Microsoft 365 Dev subscriptions free with Dev Essentials (also free)
๐ฃcryolithic
Iโm going to make so many word documents it will be like a 730 day trial
๐คJaimz22
Only 90 day trial
๐คxxbiohazrdxx
I saw they added what seems like a slew of additional freebies.
๐คnameandfaceless
๐@malwr
๐ฃcryolithic
Iโm going to make so many word documents it will be like a 730 day trial
๐คJaimz22
Only 90 day trial
๐คxxbiohazrdxx
I saw they added what seems like a slew of additional freebies.
๐คnameandfaceless
๐@malwr
ATT SMS record analysis
I've been asked to provide some analysis of SMS records which were subpoenaed from the carrier but am having a little trouble resolving a few things. There are several messages from a two digit phone number and several instances where two or three messages were sent by the phone at the exact same time (down to the second). It appears to me that the messages sent at the same time were likely long messages broken up into 2 or 3 messages due to character limits, but I can't really come up with anything that would allow a two digit phone number to deliver messages. Any help would be greatly appreciated.
๐ฃkstewart0x00
I often find that those records reflect carrier services, like paying a bill, checking data plan current usage, and messages regarding the account.
If you received this data in a subpoena return, there should be a document explaining these numbers. When in doubt, I usually call the division that supplied the records.
๐คchilledquesadilla
Could they be something that came from AT&T?
Is it from a service? or is it a conversation?
Here's someone asking AT&T the same question about messages on their bill. And AT&T providing stellar customer service, too.
https://forums.att.com/conversations/wireless-account/2-digit-phone-number/5defd200bad5f2f606f76a5c
๐คtechnologite
๐@malwr
I've been asked to provide some analysis of SMS records which were subpoenaed from the carrier but am having a little trouble resolving a few things. There are several messages from a two digit phone number and several instances where two or three messages were sent by the phone at the exact same time (down to the second). It appears to me that the messages sent at the same time were likely long messages broken up into 2 or 3 messages due to character limits, but I can't really come up with anything that would allow a two digit phone number to deliver messages. Any help would be greatly appreciated.
๐ฃkstewart0x00
I often find that those records reflect carrier services, like paying a bill, checking data plan current usage, and messages regarding the account.
If you received this data in a subpoena return, there should be a document explaining these numbers. When in doubt, I usually call the division that supplied the records.
๐คchilledquesadilla
Could they be something that came from AT&T?
Is it from a service? or is it a conversation?
Here's someone asking AT&T the same question about messages on their bill. And AT&T providing stellar customer service, too.
https://forums.att.com/conversations/wireless-account/2-digit-phone-number/5defd200bad5f2f606f76a5c
๐คtechnologite
๐@malwr
reddit
ATT SMS record analysis
I've been asked to provide some analysis of SMS records which were subpoenaed from the carrier but am having a little trouble resolving a few...
Reverse Engineering Challenge (HTB) Walkthrough incl binary patching with Ghidra + PwnTools
๐ฃ_CryptoCat23
๐@malwr
๐ฃ_CryptoCat23
๐@malwr
YouTube
Anti-Flag [easy]: HackTheBox Reversing Challenge (binary patching with ghidra + pwntools)
Video walkthrough for retired @HackTheBox (HTB) Reversing challenge "Anti-Flag" [easy]: "Flag? What's a flag?" - Includes binary patching with ghidra + pwntools! Hope you enjoy ๐
Sign up for HackTheBox: https://htb-signup.cryptocat.me
โขHackTheBoxโฃ
httpโฆ
Sign up for HackTheBox: https://htb-signup.cryptocat.me
โขHackTheBoxโฃ
httpโฆ
High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison for scheme that compromised tens of millions of debit and credit cards
๐ฃdigicat
๐@malwr
๐ฃdigicat
๐@malwr
Department of Justice
High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison for scheme that compromised tens of millionsโฆ
Seattle โ The first high-level manager of the notorious hacking group FIN7 was sentenced today in U.S. District Court in Seattle to ten years in prison, announced Acting U.S. Attorney Tessa A. Gorman.
