I am excited to share what our team’s been building for Ignite: https://t.co/VkGBtF7m6r
Download mindmap, checklist and blueprint here!
We are working on next version to include A365 and more! #Copilot#AgentBlueprint#AgentGovernance#M365Copilot#MCS
tl;dr archived stuff, see link below
Earlier today a GitHub titled "I-S00N" leaked supposedly sensitive Chinese government data - specifically related to offensive cyber security.
The initial discovery, and documentation of the documents, derive from @AzakaSekai_. We have archived his research and notes on the material.
It should be noted that they *probably have not covered the material in totality and more information can be expected to be released in the following days from either Azaka, or other Cyber Threat Intelligence experts familiar with Chinese state-sponsored activity.
Furthermore, the materials are written in Mandarin. We have made no attempt to translate the material to English and we do not speak Mandarin, hence we cannot provide any opinion or speculation on the material. We will leave that painstaking task to individuals who speak Mandarin, or people who feel like trying to translate the documents accurately.
What an exciting start to the week:)
You can view the archived materials here: https://t.co/pAmOcvbTV5
Check out the latest #CybersecurityAdvisory issued by the UK and US to help organizations counter malicious cyber activity by APT28 actors to exploit weak Cisco routers. Read more for recommendations to defend your network against this activity: https://t.co/4OHdXKeEsu
@reprise_99 Sysmon with good config installed on every machine for the win 😁, but question is how your Siem or log collector analytics and logic or hunting consume this awesome knowledge.
@0gtweet Enterprise customers managing updates should select the detection build 1.367.719.0 or newer and deploy it across their environments.
Microsoft Defender for Endpoint provides customers detection and alerts for the described vulnerability.
It's been a long road but it's finally here. It's been great working on this with @_EthicalChaos_, I learned so much! Special thanks to @harmj0y for the original tool and putting up with me through development ;-) Say hello to Rubeus 2.0:
https://t.co/fHwCfpr1e6
We are monitoring a REvil 'supply chain' attack outbreak, which seems to stem from a malicious Kaseya update. REvil binary C:\Windows\mpsvc.dll is side-loaded into a legit Microsoft Defender copy, copied into C:\Windows\MsMpEng.exe to run the encryption from a legit process.
Invoke-ACLpwn
Invoke-ACLpwn is a tool that automates the discovery and pwnage of ACLs in Active Directory that are unsafe configured.
- thanks for sharing @foxit#infosec#pentest#redteam
https://t.co/GIQgLF0nLb