Binwalk
I've figured out how and when exactly to use Binwalk on files (JPG files for example, steganography).
But what is exactly Binwalk? How does it show me more files inside a file?
How does it work?
๐ฃblue8ird
It looks for file format signatures and for file headers/footers of different formats.
Btw a more common use case than steganography is extracting files from a firmware image.
๐คTompazi
๐@malwr
I've figured out how and when exactly to use Binwalk on files (JPG files for example, steganography).
But what is exactly Binwalk? How does it show me more files inside a file?
How does it work?
๐ฃblue8ird
It looks for file format signatures and for file headers/footers of different formats.
Btw a more common use case than steganography is extracting files from a firmware image.
๐คTompazi
๐@malwr
reddit
Binwalk
I've figured out how and when exactly to use Binwalk on files (JPG files for example, steganography). But what is exactly Binwalk? How does it...
Writing a #GHIDRA Loader: STM32 Edition
https://wrongbaud.github.io/writing-a-ghidra-loader/
๐@malwr
https://wrongbaud.github.io/writing-a-ghidra-loader/
๐@malwr
Announcing GA of O365 ATP Campaign Views and Compromised User Detection and Response
๐ฃTeamsMe
๐@malwr
๐ฃTeamsMe
๐@malwr
TECHCOMMUNITY.MICROSOFT.COM
Announcing GA of O365 ATP Campaign Views and Compromised User Detection and Response
Office 365 Advanced Threat Protection just got even better. Together, the two features we're announcing the GA of today: Campaign Views and Advanced..
I just open-sourced sweetie data, a repo of multiple honeypot logs.
๐ฃ0xsha
Nice thanks for sharing. I've shut down the majority of my honeypots and just use threat feeds and other intelligence streams.
๐คintoxicatednoob
๐@malwr
๐ฃ0xsha
Nice thanks for sharing. I've shut down the majority of my honeypots and just use threat feeds and other intelligence streams.
๐คintoxicatednoob
๐@malwr
GitHub
GitHub - 0xsha/sweetie-data: This repo contains logstash of various honeypots
This repo contains logstash of various honeypots. Contribute to 0xsha/sweetie-data development by creating an account on GitHub.
[PDF] OSS Supply Chain Security by the Linux Foundation
https://www.linuxfoundation.org/wp-content/uploads/2020/02/oss\_supply\_chain\_security.pdf
๐ฃdigicat
๐@malwr
https://www.linuxfoundation.org/wp-content/uploads/2020/02/oss\_supply\_chain\_security.pdf
๐ฃdigicat
๐@malwr
Workshop on Binary Analysis Research (BAR) 2020 at NDSS
๐ฃmttd
It would be nice to have the slides of the invited talks as well.
๐คXVilka
๐@malwr
๐ฃmttd
It would be nice to have the slides of the invited talks as well.
๐คXVilka
๐@malwr
ObliqueRAT, a new malware employed in attacks on government targets in Southeast Asia
๐ฃquellaman
๐@malwr
๐ฃquellaman
๐@malwr
Security Affairs
ObliqueRAT, a new malware employed in attacks on government targets
Cisco Talos researchers discovered a new malware, tracked as ObliqueRAT, that was employed targeted attacks against organizations in Southeast Asia.
Tutorial: Archive Azure AD logs to an Azure storage account
https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/quickstart-azure-monitor-route-logs-to-storage-account
๐ฃdigicat
๐@malwr
https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/quickstart-azure-monitor-route-logs-to-storage-account
๐ฃdigicat
๐@malwr
Docs
How to archive activity logs to a storage account - Microsoft Entra ID
Learn how to archive Microsoft Entra activity logs to a storage account through Diagnostic settings.
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations. (Note: it is designed to alert offense to defensive 'enquiries')
๐ฃdigicat
๐@malwr
๐ฃdigicat
๐@malwr
GitHub
GitHub - outflanknl/RedELK: Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as wellโฆ
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations. - outflanknl/RedELK
CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
๐ฃRedmondSecGnome
๐@malwr
๐ฃRedmondSecGnome
๐@malwr
Zero Day Initiative
Zero Day Initiative โ CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
This most recent Patch Tuesday, Microsoft released an Important-rated patch to address a remote code execution bug in Microsoft Exchange Server. This vulnerability was reported to us by an anonymous researcher and affects all supported versions of Microsoftโฆ