Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @tlp_red
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @tlp_red
-
Wait, what? They have so many actors in the network, they actually slow each other down. And this is the UN "well-structured infosec program"... I guess, I've being doing this infosec thing wrong all along.https://twitter.com/cnoanalysis/status/1222568498901073920 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
Ladies and gentlemen, I present you a working Remote Code Execution (RCE) exploit for the Remote Desktop Gateway (CVE-2020-0609 & CVE-2020-0610). Accidentally followed a few rabbit holes but got it to work! Time to write a blog post ;) Don't forget to patch!pic.twitter.com/FekupjS6qG
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
My simple script for erase opaque jumps from code. Based on miasm framework.https://github.com/immortalp0ny/miasm-opaquejmp …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Anniversary PHDays CFP is open https://cfp.phdays.com/ I'm organizing defense track, which will cover all things
#blueteam If you're doing#malware#DFIR#ThreatIntel come join us to kick some#APT ass and chew bubble gum, it's gonna be awesome.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
Scared by latest CVE-2020-0601 certificate spoofing vulnerability? We did a
#suricata detection rule for you. It covers all known exploitations of TLS certificates and executable signing. Find it here: https://github.com/ptresearch/AttackDetection/blob/master/CVE-2020-0601/cve-2020-0601.rules …#ChainOfFools#CurveBallHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
You already know .NET/MSIL imphashes f34d5f2d4577ed6d9ceec516c1f5a744 & dae02f32a21e03ce65412f6e56942daa are fairly useless for detection purposes, but did you know there's also a common imphash for Go/Golang PEs? f0070935b15a909b9dc00be7997e6112 cc:
@cyb3rops@virustotal#dfirHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Elmar Nabigaev proslijedio/la je Tweet
Release a few lines of Powershell to do some basic reverse TCP shell... and watch how the l33t APT hunters go crazy
IT’S REVERSE TCP... I half want to port it to C# for more hilarity
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
A few fresh and rebuilt
#ServHelper samples related to#TA505 group. The Vigenere encryption for strings remains the same.pic.twitter.com/S2nDqYYiA1
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
AV telemetry can be incredibly powerful and in the past has helped with investigations against sophisticated adversaries but when a vendor decides to sell that telemetry to advertisers you're committing a disservice to the rest of the industry. This is why you end up with GDPR.https://twitter.com/josephfcox/status/1204042451440295936 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
New
#mimikatz,#kekeo and so on... ready to be signed for the next year
Reminder: #codesigning is only about authenticity, authoring and to prevent alteration after signingpic.twitter.com/a8snw5V2tP
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
Native
#yara support for base64 - accounting for padding (3x) - from@wxs
[tagging several tool authors who have included this feature in scripts for defenders] https://twitter.com/wxs/status/1201704739077054465 …pic.twitter.com/uFzBY2sOoC
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
Problems with an office document? Nothing after opening? Seems that suspicious? Try to print out it! 27a10e250f846dbfca0f56b12913d60d
#InfoSec#Funpic.twitter.com/fc7e5b1Xed
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
Infrastructure overlaps between
#AVIVORE and#C0d0so (Codoso/APT19)#APT groups. Both groups are the same or some third actor shares hosts ... copaininfo[.]com gestione6781[.]com https://unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group/ …pic.twitter.com/MVkpF8OQuJ
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Disgusting to see,
@RobertMLee used this info to PR his firm. What a dick move. I'm on@cherepanov74 side. After that kind of thing, you wonder why everyone hesitates to share, even in "trusted" groups.https://twitter.com/osxreverser/status/1195750979876085766 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
A few more
#Nim downloaders from targeted attacks in#Pakistan: 46d2045598c6482ce7b58497018230a9 hxxp://185.207.204.210/providers/oracle 545ec86c5c70f63e1921c5e58c9b7050 hxxp://185.207.204.210/media/vlcaddons#APT#APT28#Sofacy#FancyBearpic.twitter.com/jU8HGXeDNo
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
It's up. TL:DR Extract some vmware tools commands from memory dumps such as commands run, files copied etc. Both Linux and Windows vmtools supported. Although, I didn't win, it was a really great learning experience.https://github.com/volatilityfoundation/community/blob/master/ElmarNabigaev/vmtools.py …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Did you know, you could extract credentials in plain-text from VMware Tools? Stay tuned for release! https://twitter.com/volatility/status/1195091536066670592 …pic.twitter.com/roB8JEki9H
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
A few signed and parameterized
#FlawedGrace backdoors with AES CBC encoded and LZNT1 compressed main module. Pay attention to a padding part: C&C address is at the end of the module and can be decoded improperly.#TA505#malware#backdoorpic.twitter.com/6Rjbnec0ho
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Elmar Nabigaev proslijedio/la je Tweet
Don't forget that if you host open source security software on
@github or hosting services located in US, you might be bound to US export restrictions. http://www.apache.org/licenses/exports/ … Having localised EU mirror of git repositories can be important for some of your users or contributors.pic.twitter.com/PIyCLS5tbe
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
Threat Intel
Threat Hunting
OSINT