Understanding "Solorigate"'s Identity IOCs
π£Wireless_Life
The Solarwinds attack is an ongoing investigation, and teams at Microsoft continue to act as first responders to these attacks. The following post shares how they leverage threat intelligence and monitor for new indicators that could signal attacker activity.
π€Wireless_Life
π@malwr
π£Wireless_Life
The Solarwinds attack is an ongoing investigation, and teams at Microsoft continue to act as first responders to these attacks. The following post shares how they leverage threat intelligence and monitor for new indicators that could signal attacker activity.
π€Wireless_Life
π@malwr
TECHCOMMUNITY.MICROSOFT.COM
Solorigate AzureAd IOCs
Solarwinds solorigate IOCS Identity
Forwarded from CVE Notify
π¨ CVE-2020-28641
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
π@cveNotify
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
π@cveNotify
Malwarebytes Support
Arbitrary file deletion vulnerability fixed in Malwarebytes Endpoint Protection
In October 2020, Fortinet's FortiGuard Labs reported an arbitrary file deletion vulnerability in our product Malwarebytes Endpoint Protection. The product was mistakenly deleting good files that we...
DirectX creator Eric Engstrom dies aged 55, leaving behind a game-changing legacy
π£instilledbee
According to wikipedia, he died from complications from dropping a monitor on his foot. Talk about unlucky. Damn.
π€turniphat
π@malwr
π£instilledbee
According to wikipedia, he died from complications from dropping a monitor on his foot. Talk about unlucky. Damn.
π€turniphat
π@malwr
Developer Tech News
DirectX creator dies aged 55, leaving behind a game-changing legacy
DirectX creator Eric Engstrom has sadly passed away at the age of 55, following a career which helped to shape the gaming industry as we know it.
BlueTeam Online Training
Iβm looking to have continuous training for a blue team and Iβm curious as to what the group would recommend. Outside of Cybrary and SANS what do you recommend?
Iβm personally interested in core disciplines and not aimed towards a certification. Also, being continuous is also helpful.
π£nullsku
https://wildwesthackinfest.com/training-schedule/
π€Sho_nuff_
I havenβt used it but ISACAβs training looks solid. Was gonna try it before training budget was cut.
Maybe you can do a trial to see if you like it.
https://www.isaca.org/training-and-events/cybersecurity
π€Just_saying_brah
π@malwr
Iβm looking to have continuous training for a blue team and Iβm curious as to what the group would recommend. Outside of Cybrary and SANS what do you recommend?
Iβm personally interested in core disciplines and not aimed towards a certification. Also, being continuous is also helpful.
π£nullsku
https://wildwesthackinfest.com/training-schedule/
π€Sho_nuff_
I havenβt used it but ISACAβs training looks solid. Was gonna try it before training budget was cut.
Maybe you can do a trial to see if you like it.
https://www.isaca.org/training-and-events/cybersecurity
π€Just_saying_brah
π@malwr
Reddit
From the blueteamsec community on Reddit
Explore this post and more from the blueteamsec community
Reversing APT-28 64-bit Keylogger [Zebrocy Nim TLP: White ](https://0xthreatintel.medium.com/reversing-apt-28-64-bit-keylogger-zebrocy-nim-tlp-white-a77033f5c36b)
π£digicat
π@malwr
π£digicat
π@malwr
Zelda Hit Detection - Behind the Code [YouTube](https://www.youtube.com/watch?v=FBk-QkzMeIk)
π£rolfr
π@malwr
π£rolfr
π@malwr
YouTube
Zelda Hit Detection - Behind the Code
Code walk through sword collision detection, sword/wand states, and the wand collision bug.
If you would like to support this channel, here is a link to the Displaced Gamers Patreon page - https://www.patreon.com/displacedgamers
Twitter: https://twitβ¦
If you would like to support this channel, here is a link to the Displaced Gamers Patreon page - https://www.patreon.com/displacedgamers
Twitter: https://twitβ¦
Attacking Active Directory | Capturing Hashes via File Shares & .LNK Files
π£infinitelogins
π@malwr
π£infinitelogins
π@malwr
YouTube
Attacking Active Directory | Capturing Hashes via File Shares & .LNK Files
This one was a ton of fun because it shows the importance of following the principal of least privilege when it comes to setting permissions on public file shares. In this demonstration, we're able to craft a .lnk file that forces clients to send their NTLMv2β¦
Tutorial video explaining Paging in x86_64 systems and how to add it to your C++ OS
π£AbsurdPoncho
π@malwr
π£AbsurdPoncho
π@malwr
YouTube
Page Table Manager | How to Make an OS: 8
In this video we make a Page Table Manager so that we can map any virtual address to any physical address when we need to.