How to monitor in real-time for SSH sessions
Blog post on how to monitor in real-time for SSH sessions: https://cryptsus.com/blog/ssh-security-siem-dashboard-kibana.html
๐ฃkrabelize
๐@malwr
Blog post on how to monitor in real-time for SSH sessions: https://cryptsus.com/blog/ssh-security-siem-dashboard-kibana.html
๐ฃkrabelize
๐@malwr
Endpoint Discovery - Navigating your way through unmanaged devices
๐ฃdigicat
This is pretty awesome.
๐คm0wax
๐@malwr
๐ฃdigicat
This is pretty awesome.
๐คm0wax
๐@malwr
TECHCOMMUNITY.MICROSOFT.COM
Endpoint Discovery - Navigating your way through unmanaged devices
Unmanaged endpoint discovery is a new feature that has been added to the Public Preview for Microsoft Defender for Endpoint. In this blog we describe its..
Disables the Windows Platform Binary Table (WPBT) in your firmware. This program use a non-permenant, non-destructive method to remove the table from system memory, so it should be executed every time the computer is rebooted before Windows bootloader starts. - sophisticated UEFI implant mitigation
๐ฃdigicat
This would be such a pain in the ass to deploy on one machine, let alone an entire enterprise
๐คedward_snowedin
>Because this feature provides the ability to persistently execute system software in the context of Windows, it becomes critical that WPBT-based solutions are as secure as possible and do not expose Windows users to exploitable conditions. In particular, WPBT solutions must not include malware (i.e., malicious software or unwanted software installed without adequate user consent).
Basically this is a catch-22 situation. This tablet could be used for legitimate purposes like loading antitheft software OR it could be used to load malware persistently
๐คCrowGrandFather
๐@malwr
๐ฃdigicat
This would be such a pain in the ass to deploy on one machine, let alone an entire enterprise
๐คedward_snowedin
>Because this feature provides the ability to persistently execute system software in the context of Windows, it becomes critical that WPBT-based solutions are as secure as possible and do not expose Windows users to exploitable conditions. In particular, WPBT solutions must not include malware (i.e., malicious software or unwanted software installed without adequate user consent).
Basically this is a catch-22 situation. This tablet could be used for legitimate purposes like loading antitheft software OR it could be used to load malware persistently
๐คCrowGrandFather
๐@malwr
GitHub
GitHub - Jamesits/dropWPBT: Disables the Windows Platform Binary Table (WPBT) in your UEFI firmware.
Disables the Windows Platform Binary Table (WPBT) in your UEFI firmware. - Jamesits/dropWPBT
Deep Analysis: New FormBook Variant Delivered in Phishing Campaign โ Part I | FortiGuard Labs
๐ฃmalware_bender
๐@malwr
๐ฃmalware_bender
๐@malwr
Fortinet Blog
Deep Analysis: New FormBook Variant Delivered in Phishing Campaign โ Part I
FortiGuard Labs captured a phishing campaign sending a PowerPoint document as an email attachment to spread a new variant of the FormBook malware. In part 1, learn more about how the malicious VBA โฆ
Compromised Linux VM for DF training?
Does anyone have a vmdk of a compromised Linux host (perhaps from a Honeypot?) they'd be willing to share? I'd like to have my blue team try their hand at manual forensics as a table-top / Forensics Capture-the-Flag exercise
Plans:
\- Have them import it into Virtualbox (they all use Ubuntu as their workstations)
\- Browse around the host and see what they can find manually first
\- Utilize something like Plaso / log2timeline and import it into a log tool like Splunk
๐ฃAbracaBOOYAH
Not exactly what you are looking for but I was just at a competition last week and it had some forensic CTFs. Found them here, might be what you are interested in.
