Because you typically cannot install EDR on edge devices like FortiGate, your defense strategy has to shift. You need to stream your logs to a SIEM.
Get the full threat breakdown and defense playbook from @LabsSentinel researcher @spiderspiders_ and DFIR members Stephen Bromfield, Mary Braden Murphy, and Amey Patne: https://t.co/CndvPdlabl
What happens when the FortiGate next-generation firewall protecting your network becomes the backdoor? 🚪
Our DFIR team has been tracking a wave of FortiGate NGFW compromises. Attackers are exploiting vulnerabilities to extract config files, steal service account credentials, and move laterally.
The worst part? Most organizations lack the log retention to see how it happened. 🧵👇
Signal’s encryption is irrelevant to the discussion. The real problem with sharing Top Secret data over Signal is not the security of the app, it’s the security of the phone. And mobile phones are not secure against state level threat actors.
"oTheR cOmpAnieS haVe MorE mAlwArE thAn yOu"
Ted Talk time.
First of all, we're not a company. We're just a bunch of internet nerds wildin' out on a computer.
Secondly, right now vx-underground ingests roughly 120,000 malware samples a month with a budget of a slice of pizza and some weird lookin' lint we found in our pocket.
The reality of the situation is large organizations ingest absurd quantities of malware. Antivirus vendors, (some) Threat Intelligence vendors, and Endpoint Security vendors ingest terabytes of malware a day.
We are aware of some organizations which ingest 500,000 - 1,000,000 malware samples a day. Whereas some AV vendors reportedly ingest over 5,000,000 malware samples a day. These organizations dwarf us.
Part of the reason why is simple: intelligence. Vendors are ingesting malware in large quantities, through various means such as honeypots, sharing between organizations (private exchanges), submissions from VirusTotal, and malware captured from user endpoints.
They use this data to track and monitor malware campaigns, C2 addresses (IPs or domains), look for modification of code bases, and look for any missteps and leaking of PII. They then distribute this data and update security rules, update known-good and known-bad SHA256 collections, and often work with law enforcements agencies to takedown Threat Groups. This is work that happens everyday, around the clock, 24/7 and these organizations work hard monitoring malware nerds.
Our purpose of collecting malware is historical in nature – people can download the malware, reverse the malware, and study the malware. Our malware is often hammy downs (metaphorically speaking) from larger organizations and is rarely cutting edge. It would be difficult to identify a new Threat Group from our malware collection. The advantage of our collection is it is often difficult for people to even get hammy down malware without begging someone (or some organization) OR the malware samples are scattered all over the place. Our collection is in 1 singular location making it easier to get the cool stuff nerds wanna study.
Thanks for coming to our Ted Talk.
Wishing you all a Happy New Year! 2023 was my first conference keynote, and I launched https://t.co/gRXjyEfJ8X, both of which were goals I had set for myself (well, giving a talk, the keynote was a bonus). If you're planning your own 2024 goals, I hope you achieve them!
I've created a detection repository to help your organization detect this behavior: https://t.co/y5GpP2SLsN
I've got @sigma_hq , @sublime_sec , and Exchange rules. High fidelity, actionable, and responsive to the latest TTP!