β€Discord:
https://discordapp.com/invite/p2JYhr9
β€Github:
https://github.com/Absurdponcho/PonchoOS/tree/Episode-8-Page-Table-Managerβ¦
β€Discord:
https://discordapp.com/invite/p2JYhr9
β€Github:
https://github.com/Absurdponcho/PonchoOS/tree/Episode-8-Page-Table-Managerβ¦
SOLARWINDS BACKDOOR (SUNBURST) INCIDENT RESPONSE PLAYBOOK
π£digicat
Looks like some good steps and would be a good starting point for many looking to have a checklist of items if their security IRP is not well flushed out.
π€hackfacts
π@malwr
π£digicat
Looks like some good steps and would be a good starting point for many looking to have a checklist of items if their security IRP is not well flushed out.
π€hackfacts
π@malwr
TrustedSec
SolarWinds Backdoor (Sunburst) Incident Response Playbook
SolarWinds Orion servers should be forensically preserved, if possible, to allow forensic examination. User Activity The accounts mentioned below includeβ¦
CVE-2020-8554 is a vulnerability that particularly affects multi-tenant Kubernetes clusters. If a potential attacker can create or edit services and pods, then they may be able to intercept traffic. Learn how to detect CVE-2020-8554 using open source Falco
π£RoutineConversation4
π@malwr
π£RoutineConversation4
π@malwr
Sysdig
Detect CVE-2020-8554 using Falco β Sysdig
How to detect the CVE-2020-8554 vulnerability that allows users to intercept traffic from other pods or nodes in a Kubernetes cluster.
Malware wrapped in Cyberpunk 2077
π£f474m0r64n4
And this is why that walled garden works!
Edit: and this is why we iOS users donβt need third party stores or the ability to side load just by clicking a link
π€AndreiD2017
π@malwr
π£f474m0r64n4
And this is why that walled garden works!
Edit: and this is why we iOS users donβt need third party stores or the ability to side load just by clicking a link
π€AndreiD2017
π@malwr
Kaspersky
Ransomware disguised as a mobile version of Cyberpunk 2077
Cybercriminals spread mobile ransomware under the guise of a beta version of Cyberpunk 2077 for Android.
Cloud-native security operations with Azure Sentinel. A new βMicrosoft Learnβ training module, finally replacing the βNinjaβ training.
π£munrobotic
π@malwr
π£munrobotic
π@malwr
Docs
Cloud-native security operations with Microsoft Sentinel - Training
This learning path describes basic architecture, core capabilities, and primary use cases of its products. You'll also learn about differences and Get familiar with Microsoft Sentinel, a cloud-native, security information and event management (SIEM) service.
Emotet Returns to Hit 100K Mailboxes Per Day
π£DrinkMoreCodeMore
How wholesome, dropping Christmas presents!
π€PM_CUTE_PUSSY
π@malwr
π£DrinkMoreCodeMore
How wholesome, dropping Christmas presents!
π€PM_CUTE_PUSSY
π@malwr
Threat Post
Emotet Returns to Hit 100K Mailboxes Per Day
Just in time for the Christmas holiday, Emotet is sending the gift of Trickbot.
HalMakeBeep - Reversing A Tiny Built-In Windows Kernel Module [Journey from Kernel32 to HAL](http://www.debasish.in/2014/02/reversing-tiny-built-in-windows-kernel.html)
π£doctorstyles
π@malwr
π£doctorstyles
π@malwr
www.debasish.in
Reversing A Tiny Built-In Windows Kernel Module [Journey from Kernel32 to HAL]
Debasish Mandal's Personal Blog about Information Security Research,Exploit Development,Vulnerability Research,Python and some random ideas!