Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @malwaresoup
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @malwaresoup
-
Pretty interesting campaign we've been following. It's stated there, but despite the use of the packer/loader seen in MINEDOOR (packer used by
#Get2), we're tracking this activity as separate from TA505 - TTPs are quite different from what we've seen from that grouphttps://twitter.com/a_tweeter_user/status/1225062617632428033 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
2020-01-31:[INTEL]

Please remember: #TA505 is not necessarily#EvilCorp (linked to#Dridex operation).
While there might be some distribution member overlap, these groups are not the same and cannot be equated.
I'm not sure why TA505 is being again AKA'ed as EvilCorp here.https://twitter.com/MsftSecIntel/status/1222995250911703041 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
#TA555 back again. Stage 1 still GET to 7 character png, followed by 9 character png -> poshAdvisorHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Two very different takes on the snow this morning...pic.twitter.com/tZvQWLkw6N
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Pretty shameful stuff right herehttps://twitter.com/NBCPolitics/status/1067961626635223040 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
One way to deal with imposter syndrome is to engage with your peers and put your ideas out there. You'll probably find out that those ideas aren't as crazy as you think. :)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
LMK if you would like to hunt for bad guys on a massive and ever changing network. Work for a company that encourages and values innovation. Be part of a global team that is focused on detecting / responding to threats of all types. https://jobs.gecareers.com/ShowJob/Id/62063/Staff-Incident-Responder/ …
#DFIR#ThreatHuntingHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
New
@ESET research: Analysis of the#Turla Outlook Backdoor. It is fully controlled by PDF attachments sent by emails. It was allegedly used against the German Foreign Office last year. Blogpost: https://www.welivesecurity.com/2018/08/22/turla-unique-outlook-backdoor/ … Full WP: https://www.welivesecurity.com/wp-content/uploads/2018/08/Eset-Turla-Outlook-Backdoor.pdf …pic.twitter.com/arZyIHdUD9
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
"Normal" or "expected" behavior does not always look normal at first glance. Just spent 2 days investigating traffic I was convinced was malicious only to discover some fun quirks in the way WPAD works.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
More
#infosecjobs on my team @ large growing FinTech in NoVA. Unfortunately not remote need to be willing to be based in McLean or Richmond. Internal InfoSec consultant w/2-5yrs in risk management and AppSec. Will consider even if you were more tech side than security side. DMHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
TLDR:
#CVE-2017-11882 exploits work using either 0x00430C12 or 0x00630C12 as the target memory address bc input is converted to uppercase before the buffer overflow occurs. 63 = 'c' and 43 = 'C'. Neat signature evasion trick.#TrickBot#maldoc#RTF https://malwaresoup.com/tricky-cve-2017-11882-trick-used-to-deliver-trickbot/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet

Just 1 more month to submit your talk at BSides DC cc @bsidesdc! https://cfptime.org/311/#cfp#infosec#bsidesdcHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
Red team: “we can’t tell you how we did that” “...then what good are you?” We can wrap up
#blueteamsummit right now, that’s the takeaway for the week.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
Automatically Stealing Password Hashes with Microsoft Outlook and OLE. Put the case that rather than a remote image file, it's an OLE document that is loaded from a remote SMB server... cc:
@MalwareMustDie and@binitamshah https://insights.sei.cmu.edu/cert/2018/04/automatically-stealing-password-hashes-with-microsoft-outlook-and-ole.html …pic.twitter.com/CcNNoCnkBH
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
Powershell Download Cradles: an overview about
#detection executing#PowerShell code typically at the end of a maldoc or exploit. "A download cradle is a single line command for download and code execution". Via@mgreen27 cc:@binitamshah https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html …pic.twitter.com/Xw5lhhrnY9
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
New blogpost announcing the release of Endgame Red Team Automation (RTA), which is an open source toolkit to enable organizations to test their defenses against a range of tactics within MITRE’S ATT&CK matrix:https://www.endgame.com/blog/technical-blog/introducing-endgame-red-team-automation …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
If it’s not a hypothesis led proactive investigation it doesn’t fit. Also it has to go beyond your current automation footprint, so by default if a tool is doing it it’s not threat hunting. But an analyst could use any tool to go on a hunt if it helps test the hypothesis
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
Here’s a question for you... If you could step away from your job for three months, and with that time your goal was to use your tech skills to help improve as many people lives as possible...what would you do?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Andy Moore proslijedio/la je Tweet
Blue Team Summit speakers
@malwaresoup &@kathayra of@CapitalOne will explain how pack hunting can demonstrate the value of integrating a well-defined hunt program into an organization's detection strategy | April 23-24 | Louisville, KY | Agenda: http://www.sans.org/u/AgS pic.twitter.com/YTAIoH2g2e
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Excited to be speaking along side
@kathayra at#SANSBlueTeamSummit (April 23-24 | Louisville, KY). We'll be talking about threat hunting as a team and some of our lessons learned from implementing a hunt program in a large organization. http://www.sans.org/u/Aei pic.twitter.com/5xxPTHr0LJ
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.