Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @dmargaritis
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @dmargaritis
-
Prikvačeni tweet
Before developing advanced detection techniques for powershell and lateral movement lets think if we can use the build-in free Windows firewall to prevent widely used techniques. Then we can detect unmanaged poweshell etchttps://medium.com/@dimitrismargaritis/prevent-legitimate-windows-executables-to-be-used-to-gain-initial-foothold-in-your-infrastructure-39771cd6ec90 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Top 5
@MITREattack Mitigations for Windows mapped to@NIST CSF https://bit.ly/2RU1UEM , in 2 words Cyber Hygienepic.twitter.com/q7clwxTCB8
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je Tweet
Red Teaming with Covenant and Donuthttps://blog.naijasecforce.com/red-teaming-with-covenant-and-donut/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je Tweet
Well, we have a Sigma rule from 2017 that would detect this "brand new" Trickbot campaign and I'll write one for the wreset.exe UAC bypass Rule https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_svchost.yml … https://twitter.com/ReaQta/status/1222548288731217921 …pic.twitter.com/ELcxrA0Sng
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je Tweet
1. Network segmentation 2. Host-based Firewalls 3. Windows Credential Guard/Exploit Guard 4. Applocker 5. Privilege Account Monitoring 6. EDR 7. Sandboxed Office365/Outlook 8. 2FA 9. AMSI 10. MSBuild/Powershell Monitoringhttps://twitter.com/jhencinski/status/1221819451617705984?s=20 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you have ATP enable the NO-DEFAULT protections: 1)block office apps from creating child process and inject code to other process2)Block JS &VBS from launching downloaded executable content 3)Block credential stealing from lsass.exe and much morehttps://bit.ly/2TVkTjl
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je Tweet
#BlueTeam command-line MSBuild.exe detection's got your#RedTeam down? How about MSBuild without MSBuild.exe? https://s5.gifyu.com/images/msbuild_api.gif …https://github.com/rvrsh3ll/MSBuildAPICaller …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je Tweet
The bad news is that even if you’ve patched your systems Monday morning, strictly speaking, you can’t trust them anymore
Attackers had 55 (+ x) hours to exploit that 0day & drop a webshell or reverse shell
Please don’t shoot the messenger 
https://twitter.com/bad_packets/status/1216635462011351040 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Use AccessEnum.exe from Sysinternals to find globally writable folders in c:\windows and do something for it... Think twice for this if you have default AppLocker implementation without rules for these folders
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
There many subfolders in c:\windows where normal user has write access. Find them and remove write access https://twitter.com/subTee/status/1216465628946563073 …
Tweet je nedostupan.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Dimitrios Margaritis proslijedio/la je Tweet
#OilRig targets LANDesk Agent users via PowDesk - New PowerShell-based malware resembles QUADAGENT. PowDesk checks for the presence of LANDesk Agent folder and service before C&C beacon. Full analysis coming soon. https://www.virustotal.com/gui/file/8406ca490c60ec41569b35f31f1860ff4663bba44d1daac64760ecdfe694203d/detection … lcepos[.]com/php/reclaimlandesk[.]phppic.twitter.com/Fqw0RoWU56
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
"Offsec wrote defensive rules" this is something that we are missing in many caseshttps://twitter.com/cyb3rops/status/1208285311027077120 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je Tweet
Interesting project to check for security issues in terraform files (has checks for AWS, Azure, and GCP). Similar to Hashicorp Sentinel.https://github.com/bridgecrewio/checkov …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Strange feelings when I saw this picture for my country...
@Pierrakakis I hope understands the importance of cybersecurity and soon Greece will have better position amongst EU countries. There are many Greeks in cybersecurity,unfortunately outside the country, that can helppic.twitter.com/DJvKLdoyoy
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Dimitrios Margaritis proslijedio/la je Tweet
Important update for Sigma rule that detects suspicious PowerShell encoded commands to cover the latest
#Emotet campaigns https://github.com/Neo23x0/sigma/blob/master/rules/windows/process_creation/win_susp_powershell_enc_cmd.yml …pic.twitter.com/4pWicyQ3iH
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dimitrios Margaritis proslijedio/la je Tweet
Crime vs. APT (from a slide deck that I am currently preparing)pic.twitter.com/2iX7wGPmiO
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Why @WindowsATP doesn't log the real remote IP and DNS name in the network connection and logs the name and the IP of the proxy? Don't tell me use Sysmon EID 22 if you want such info :-)
@JohnLaTwCpic.twitter.com/OtcJ5dQxK3
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Cool tools from fireeye in githubhttps://twitter.com/FireEye/status/1205181723341991937 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
United States: 9,880
Germany: 2,510
United Kingdom: 2,028
Switzerland: 1,094
Australia: 1,076
Netherlands: 713
Canada: 682
France: 591
Italy: 568
Norway: 446
All others: 5,533