4+ Database!
https://t.co/ZqhIkM1dNn
Under *very* active development but ready for use. Expect orders of magnitude more data and JA4+ combinations over the next few months. I recommend downloading the DB and loading up in your data explorer of choice for now.
Everyone has a different use-case for JA4+ so we're trying to make it easy to find what you're looking for. Below are some examples you can do in a data explorer like Elastic.
JA4 to JA4H
JA4 to User-Agent String
JA4 to Application
JA4 to Library
JA4T to Device
JA4X to Device
JA4X to Application
JA4X to Issuers
JA4X to JA4T
etc. etc. etc.
There are so many combinations and use cases for each.
Please send me any feedback, improvement suggestions.
🚨IMPORTANT🚨 We have observed that the implant placed on tens of thousands of Cisco devices has been altered to check for an Authorization HTTP header value before responding [1/3]
! ALERT ! A vulnerability has been found in multiple versions of Fortinet Fortigate devices when SSL-VPN enabled. ACSC recommends organisations apply the available patches immediately, and investigate for signs of compromise. For more details visit https://t.co/1zBXR0EfLJ
.. that I was able to help people uncover threats, prevent further damage, determine the extent of the compromise, kick out the bad guys & ruin their day
Our industry has significant demand for detection engineers that support DFIR & SOC teams
Learn YARA, Suricata, Sigma, Zeek!
What people seem to miss:
The #Log4Shell vulnerability isn't just a RCE 0day.
It's a vulnerability that causes hundreds and thousands of 0days in all kinds of software products.
It's a 0day cluster bomb.
More modules! Just merged two new modules from @thetechr0mancer - Sublist3r and DNSDumpster (from the great @hackertarget team).
Stopped counting how many modules we have now, but it's over 200. Reply with any we are missing!
On master: https://t.co/NvScnUErx6
#OSINT
Extending DetectionLab. A Vagrantfile to deploy Ubuntu with #osquery and ossec pre-configured to send logs to #Splunk on Logger. https://t.co/sHH209Iosr