@PandaRE__ I've been using a Mac for 3 years now at work as well (against my will, obviously). Running a 34 and 32, both curved and I've been using a Targus docking I got in 2020. Still works.
https://t.co/bC8SUyuMWz
There's a newer version, probably better. More expensive though.
We’re really excited to publish this one alongside @malbearlabs 🥳
For the first time at Threat Hunting Labs, we’re releasing a real intrusion as both a public investigation report and a hands-on lab:
*️⃣ From SEO Poisoning to Custom RMM and Cobalt Strike
Read exactly what happened in this real intrusion, then open the lab and investigate the same evidence yourself.
It started with an administrator searching for RVTools and executing two malicious downloads on the same workstation. The activity then split into separate paths involving browser process injection, Level RMM, another custom RMM-style service, and eventually a Python-hosted Cobalt Strike Beacon.
What stood out to us was the amount of remote-access tooling involved. Instead of relying on one method, the attackers ended up with multiple access paths using legitimate RMM software, custom tooling, and Cobalt Strike.
You can investigate the evidence across Threat Hunting, Incident Response, Detection Engineering, and Malware Analysis.
🎥 When you finish, every lab includes a recorded walkthrough where we explain how we investigated the activity and arrived at the answers.
MalBear Labs went much deeper into the recovered payloads and malware, complementing our intrusion analysis with their own companion report.
And a big thank you to @securityaura for helping us with the threat intelligence context around the SEO poisoning and malicious samples.
Lab:
https://t.co/6zGJ9En7zo
Intrusion report:
https://t.co/HIwTgP1gxn
MalBear Labs:
https://t.co/uRczAOpoZH
New @MalbearLabs collab with @ThruntingLabs and this one is a GOOD one: four payloads from one intrusion, all built to waste an analyst's time.
PavokwiLoader was the spicy one - WinMain is a single function with over 80,000 instructions and over 2,000 MBA clusters in that one function.
Also in there: RMMCRAT, a custom C++ payload wearing an RMM agent's clothes, a fake RMM service, and a Python loader that brute-forces its own decryption key instead of storing it.
@ThruntingLabs traced the intrusion and turned it into a hands-on lab. Big thanks to @SecurityAura for the threat intel context on the SEO poisoning and the samples 🐼
MalbearLabs teardown: https://t.co/e5vVPFS3rK
We are super stoked to publish this collab with @ThruntingLabs: four payloads from one intrusion, all built to waste an analyst's time.
@ThruntingLabs traced the intrusion and turned it into a hands-on lab. Big thanks to @SecurityAura again for the threat intel context on the SEO poisoning and the samples 🐼
Our teardown: https://t.co/8ldpXYPAq6
THL Lab:
https://t.co/ERHeubcZVM
THL Intrusion report:
https://t.co/0J4cQBDvZl
Have you read some of our @HuntressLabs blogs and thought to yourself, damn, this looks like fun?
Do you love logs and investigating incidents ?
Want to help protect the 99 percent?
If it's a yasss across the board then I have good news for you, I'm hiring for 2 positions on our Tactical Response team!
Check out the posting below and apply!
https://t.co/19E93y4SQ1
Giveaway: I've got 5 FREE entries to the first public Threat Hunting League competition from @ThruntingLabs! Hunt an Iranian APT campaign in a 4-hour personal lab using Splunk, Elastic or Azure Log Analytics. All levels welcome.
Leave a comment and I'll draw 5 winners on Wednesday 9/23.
🏆 Prizes:
🥇 13Cubed Investigating Windows Endpoints (1 yr access)
🥈 2 months THL + a private 1:1 threat hunting coaching session
🥉 1 month THL
Competition runs Sep 25–27. Details:
https://t.co/FU1R0K4IDJ
Releasing EntraTrace
EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID.
The tool is still in early development, feel free to have a look and share your feedback!
https://t.co/E6qSNQBW8p
@fabian_bader Honestly hope nobody read my PIM and AdminByRequest justifications.
... I haven't been called in by HR yet so either nobody reads them, or the auditors are getting a kick out of my justifications and wants to keep them coming.
@nas_bench Hot take: A lot of people talking shit or giving shitty opinions about incident response, have probably never responded to a single alert, even less an incident, in their life 😂
@techspence Security would be so much easier if orgs dropped their God damn applications in proper folder architectures and actual folders for, I don't know, installed programs.
That rule would suddenly become much easier to deploy 🥲
Organization implements MFA for sign-ins.
User receives a phishing email.
Performs a full sign-in on the phishing domain, INCLUDING passing the MFA challenge, manually, WILLINGLY, of his own violation.
"MFA BYPASS ACHIEVED!"
Bypass probably means something entirely in InfoSec
GTG, BleepingComputer and Malwarebytes Forums are how I got started in cybersecurity and got me to where I am today.
Malware Removal online, to DFIR.
A lot of what I learned and do everyday comes directly from these forums and the time I spent there as MRT.
RIP to an era.
The fact that normal people/users are still discovering ClickFix today and calling it new and highly dangerous because it looks so legit is probably why macro-laced documents and Invoice.pdf.exe worked all these years.
And still works to be honest.
@chrissanders88 Based on the location of the
.iso too, unless the user REALLY messed up a local "Save to" action to that folder, I would be very tempted to say that something else (automated) dropped that ISO there.
Though it would be weird because ISOs mostly rely on user interactions.
@chrissanders88 The fact that there was code execution because of the rundll32.exe launch is enough for it to be an incident.
Question for me at this stage is what's the scope and the impact. Which would include determining if the payload executed successfully or not.