I shared the @MISPProject playbook for malware triage that I regularly use for a first assessment on new samples. It uses MISP, @virustotal , MalwareBazaar, Hashlookup and pefile, uploads to MWDB and alerts to Mattermost. #csirt#ir#dfir https://t.co/tgOmnJtsZ4
Hey, #ThreatHunting peeps! Video of my #SecurityOnion Conf 2023 talk last week, "Achieving #PEAK Performance: Introducing the PEAK Threat Hunting Framework" is out. If you're looking for a good introduction to the framework, this might be your lucky day!
https://t.co/sBqqRWh08Z
https://t.co/03Zb3VVVqo is live! 🛡️ I thought about starting a blog page for a while now, the first steps have been taken. In the next period, I will start uploading more #KQL and security related content.
🚨After 12+ months of development, 3 Beta releases, and 2 Release Candidates, we are thrilled to announce that #SecurityOnion 2.4 has now reached General Availability (GA)!🚨
See blog post or mega thread 🧵below!
https://t.co/zbX0ln7hCt
#CyberSecurity#InfoSecurity#DFIR
Very interesting project for incident response investigation. It's a compilation of questions an investigator might pose during an incident! There are also some examples scenarios🧐 #DFIR#infosec
👉https://t.co/ExGnG49fkD
For anyone who's lost with trying to set up intelligence requirements, this framework is worth checking out. Each team's requirements might be unique, but many teams will have similar requirements, and this is a great place to start.
We are excited to announce the launch of our latest project: https://t.co/mFyRYmXNws.
The inception of this project was sparked by the emergence of the BlackLotus bootkit. Bootloaders/kits - a subject I had never delved into before. My explorations into bootloaders and bootkits led me to discover fascinating aspects, such as revoked bootloaders, EFI system partitions, the updating of DBX files and so much more. All of these were completely new terrains for me.
As defenders, we often rely on OS vendors or EDR and AV systems to guard against such attacks. However, the BlackLotus incident served as a stark reminder that conventional defenses might not always suffice.
Today marks the introduction of https://t.co/mFyRYmXNws, an initiative aimed at demystifying a subject often considered enigmatic for defenders. By shedding light on these complex topics, we hope to foster collective learning and empower all of us to better defend our organizations.
Read more about this project in our release blog:
https://t.co/k0w4oI9sIZ
Huge thanks to @nas_bench@_josehelps for helping push this over the finish line.
We hope you enjoy it and learn something new as well!
We're thrilled to announce BloodHound Community Edition (CE) -- the next evolution of #BloodHound.
Scheduled for release on 8/8, BloodHound CE has many new features & enhancements, making it easier for users to deploy, manage, and utilize.
Learn more: https://t.co/aLMuHQvwfB
#KQLADS Day 2🛡️. Are you alerting on the AsrRansomware events in MDE? This does not trigger an alert by default, thus if you have not implemented a #KQL query to identify this behavior yet, do so as soon as possible.
#MDE#Sentinel
Query: https://t.co/2rTs2urzVc