"Riddle me this, @RpughIII and @M1RC4T: how do you analyze 1000s of #phishing emails for your customers?"
See why Ray (and our team) likes @vmRay (😉), how we use it, and how it can help you protect your org’s environment: https://t.co/b8SiGDuFYc #TechTuesday
Wondering how to protect your org against #ransomware ?
Here’s some trends we’re seeing at @expel_io and some ways to harden your defenses 💪
https://t.co/ySHaiKtldc
Please RT for 13-18's interested in tech - Teen Village at @DianaInitiative - a schedule of talks, workshops, and activities for teens, to support teens exploring the idea of joining infosec - free tickets for teens!
https://t.co/Bx0RjwZzC3
Seeing automated exploitation of Internet-facing Exchange servers to drop webshell (working to confirm CVE#)
- exploit to deploy webshell
- w3wp.exe ➡️ CMD shell ➡️ PS download cradle
- c2: 86.105.18.116
Process tree below so folks can query / write detections
Also, update!
New blog post and start of a series! I know it's tough to get started in #CTI, especially if you don't have $ for formal training. I'm sharing a self-study plan that brings together links to free resources and a couple questions to consider for key topics. https://t.co/VuoBHPlbVc
Google Cloud Platform (#GCP) CTF played through Cloud Shell: https://t.co/I8PEEAIl1p
I haven't gone through it yet, but looks interesting!
"Players new to Google Cloud can get a free $300 credit."
Can we detect ZIP / JScript for initial access on 🪟?
1. Open txt editor
2. var WshShell = new ActiveXObject("https://t.co/UPvOPufD6x");
WshShell.Popup("You can configure WSH files to open in Notepad");
WScript.exit;
3. Save as 1.js
4. Double-click
5. Query SIEM / EDR
⚠️URGENT⚠️
Hackers exploit #Solorigate supply-chain backdoor in #SolarWinds enterprise monitoring software to breach US Treasury, Commerce Department, other government agencies, and cybersecurity firm #FireEye.
Details: https://t.co/iPqcm4CDpH
#infosec#cybersecurity#sysadmin
Super excited to share that we've updated the @expel_io#mindmap on detection and response in #AWS.
Via the link below you'll receive:
- @expel_io AWS mindmap
- defender's cheat sheet in AWS
- a blank mind map so you can build your own!
https://t.co/YRq8h8chYR
when a user choose to run a program as another user (right-click + shit), the process lineage will be a child of rundll32 with cmdline value like "SHELL32.dll,RunAsNewUser_RunDLL Local\{4ddb9f3f-700c-4bd6-9fc0-eaf85c01d25b}."
APT hackers-for-hire operations target financial and entertainment companies with previously undocumented #malware.
Learn more about ‘CostaRicto’ attacks here ➤ https://t.co/X1DLQUGKLB
#infosec#cybersecurity
To the "do it all" IT folks or new #SOC analysts that need a little help - a thread for you.
Cheat sheets and example queries for Endgame, CS Falcon, ATP, and CbR using a recent incident as the starting point.
cc: thanks to @AshwinRamesh94 for the query work