๐คAppCompatCache-SI-TS
Just infect a Linux vm
๐คStofers
The Great Hal Pomeranz made a course, with resources from Ali Hadi/Champlain College, that might help you out:
https://archive.org/download/HalLinuxForensics
https://github.com/ashemery/LinuxForensics
๐คawk_warden
๐@malwr
Does anyone have a vmdk of a compromised Linux host (perhaps from a Honeypot?) they'd be willing to share? I'd like to have my blue team try their hand at manual forensics as a table-top / Forensics Capture-the-Flag exercise
Plans:
\- Have them import it into Virtualbox (they all use Ubuntu as their workstations)
\- Browse around the host and see what they can find manually first
\- Utilize something like Plaso / log2timeline and import it into a log tool like Splunk
๐ฃAbracaBOOYAH
Not exactly what you are looking for but I was just at a competition last week and it had some forensic CTFs. Found them here, might be what you are interested in.
๐คAppCompatCache-SI-TS
Just infect a Linux vm
๐คStofers
The Great Hal Pomeranz made a course, with resources from Ali Hadi/Champlain College, that might help you out:
https://archive.org/download/HalLinuxForensics
https://github.com/ashemery/LinuxForensics
๐คawk_warden
๐@malwr
reddit
Compromised Linux VM for DF training?
Does anyone have a vmdk of a compromised Linux host (perhaps from a Honeypot?) they'd be willing to share? I'd like to have my blue team try their...
Extracting VOIP Calls from network traffic - BruteShark (v1.2.1) is now capable of extracting Voip Calls among credentials, hashes, DNS, files and more. P.S: I would love for people to join the project!
๐ฃBruteShark
๐@malwr
๐ฃBruteShark
๐@malwr
GitHub
GitHub - odedshimon/BruteShark: Network Analysis Tool
Network Analysis Tool. Contribute to odedshimon/BruteShark development by creating an account on GitHub.
[Video Makop Ransomware - Decrypting the Encrypted Section](https://youtu.be/mlIRoGrxrmA)
๐ฃStruppigel
๐@malwr
๐ฃStruppigel
๐@malwr
YouTube
Makop Ransomware - Decrypting the Encrypted Section
SHA256: bc0ed3e73b8d1fdc839f2e8ed3578ca3221dba4eb984e581cb00dfb4cdfb7d49
pyMalleableC2: Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.
๐ฃbyt3bl33d3r
๐@malwr
๐ฃbyt3bl33d3r
๐@malwr
GitHub
GitHub - byt3bl33d3r/pyMalleableC2: Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build andโฆ
Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically. - byt3bl33d3r/pyMalleableC2
Getting Started Reverse Engineering Bare Metal Kernel Images - (Part 1/Setup) | This is a series, more will be released soon.
๐ฃragnarsecurity
Arent all kernels bare metal kernels? Iv not seen one that is specifically designed to run in a VM. I dont doubt that one may exist, but ive never seen one.
๐คAllenKll
Hey man, good write up :)
Can I ask what do you refer to as a "kernel"? In my experience, kernel is generally only used to refer to a component of an OS.
I'd generally describe a bare metal firmware as having no kernel. And the built application is just a binary, or a firmware image.
๐คPalantir555
๐@malwr
๐ฃragnarsecurity
Arent all kernels bare metal kernels? Iv not seen one that is specifically designed to run in a VM. I dont doubt that one may exist, but ive never seen one.
๐คAllenKll
Hey man, good write up :)
Can I ask what do you refer to as a "kernel"? In my experience, kernel is generally only used to refer to a component of an OS.
I'd generally describe a bare metal firmware as having no kernel. And the built application is just a binary, or a firmware image.
๐คPalantir555
๐@malwr
Medium
Reverse Engineering Bare Metal Kernel Images with QEMU- Part 1
This tutorial was designed as a setup tutorial for UMDCTF; however, it will be also be a part of a series for bare-metal embeddedโฆ