Added some UserAgent IOC sweeping queries for the EntraTrace project.
Queries matches in:
• Entra sign-in logs
• Microsoft Graph activity logs
• Azure AD Graph activity logs
Queries are added with prefix EntraTrace -, individual links in comments.
https://t.co/oL54u4V4uI
Investigation Scenario 🔎
Windows Defender Event ID 5007 shows DisableRealtimeMonitoring changed from 0 to 1, yet MsMpEng.exe appears to still be running.
What do you look for to investigate whether an incident occurred?
#InvestigationPath#DFIR#SOC
New RE video:
https://t.co/mOZu9oNQf1
Packed malware on Windows is common but not as common on macOS. In this video I go through two examples: one written in Rust with a simple embedded binary and another that de-obfuscates a mach-O and executes it. Also binja scripts :)
Please remember that all this AI doom is just marketing. Convincing people that nothing can be done is great for business. So is convincing people that you alone can protect them. IMO the best overall solution is to use less tech wherever possible and ignore the breathless hype.
Had some fun today crafting prompt-injection emails.
Overall, I’m impressed with how Defender for Office 365 handled them. This feels like a great excuse to finally write a new post for https://t.co/tYloGCbvh4, it’s been far too quiet there lately 😒.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
This guy is the CEO of Flock
He takes pictures of you and hands them over to the cops
But, he doesn’t want you to know what he looks like
PLEASE do NOT share his photo!
Remember the guy who hacked his gym using AI, Andrew Bird?
Well, I did a little OSINT, and it turns out he is the Conference Co-Director of Effective Altruism Global since 2015.
Isn't it interesting that every major "AI" hack has been made by people directly connected to Effective Altruism?
Theory: there are a lot of people in 'AI' who don't know how computers work, know nearly nothing about cyber security but have suddently decided they have discovered all these new things....
and because it's new to them, and they are super smart, it must be NEW to the world....
-- a theory...
People really fail to understand just how dangerous pattern of life and location tracking is. Tracking like this is used by powerful nation states around the globe to track, target and kill individuals on a daily basis. It can be used for en mass enforcement purposes like in China to arrest/imprison/kill millions of people based on race, political view or religious view and it can be used to limit peoples ability to move/travel, as well as punish people for whatever location based offences happen in the future.
Either we stop this now or governments will have the same level of surveillance and power over us as citizens that the military has over their own kinetic targets....
Anyone who doesn't think this ends with governments banning open source models, open source abliterated/heretic/apostate models and "foreign" models has no idea what is coming. The work the frontier labs are pushing for is a two tier system of power, control and freedom with AI.
Lindsey Isaacs, a 23-year-old from Palm Coast, Florida, testified about being thrown into solitary confinement for more than three days after a Flock license-plate camera wrongly tied her Dodge Durango to a deadly I-4 crash.
Jail staff told her she had to stay isolated because of how serious the charges were. The cell door stayed locked for about 86 hours.
She said she was terrified she would spend the rest of her life in prison for a wreck she knew she hadn’t caused.
At her lowest point she didn’t want to live. She spent nearly two weeks in maximum-security jail before prosecutors dropped the charges.
Flock should be sued out of existence for this.
Investigation Scenario 🔎
Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred.
What do you examine next to determine who added the credential and whether it was used?
#InvestigationPath#DFIR#SOC
I told you they'd keep pressuring things beyond social media. We see it now near globably going after app stores, gaming, social media, chat services, streaming, media services, forums, blogs, etc.
The whole internet is the eventual target, and therefore all privacy.
🚨#BREAKING: An employee for Flock told a reporter that if he wants privacy, he can "opt out of society."
So that reporter filmed a Flock worker installing a Flock cam on a public road next to his house...
...so Flock called 3 POLICE OFFICERS to pull over THE REPORTER for following them
Yep, you read that right... the surveillance camera company called the cops because someone was surveilling them install surveillance.
The reporter's name is Brendan Keefe.
He's a national investigative reporter who has been digging into Flock and police abuse of its surveillance network since January.
Flock happened to be upgrading a camera about a mile from Keefe's own house, so he parked at a distance, put out his press placard, put on a yellow vest, and pulled out a news camera.
The Flock installer saw him, packed up his ladder, jumped in his vehicle, and took off.
Keefe followed several cars back to document the next installation.
The Flock employee picked up the phone and called 911.
"I work with Flock Safety, and I'm getting followed, harassed pretty much, taking videos and pictures."
Next thing Brenden sees are THREE Georgia police cars with their lights on behind him.
"The reason why I'm stopping you is because there is a vehicle that says that you have been following them."
He was released with no charges.
Because he did nothing wrong.
Filming in public is legal in all 50 states.
Say no to age verification at the operating system level.
Say no to age verification at the app store level.
Say no to age verification for apps.
Say no to age verification for websites.
Say no to age verification anywhere online.
Age verification is a scam and a con job.