We uncover malicious infrastructure through active monitoring to flag emerging threats. dropbox-share[.]ga is a live phishing site with a 0/95 VT score that captures 2SV tokens and relays them via the Telegram Bot API to the actor for instant use 💥
@Tesla model Y is the hardest $65k I’ve spent. Not because I’m unwilling, but the numerous #Failures in the ordering process, lack of follow up from Sales “Specialists”, Errors in DMV paperwork, lack of Customer Service; This is BEFORE calling out Build Quality #1990Kia@elonmusk
If you’re looking to completely waste your money during #COVID19 Please order @adidasoriginals@adidas face coverings! To add salt to the cut, try calling customer service for them to provide nothing more than “they are non-returnable”. #Defective#DoesntMatter#SweatShopMade
Had severe FOMO from missing BH/DefCon in Vegas. Saw @alphasoc was giving out some Faraday bags and they sent me one...AND SO MUCH MORE. Awesome job guys!
Following-up on the @TalosSecurity#DNSpionage research published in November, @lastlineinc dig into the Agent Drable implant targeting organizations in Lebanon and UAE and its DNS tunneling mechanism >> https://t.co/QVtQupAUZV
Got Splunk? Evaluate our app for 30 days without restriction to uncover infected hosts and emerging threats in your environment. Hundreds of security teams use Network Behavior Analytics for Splunk to solve difficult use cases. Learn more >> https://t.co/BKWpaRYg0J
Network Behavior Analytics for Splunk provides security teams with instant threat hunting options and deep visibility into their networks. In this video we walk through the analytics features, use cases, and deployment options >> https://t.co/Qb1ZJSkvyr
The webinar we recorded with the @corelight_inc folks back in November is available! Learn how Corelight sensors gather rich DNS logs, and how you can process that telemetry to uncover emerging threats >> https://t.co/WDnAxJMtgp
Network Behavior Analytics for Splunk 1.1.8 released 🚀 New features include tooltips for individual flags, @maltiverse_com support (under the Actions dropdown) and rare HTTP user agents displayed in the Performance view >> https://t.co/BKWpaRYg0J
Webcast: Join @alphasoc as they detail common #SOC blindspots that adversaries exploit and how you can measure the visibility of your #SIEM apparatus with free, open source tools | https://t.co/FOfkVaYgxD
We're seeing an uptick of #SmokeLoader and other traffic this week. Interesting C2 indicators to hunt around include viewmanage101[.]tk, pielaboastwattallaht[.]host and 5.45.69[.]149:7000. The associated infrastructure (affiliate 1501) can be found here >> https://t.co/42J7UerrrA
The AlphaSOC Analytics Engine provides deep classification of network telemetry and enables security teams to uncover emerging threats. In this video we describe the system architecture and integration options >> https://t.co/jAefMnQPEf
Third-party VPN services, unwanted programs, and remote access packages (e.g. TeamViewer) are often used to retain access and exfiltrate data within environments. Most SIEMs and security tools are blindsided >> https://t.co/Q62BxbnY8X
We're proud to announce that @osquery support is coming to the AlphaSOC Analytics Engine, enabling teams to hunt threats and process both network and endpoint telemetry. Contact us via DM here or email [email protected] to be part of the pilot program 🚀
Interesting competitive analysis between AlphaSOC and other security analytics providers. You won't find any talk of #Cyber#AI on our site, the pricing is public (..it starts at $8/endpoint/year), and you can self-provision an evaluation API key without having to talk to anyone!
To defend against evolving #threats and unknown actors, #security teams need to leverage analytics. Learn how with @alphasoc | 2/20 @ 1 PM ET | https://t.co/FOfkVaYgxD
Automatically flag #Hancitor and other malware infections without threat feeds or indicator lists by using our analytics apps for Splunk and other platforms. Read @malware_traffic's original research here >> https://t.co/QaJMgW6g3l