New blog on detecting LAPS decryption in AD environments.
Spoiler, detecting successful reads is still unreliable, but at least we know what triggers the 5071/F event :')
https://t.co/tpk5kazH8R
#LAPS#Windows#DetectionEngineering#ActiveDirectory
I don’t think the AI doom messaging from OpenAI and Anthropic is really about safety at all
I think the goal is to make themselves too important to fail: get regulated, raise the barriers for competitors, become “critical infrastructure” and make government support almost inevitable if their extremely capital-heavy financial models start to crack.
I can’t prove that this is the motive. But the incentives line up remarkably well.
“Our tech will transform the entire economy, but it’s also far too dangerous to leave unregulated” is a very convenient story when you need govs and investors to believe they simply cannot afford to let you fail.
Great news! Yesterday's Patch Tuesday fixed PPLFault. Thanks so much to everyone at Microsoft who helped get this 510-day bug fixed (🙌 especially @PhilipTsukerman and @depletionmode). If you'd like to know more about the fix, see my article: https://t.co/8s8qIBLr5J (1/5)
Windows Hello fingerprint security failures! Great work from @blackwinghq
"We initially implemented this attack on a Raspberry Pi 4, but reimplemented it in TamaGo on the USB armory since the RPi4 takes too long to boot and we wanted a quicker demo. 😜"
https://t.co/tKjCzDExGb
Unable to dump LSASS using the previous script? No problem, just ask S1 for a Live Kernel Dump instead! You can open this in windbg (and use mimilib.dll) and go from there.
https://t.co/8Ci5u2jIvR
Modern day vulnerability management is great at finding a whole bunch of stuff that doesn’t matter that makes IT teams deprioritize stuff that actually matters in order to drive down a number to show artificial risk reduction
TIL
In MSEdge, you can open the developer tab, and make sure the network table is recording.
Then go to a webpage.
Do a thing.
Check network tab in developer mode, right click and choose “copy as PowerShell”.
This makes automating pages without an API so much easier…
Lucy has a nice summary of the Defender for Cloud and Sentinel capabilities here :)
Part 1: https://t.co/iqRLy5XE70
Part 2: https://t.co/PPegRKoWUE
Part 3: https://t.co/Bq3MV3rNps
Some good config callouts, examples, and such :)
AWS HAS ENTERED THE HUGE HONEYPOT NETWORK GAME LETS GOOOOOOOOOOO
https://t.co/uEHfoynJTS
stoked to see @awscloud finding success with honeypots. I continue to carry an incredibly healthy respect for the excellent folks at @AWS_Security.
BLUF: huge, adaptive honeypot networks are effective where the rest of the cyber vuln mgmt, perimeter security, and cyber threat intel industries are failing miserably.
having spent the last six years building, expanding, tuning, and operating @GreyNoiseIO, I figured I'd share some thoughts in no particular order:
AWS is moving 5.5 billion events in one quarter, which is about 61m events on average per day (The average routable IP on the internet receives between 10k and 100k unsolicted packets per day)
we move about ~400m events per day at greynoise (receipts attached). averages are useful in some stats for honeypot networks, averages are misleading in others.
> "The sensors observe more than 100 million potential threat interactions and probes every day around the world, with approximately 500,000 of those observed activities advancing to the point where they can be classified as malicious."
^^^^ 0.5% malicious tag rate is a great place to start, but leaves a lot of wood left to chop. We've gotten up to between 30% and 50% malicious tag rate with high confidence (receipts attached). You're going to need to really really build up that corpus of detections.
if I were having a conversation with the leads/architects/product managers of AWS's MadPot, I'd give the following (very unsolicited) guidance:
- Get into every single other cloud provider. Collection from AWS is not enough. You need to be in every country and every provider.
- You're going to need to collect from non-cloud (residential, business, mobile) networks as well.
- Persona & state management (what the sensor looks like, and when) is going to become increasingly complex and challenging. Think about a strategy for this.
- You're going to have to allow sensors to be compromised eventually, and you're going to have to have solid data models for endpoint telemetry in addition to network telemetry
- You're going to need to eventually combine the sensor data with port scan/crawl data in order to achieve "malicious" or "compromised" verdicts.
- If you don't have a strategy for benign internet scanners, you'll need one
- Primitives for byte-level pattern matching in unstructured byte data in the state-of-the-art in datastores are very poor, you'll need to fill the gaps here
- If you don't have an opsec strategy (counter-fingerprinting) then you'll need one
- Prepare a strategy for dealing with spoofed TCP SYN noise storms
- off the shelf detections and IDS signatures are built for middling and detecting on traffic for networks that also do business things (service users and servers, etc). They will provide value but they *will not all work out of the box* on honeypots for a multitude of reasons.
- The right enrichments are crucial for decorating the data. Attacks will practically pop out of the computer screen when you enrich and lay the data out correctly.
- You're going to need to partner with the cybersecurity research community to win this game- think about how the rest of the world can contribute data or analysis.
- Don't let your eye off the ball on achieving high and tight, rapidly shifting block verdicts.
- Store *everything* *forever*.
I'm excited to see how AWS's MadDog honeypot evolves. Huge adaptive distributed honeypots are effective but hard to build and scale. Congrats team- this is one of the best writeups I've seen to date!
Dear DFIR colleagues,
Always be wary of 404 error codes in web server log files. Some webshells intentionally send this error code to deceive you into thinking the request failed.
https://t.co/xfAyqFuesC
When you log into a Linux system, make it a habit to look at the processes with this command:
ps -auxwf
This will list out all processes in tree format. It makes it easy to spot unusual activity.
For instance, this is what a PHP reverse bindshell backdoor will look like.
How the signing key got stolen.
IMO a must read for all infosec practitioners
https://t.co/ZYvwauGxvG
I am very appreciative of MSFT for the level of detail they've released here. I wish it were a little faster, but IDK? maybe it took them a while to get this done?
The industry accepts MS can't protect your OS which is why people buy EDR/etc. However MS doesn't license your OS logs and telemetry for more money. The cloud shouldn't be any different additional logging isn't a paid feature its a core product function.
Check out ShellSweep, an innovative PowerShell/Python/Lua tool designed to detect potential webshell files. It uses entropy calculation to estimate the likelihood of a file being a webshell. Flexible in its usage, it allows for specific file types, directories, and hashes to be included or excluded. Sweep away the evil with #ShellSweep! 🧹💻
https://t.co/46iAgR22r1
Did you know explorer.exe can directly use WebDAV.
Building an attack chain involving a .zip TLD, Windows Explorer, WebDAV and a jar file.
https://t.co/MnZtTD2ZMd
"I'm the cybersecurity director at NSA and you could absolutely craft a phishing message that would get me to click a link. You’ve got to design your architecture to assume the humans are humans and bad things will happen." @RGB_Lights
AMEN