DEATHCon online/remote ticket sale round 1 will start Monday 7th of July at 00:01 UTC! https://t.co/KdtS4hFW0Q Last year they sold out in 24h 😳
On-site tickets will be available on 7/7 at around 10am local time for each site.
All details here: https://t.co/KM6GPba8AE
⚠️ Developers, please be careful when installing Homebrew.
Google is serving sponsored links to a Homebrew site clone that has a cURL command to malware. The URL for this site is one letter different than the official site.
Tip: Collecting JARMs and building a database will help in creating effective hunt rules and potential pivot points.
For example🇻🇳APT32/Ocean Lotus Cobalt Strike cloudflare malleable profiles on the servers:
5.230.35.192 AS 12586 (dupbleanalytics[.]net)
51.81.29.44 AS 16276 (adcconnect[.]me)
have unique JARM fingerprints:
`15d3fd16d21d21d00042d43d00041dfb8ded729e5899dcf86327a042f6c343`
`15d3fd16d00000000042d43d00041d6d5ac0931aa1a1c36f5f4f6d6e5e457e`
These JARMs are quite uncommon for Cobalt Strike.
The same JARM (`15d3fd16d21d21d00042d43d00041dfb8ded729e5899dcf86327a042f6c343`) and Cobalt Strike cloudflare malleable setup was also found on 45.91.200.110 (AS 211381, promos-sercurity[.]live), which is down now.
Ref:
https://t.co/BrJKJ9LH3a
Our talk from @defcon is now available! In the presented research, we document every EDR bypass technique used in the wild along with how to detect it using new memory forensics techniques and @volatility plugins. Feedback appreciated!
https://t.co/fWD57fzchj
#DFIR
Threat hunting just got easier! This new repo of detection rules is crafted by our veteran detection engineers and powered by different Elastic query languages. Get the details of what’s included and see the future of this repo here: https://t.co/84lPcK4m0j
#ElasticSecurityLabs
This is a great resource for those actively tracking threat actors. Looking forward to seeing future integration efforts!
I'd definitely love to see the inclusion of sigma rules to complement the tools section.
Exciting news! There will be an in-person location to participate in DEATHCon in Amsterdam this year! Tickets 🎟️ will be available to last year’s attendees on July 1, and generally available on 7/7
Interesting note on the #xz backdoor:
If you plot Jai Tan's commit history over time, the cluster of offending commits occurs at an unusual time compared to rest of their activity.
If the dev was pwned, it could be a sign that the threat actor contributed in their own timezone