From OneNote to RansomNote: An Ice Cold Intrusion
🌟Analysis & reporting completed by @iiamaleks, @IrishD34TH, and @Miixxedup
🎵Audio (New Voice!): Available on Spotify, Apple, YouTube and more!
🏹Services: https://t.co/k8UVEOdKTQ
📚Report: https://t.co/Ll3pwfh9fp
SEO Poisoning to Domain Control: The Gootloader Saga Continues
🌟Analysis and reporting completed by @_pete_0, @malforsec & @r3nzsec
🎵Audio: Available on Spotify, Apple, YouTube and more!
🏹Services: https://t.co/k8UVEOdKTQ
📚Report: https://t.co/Jk1LFE046i
As a fan of non-obvious persistence mechanisms I had to try to collect (and categorize!) them all. It has just started, first 10 entries appeared, and more is coming each day.
I am happy to share it. Enjoy, contribute, use freely - https://t.co/PWb2ofSZjQ
Enemybot, a Gafgyt-based Linux botnet, observed April 11 exploiting #SpringShell. This botnet incorporates the exploit within the binaries themselves – both the webshell and command injection stages. IoCs at https://t.co/skL81VSuhM More on SpringShell at https://t.co/5gs5aJTEUv
2021 Year in Review
➡️Summary of tools we've seen
➡️Summary of indicators of attack
➡️Opsec failures
➡️Most common TTPs of the year and much more
https://t.co/D0k2TxLyeJ
Report lead @kostastsale
Contributing analysts @ICSNick, @yatinwad, @_pete_0 and 1 unnamed contributor
I found a vulnerability in #Azure allowing me to access Azure accounts of companies worth billions
We all know vulnerabilities exist. This isn't an injection, XSS, or RCE.
But the crazy thing about it?
It took 2 hours to discover. 🤯
Here's the story of #AutoWarp👇 (1/10)
Very excited to announce FLARE is open sourcing GoReSym, a standalone cross platform/architecture tool for Golang symbol recovery! Go checkout our blog here for details: https://t.co/tPEnHOjso0
Sometimes we focus too much on the payload of an attack and can miss signals that could have prevented it. New blog post ✍️ Detecting malware kill chains with Defender and #MicrosoftSentinel - https://t.co/LlB3FTTJRn
Other day I asked for large repos of detection rules here is the running list of responses.
Elastic - https://t.co/OwVwhHU3nZ
Sigma - https://t.co/LygEgGSBeB
Chronicle - https://t.co/4QqDyzJCWC
Splunk - https://t.co/csHzWFCpLE
Falcon Force -https://t.co/9cOd5elj3U
Empire 4.4.0 is being released this week to @kalilinux and sponsors. Here are just a few of the new features:
- New Process Injection Module
- Auto copy Stagers to Clipboard
- Custom bypass yamls
- Modernized Psinject
#redteams#cybersecurity#infosec
Let me introduce you to KrbRelay, the only public tool for relaying Kerberos tickets and the only relaying framework written in C#.
No-fix LPE + No-fix Cross-Session, VDI deployments has never been more broken.
Demo at Images/demo.mp4 !
https://t.co/xmZM1X7lqI
Happy Friday, #BlueTeam friends! Here's a little #opensource tool I wrote to help you check your detection alerts for domain fronting #beacon network traffic. You can set front/back domains, polling, jitter, etc just like Cobalt Strike but harmless: https://t.co/d0dhOOrJOQ
Obfuscating Malicious, Macro-Enabled Word Docs
'...summary of a recent macro I made and the research that inspired the decisions that built the macro.'
#infosec#pentest#redteam
https://t.co/o6GFWLy5sN
Microsoft identified a unique destructive malware operated by an actor tracked as DEV-0586 targeting Ukrainian organizations. Observed activity, TTPs, and IOCs shared in this new MSTIC blog. We'll update the blog as our investigation unfolds. https://t.co/wBB82gp6TX
In December the @Splunk Threat Research Team #STRT analyzed malware that utilized novel ways to load it self using dynwrapx.dll written in VBscript. We built 🛡️ 12 detections to find malware script loader behaviors and 📓3 playbooks to investigate them. https://t.co/z7BrYaoca8
Intezer researchers analyse SysJoker, a new multi-platform backdoor that targets Windows, Mac and Linux. SysJoker masquerades as a system update and generates its C2 by decoding a string retrieved from a text file hosted on Google Drive.
https://t.co/o603LzsvFP
1\ #MalwareAnalysis: Anti-Virtualisation Technique
Malware can look for the magic number 0x564D5868 - “VMXh” in ASCII to detect presence of VMWare usage.
Non-VMWare hosts will error when the malware reads from the I/O port "VX" - but VMWare will return the magic number back :)
My blog about malicious Office files and how to analyze them is out!
Learn the main differenced between the formats and which tools to use to analyze them
https://t.co/kx5u0WOaKo