@SwiftOnSecurity Really sucks if your entry name give away the username (e.g. if you have multiple twitter accounts). Also pre 2019 accounts have their password iterations set to 5k by default but to my knowledge @LastPass never let customers know of the new 100100 iteration max.
If you ever changed your #LastPass password iterations count, it never got updated when @LastPass changed their default to 100,100 from 5k. Anyone got a calculator to see how long it would take various iteration amounts to crack?
@cyb3rops Great cheat sheet. Will have to use it to marry it up with the alignment of log sources and log events from clients and see where gaps reside across the base.
While I never got the opportunity to meet him in person, I have so many fond memories of chatting with him in DMs and seeing his analysis on the random stuff I tag him in. Sad to lose a hero and such an amazing person in the field.
The SentinelOne team is deeply saddened by the sudden loss of our former teammate, & friend of so many, @VK_Intel. Vitali was a founding member of SentinelLabs & made numerous contributions to the security community. Our thoughts are with his family.
My first blog with @MicrosoftDART!
This is a post incident report, talking about some of the TTPs we saw in a recent ransomware incident. This really emphasizes the importance of doing a post ransomware IR.
https://t.co/NXPOqR5EST
@tsunami_cyber@avuko@Fortinet@FortiGuardLabs What follow up activity have you observed? The ones we looked into, some are potential FPs for actual admin activity or patching at the time. Still waiting for more responses and info.
Any one got logs to share regarding CVE-2022-40684? Seeing some activity for the string in the advisory user="Local_Process_Access" - you all seeing these as system config file downloads via report runner? @Fortinet@FortiGuardLabs#CVE202240684#exploit#cybersecurity#infosec
@avuko@tsunami_cyber@Fortinet@FortiGuardLabs The "Admin performed an action from GUI" does get forwarded as a system event. No instances of the other log within my sources unfortunately for confirmation.
Any one got logs to share regarding CVE-2022-40684? Seeing some activity for the string in the advisory user="Local_Process_Access" - you all seeing these as system config file downloads via report runner? @Fortinet@FortiGuardLabs#CVE202240684#exploit#cybersecurity#infosec
@GossiTheDog@Fortinet@FortiGuardLabs Unfortunately not - I don't believe we receive that level of logging. I haven't had a chance to dig into the logs for these orgs yet.
Incredible amount of pages on @issuu with a clickable box/link (usually for click here to access document) to 0365 #credharvesters#infosec https://t.co/APuke00tbx