Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @TekDefense
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @TekDefense
-
1aN0rmus proslijedio/la je Tweet
1\ I've written a little compiler to ship ML models as standalone Yara rules, and done proof of concept detectors for Macho-O, RTF files, and powershell scripts. So far I have decision trees, random forests, and logistic regression (LR) working. https://github.com/inv-ds-research/yaraml_rules …pic.twitter.com/sfuXEkHeNO
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
that would make you pause a minuet.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stumbled across "ENTER-BSOD" while reviewing some powershell hitting pastebin hits. Far superior to the old screenshot the desktop and hide all the icons stuff we used to do!pic.twitter.com/N1MejTuSAA
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
Learn more about the tool we worked on with
@citrix to help orgs identify compromised systems associated with the CVE-2019-19781 vulnerability: https://feye.io/2NNzv0q pic.twitter.com/yEInzSl98i
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
Great work by
@williballenthin@cglyer and many others to get this out quickly!https://twitter.com/citrix/status/1219984375720431616 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
Lots of late nights and work on the weekend/holiday to get this out. Many thanks to
@williballenthin@MadeleyJosh@_bromiley@jkoppen1@ItsReallyNick for help making it happen.Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
1aN0rmus proslijedio/la je Tweet
We are committed to the security of our products & we are making every effort to ensure all customers are supported in response to
#CVE201919781. To that end, we have teamed up with@FireEye on a scanner that aids customers in the detection of compromise.https://www.citrix.com/blogs/2020/01/22/citrix-and-fireeye-mandiant-share-forensic-tool-for-cve-2019-19781/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#DFIR new tool released to help with CVE-2019-19781 identification https://github.com/fireeye/ioc-scanner-CVE-2019-19781/ …https://twitter.com/cglyer/status/1219984237878763521 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
PATCH PATCH PATCH, GO GO GO !https://twitter.com/citrix/status/1219003086133395460 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
“FireEye believes that actors deploy
#NOTROBIN to block exploitation of the CVE-2019-19781 vulnerability while maintaining backdoor access to compromised NetScaler devices.” https://www.fireeye.com/blog/threat-research/2020/01/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html …pic.twitter.com/bIUlLRE0YNHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
Dashboard view of recent RDP
#Honeypot activity. Looking to add these screenshots to the daily summaries soon™#DFIR#InfoSec#ThreatHuntingpic.twitter.com/ahRnIW5JSc
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
We found an unexpected development with the Citrix Netscaler vulnerability. A seemingly “white knight” who left a backdoor to deploy additional malware while keeping out other criminals.https://www.fireeye.com/blog/threat-research/2020/01/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
In which we discuss an actor deploying a mitigation for the Citrix vuln, but also appearing to have a backdoor.https://www.fireeye.com/blog/threat-research/2020/01/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
ROFL at the internet white knight that's dropping payloads to inoculate Netscaler devices.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
New blog with @_bromiley on CVE-2019-19781 - "I Promise It'll Be 200 OK", covering: • ASCII encoding trick evading most (all?) public rules /.%2e/%76pns/
• @Snort
#detection tricks (negative distance, exploitation flowbits)
https://www.fireeye.com/blog/products-and-services/2020/01/rough-patch-promise-it-will-be-200-ok.html …
• #DFIR tips
pic.twitter.com/LbiPHq6KFv
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
NEW: Google to phase out user-agent strings in Chrome * UA strings to be replaced with Client Hints * Move is part of the larger Privacy Sandbox project * UA string freezing and deprecation to take place between Chrome 81 and 85 https://www.zdnet.com/article/google-to-phase-out-user-agent-strings-in-chrome/ …pic.twitter.com/tI3goGmRRO
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
PDBlaster: a tool for "scalable PDB extraction and analysis" - this is cool because as
@kcin418 points out in the blog, PDB paths may only be present in ~5% of malware, so collection, parsing, pivoting in BULK is key to squeezing meaningful juice out of the artifact.#PDBlaster https://twitter.com/kcin418/status/1216769454811557889 …pic.twitter.com/UkxY6yXEFl
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
1. Never stop learning. 2. See failure as a beginning. 3. Teach others what you know. 4. Assume nothing, question everything. 5. Analyze objectively. 6. Practice humility. 7. Respect constructive criticism. 8. Love what you do. 9. Give credit where it's due. 10. Take initiative.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
1aN0rmus proslijedio/la je Tweet
BREAKING: I have decided to follow
@James_Holzhauer on Twitter, since he’s been following me on Jeopardy all week.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.