given the rise and impact of ICS phishing, we open sourced a tool to help the SOC clean up malicious calendar invites even if you’re not using @sublime_sec. please xpost for reach: https://t.co/Ifj79yCd0v
We've released a new detection for an ongoing Pikabot campaign: https://t.co/gNAijjdsbW
This covers both behavioral detection of the delivery technique (Plaintext URL -> Archive -> JS) as well as IOCs in @abuse_ch URLhaus + MalwareBazaar
h/t @affje0x65@k3dg3@samkscholten
📣 Hello fellow X'ers. As some of you may know, @ajpc500 and I will be running an email detection engineering and threat hunting workshop at DEF CON and BSidesLV in a couple weeks.
We are looking for a small number of folks who'd be interested in attending an "alpha" version of the workshop *for free* next week, in exchange for feedback and some @sublime_sec swag 🌶️
I know that this *may* conflict with your plans to watch Barbie (I had to cancel my plans), but we'd greatly appreciate it.
Date: Wednesday, August 2nd 2023, 2pm-6pm ET
Register here: https://t.co/azEWmvZtNY
i was feeling pretty (inspired) last night and decided to record myself writing a new @sublime_sec detection for a SharePoint phish
it uses computer vision to detect the SharePoint logo, OCR to convert the image to text, and NLU to analyze its output for credential theft language
We're excited to launch Sublime Thoughts: our new Blog.
Our first post features @rw_access introducing the magic behind Sublime: Message Query Language (MQL), the first universal DSL purpose-built for preventing email attacks, threat hunting, and more.
https://t.co/LTzOL4ovgp
I'm extremely excited to announce that @sublime_sec has raised $9.8M in funding. I am so proud of what we've built, and this is just the beginning.
Thanks to our team, customers, community, and investors for their trust and support. Onward.
https://t.co/2U2LwCPiua
it took @vector_sec 29 minutes from seeing this write-up to writing, backtesting, deploying, and sharing a detection to his public rule feed. he literally beat me to it
https://t.co/mF2fmjztpH
In response to the invasion of Ukraine, we (@sublime_sec) are doing what little we can to help affected organizations detect and hunt for Russian phishing TTPs.
This includes 3 things starting today:
1/n
The latest from Sublime! I love Love LOVE empowering people to wire systems together, and webhooks open up countless possibilities. Can't wait to see how folks use them!
Announcing arbitrary Webhook actions.
Write a rule to flag any type of behavior in your email environment, set it active on any or all of the mailboxes in your domain, and trigger a webhook notification to an arbitrary HTTP(S) endpoint.
Available to all free Platform users now.
What is a Sublime detection rule?
- Sigma rules run on logs
- Snort rules run on packets
- YARA rules run on binaries
- Sublime rules run on email
(2/10)
The free Sublime Platform now supports real-time detection for both Microsoft 365 and Google Workspace email environments.
Write a detection rule for a phishing technique, share it with almost any other organization, and they can deploy it today. (1/10)
@mitchellh Very much looking forward to it, and you're welcome! Yes, the more mistakes and "bad ideas", the better. Can never have too many reminders that's all part of the process...
@mitchellh I read in your terrific AMA @ https://t.co/FK99zqLHaS that you have your original handwritten sketches for Vagrant/Packer/Consul/Terraform. Would you be willing to share any of those? It would be incredible to have those bits of history in the public domain!
@rrhoover I'll do all the work for you if you'd like to add a button like this to PH! Also ty for the dead-simple landing page: https://t.co/fDCpOSTofr