Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @Jason_DFIR
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @Jason_DFIR
-
cog proslijedio/la je Tweet
Threat hunting is critical for proactively guarding against threats that evade traditional detection methods. Read this eBook to learn: - What defines threat hunting success - Common misconceptions/pitfalls - 6 key elements for effective threat huntinghttp://ow.ly/tW8I50ydwaY
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
Windows 10 UAC bypass for all executable files which are autoelevate true.https://github.com/sailay1996/UAC_Bypass_In_The_Wild …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
I found this article to be excellent. From building Windbg Tooling to working exploits. Its a dense and rich read. Really well done. I thought. Introduction to SpiderMonkey exploitation. https://doar-e.github.io/blog/2018/11/19/introduction-to-spidermonkey-exploitation/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
2020-01-29:


#TrickBot#Loader |#Signed
[FLORAL]#Sectigo Crypted Binary ->@realDonaldTrump#Impeachment Trial News
Generator

Why?
Crypters Devs Leverage Possible Whitelist Strings to Bypass Some AI/ML Engines
h/t @malwrhunterteam Bypass Eg -> https://skylightcyber.com/2019/07/18/cylance-i-kill-you/ …pic.twitter.com/GmESASoqui
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
Some study notes on LSASS hooking for harvesting interactive logon credentials. https://ired.team/offensive-security/credential-access-and-credential-dumping/intercepting-logon-credentials-by-hooking-msv1_0-spacceptcredentials … Thanks to
@_xpn_ for his inspiring posts about mimikatz.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
LogonTracer. Investigate malicious Windows logon by visualizing and analyzing Windows event log, by
@jpcert_enhttps://github.com/JPCERTCC/LogonTracer …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
#Emotet changed Webshells for S.A.P v.2.1. The same code logic is being pushed by the same upstream servers via POST queries. My script emotet_webshell_finder.py has been updated to also find those onespic.twitter.com/HkgDBTMHzb
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
cog proslijedio/la je Tweet
The claim in the FTI forensics report on Bezos’ iPhone that, “due to end-to-end encryption employed by WhatsApp, it is virtually impossible to decrypt the contents of the downloader [.enc file]...” bugged me so much that I coded up how to do it:https://github.com/ddz/whatsapp-media-decrypt …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
cog proslijedio/la je Tweet
Our global expansion continues: "Microsoft to launch new cloud datacenter region in Israel"https://news.microsoft.com/europe/features/microsoft-to-launch-new-cloud-datacenter-region-in-israel/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
Using Sysmon And ETW For So Much More
#infosec#blueteamhttps://www.binarydefense.com/using-sysmon-and-etw-for-so-much-more/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
technical
#DFIR article on how to discover new forensic evidence with "file structure analysis"https://www.hack42labs.com/blog/2020/01/14/discover-new-forensic-evidence-with-file-structure-analysis/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
Interesting Bookmarks:
#Emotet->#TrickBot->#Ryuk High-Value Target https://youtu.be/u1XvMcwdvgI?t=319 …
TrickBot Makes Headlines w/ MSP & LA Times
https://youtu.be/u1XvMcwdvgI?t=481 …
More Technical RE
https://youtu.be/u1XvMcwdvgI?t=812 …
Detections & Mitigations: Conclusion
https://www.youtube.com/watch?time_continue=1758&v=u1XvMcwdvgI&feature=emb_logo …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
2020-01-15:


#TrickBot#Loader#Signed Cert ->
[MONT-DMD d.o.o.] #Sectigo Same Crypter New
Added "foldhelper" Windows 10 UAC bypass by hijacking a special key in the Registry
Focuses More & More on Windows 10
MD5:18A19C324963BB69A492ACCF4E9A7600
h/t @malwrhunterteampic.twitter.com/fvwbNk4CUJ
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
One day – first place.
#Emotet. https://any.run/malware-trends/emotet …pic.twitter.com/QgIOuw1j4t
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
2020-01-10 - Let an
#IcedID infected host run long enough, and it'll also get a#Trickbot infection. Paste of the URLs for Trickbot EXEs: https://pastebin.com/MeLtiSp1 Pastebin raw: https://pastebin.com/raw/MeLtiSp1 pic.twitter.com/Hrl8MmoAkA
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
I had fun chatting with
@shanselman about Dapr on his show when he finally invited me back after 7 years of me askinghttps://hanselminutes.com/718/dapr-distributed-application-runtime-with-azure-cto-mark-russinovich …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
Responder 3.0.0.0 is out! Massive upgrade, support for both py3 and py2, many bug fix, enhancements and Q.A++ on all servers, poisoners and tools. Enjoy! ;)https://github.com/lgandx/Responder/releases/tag/v3.0.0.0 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
cog proslijedio/la je Tweet
Change.exe, Query.exe, and Reset.exe are basically the same tool, reading aliases from registry and launching other EXEs. Adding your own REG_MULTI_SZ to "query" could be an interesting way to fool
#DFIR forensicators for a moment.pic.twitter.com/6U7LlGHSL0
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.