@iamlukethedev@NousResearch Imagine how good this will be when the new iOS version drops with Apple intelligence and the context that you can get from messages when you ask Siri about the specific topic of a conversation that you had with Hermes! ๐ฅ
Organization should, of course, validate and build on top of their security tools and default configurations, but I very much blame those vendors' marketing and the fact that they are desperate to sell, promising the moon.
Too many organizations rely too much on out of the box configurations of their security tools. Itโs especially evident with EDR.
There are few tools that are truly set it and forget it.
If you donโt create any custom alerts and you donโt review your existing alerts for effectiveness and completeness, youโre leaving room for attackers.
Two LOLRMM entries worth calling out this week.
๐ Remotely, open-source, self-hostable, full remote access capability. The kind of tool that flies under the radar precisely because it doesn't look like malware. Now documented in LOLRMM.
๐ NetSupport Manager, still showing up in intrusion reports and malware delivery chains. Entry now enriched with richer artifact coverage including remcmdstub.exe, the remote command component defenders should be hunting for.
Thanks https://t.co/wWrhqNmhP2 and @Kostastsale for the contributions. ๐ซก
https://t.co/hPJH92BuWz
https://t.co/3E2g9gylVE
Last week we loaded RMM tools and vulnerable drivers live.
Today we're bringing in @Kostastsale from the EDR Telemetry Project to talk about what defenders can actually expect security products to see, alert on, and miss.
Looking forward to this one.
Check out the EDR Telemetry project here https://t.co/2BPXgZ2I3G
We consolidated the EDR Telemetry methodology into a single page.
No more digging through scores, eligibility, contribute, and blog posts to piece together how we evaluate telemetry. Evidence standards, status taxonomy, direct vs inferred rules, the vendor-assisted workflow, and the 75% governance threshold are all in one place now.
Live at https://t.co/55CY2VFBjv
Seeing feedback like this makes us push even harder to provide value and unique intrusions for our members!
Our new cloud intrusions take a ton of time to put together and include choose-your-path style questions and a learning module. Same with all of our other intrusion labs๐ช
Feedback like this is exactly why we keep pushing Threat Hunting Labs beyond the usual endpoint-only path.
Windows investigations still matter, and we have real cases covering the classic enterprise attack chains.
But most training platforms have been serving the same Windows intrusion for years.
You finish one, then the next one feels like the same case with a new title.
Modern analysts need more than that.
They need cloud intrusions, Linux activity, identity abuse, SaaS evidence, exposed services, and hybrid environments.
That is the range we want Threat Hunting Labs to give them.
I really like seeing posts like this. Itโs great to see this kind of recognition from CEOs towards their teams.
Good results donโt just happen on their own and definitely donโt come from marketing. They come from engineers fixing gaps, product teams prioritizing the right things, field teams bringing real feedback, and customers pushing for better visibility.
When that work shows up in the results, it deserves to be highlighted, and we are happy to do do that.
The EDR Telemetry Project is not here to point out what is bad and bash vendors. We highlight the good, too. The difference is that we do it independently, with an open methodology, and with information that is actually useful to the people using these products.
Not just C-suite reports, magic quadrants, or high-level summaries that do not help much when you are trying to investigate an incident or hunt through the logs. This is the kind of evaluation Gartner will never come remotely close to doing.
We offer open results, open methodology, and practical value for practitioners.
Hard work pays off, and weโre glad to see teams getting the recognition they deserve ๐
Business email compromise is among the most costly attacks for companies. In this case, we look at a Microsoft 365 intrusion where a mailbox was compromised.
This case provides logs that are rarely available on training platforms, since the data contains real-world noise and traces of malicious infrastructure.
โข Sign-in logs
โข Microsoft 365 audit logs
โข Exchange message trace
โข mail events
โข Graph activity
โข mailbox audit evidence
Available now in THL ๐
๐ข ๐ก๐ฒ๐ ๐ฐ๐น๐ผ๐๐ฑ ๐ถ๐ป๐๐ฟ๐๐๐ถ๐ผ๐ป ๐ท๐๐๐ ๐น๐ฎ๐ป๐ฑ๐ฒ๐ฑ, ๐ฟ๐ฒ๐น๐ฎ๐๐ฒ๐ฑ ๐๐ผ ๐ฎ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฏ๐ฒ๐ฑ ๐๐๐๐ถ๐ป๐ฒ๐๐ ๐๐บ๐ฎ๐ถ๐น ๐๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ (๐๐๐)
We responded to a business email compromise and preserved the telemetry for hands-on investigation.
The case spans Entra sign-ins, Microsoft 365 audit logs, Exchange audit activity, Graph activity, mailbox access evidence, alert records, and message trace.
We are releasing the same intrusion across three disciplines:
- Threat Hunting: follow the access patterns, cloud activity, and investigation pivots.
- Incident Response: reconstruct the timeline, scope the compromise, and determine what the evidence proves.
- Detection Engineering: turn the observed behavior into practical detection logic.
One intrusion. Three ways to work the evidence.
https://t.co/U3Qdb9iz9F
Available now on Threat Hunting Labs for Pro subscribers.
๐ข ๐ก๐ฒ๐ ๐ฐ๐น๐ผ๐๐ฑ ๐ถ๐ป๐๐ฟ๐๐๐ถ๐ผ๐ป ๐ท๐๐๐ ๐น๐ฎ๐ป๐ฑ๐ฒ๐ฑ, ๐ฟ๐ฒ๐น๐ฎ๐๐ฒ๐ฑ ๐๐ผ ๐ฎ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฏ๐ฒ๐ฑ ๐๐๐๐ถ๐ป๐ฒ๐๐ ๐๐บ๐ฎ๐ถ๐น ๐๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ (๐๐๐)
We responded to a business email compromise and preserved the telemetry for hands-on investigation.
The case spans Entra sign-ins, Microsoft 365 audit logs, Exchange audit activity, Graph activity, mailbox access evidence, alert records, and message trace.
We are releasing the same intrusion across three disciplines:
- Threat Hunting: follow the access patterns, cloud activity, and investigation pivots.
- Incident Response: reconstruct the timeline, scope the compromise, and determine what the evidence proves.
- Detection Engineering: turn the observed behavior into practical detection logic.
One intrusion. Three ways to work the evidence.
https://t.co/U3Qdb9iz9F
Available now on Threat Hunting Labs for Pro subscribers.