PCAP Analysis
Hi there.
I am just starting to learn about PCAP analysis/forensics. I am experienced in Windows OS forensics and never really worked with PCAPs before. What's some of the tools everyone uses besides Wireshark? I've been reading up on Zeek.
π£antmar9041
Look at BRIM (https://www.brimdata.io/)
But esential for pcap analysis is knowleadge about network, pacets etc.
π€sidi7
Network Miner is a good tool.
π€downtownatomizer
One thing I'd like to re-emphasize it that most tools do the same stuff with a few (mostly) minor differences. Ultimately, it's not the tool but how one uses it. There are a plethora of features in wireshark (or any one tool) and in my view, spending time to learn one or two but learning it to its fullest is the best way to excel.
Also, sorry, no one asked for me advice, I felt like mentioning so that if folks who are just getting into security read this, they shouldn't feel overwhelmed.
π€kaizen_kid
π@malwr
Hi there.
I am just starting to learn about PCAP analysis/forensics. I am experienced in Windows OS forensics and never really worked with PCAPs before. What's some of the tools everyone uses besides Wireshark? I've been reading up on Zeek.
π£antmar9041
Look at BRIM (https://www.brimdata.io/)
But esential for pcap analysis is knowleadge about network, pacets etc.
π€sidi7
Network Miner is a good tool.
π€downtownatomizer
One thing I'd like to re-emphasize it that most tools do the same stuff with a few (mostly) minor differences. Ultimately, it's not the tool but how one uses it. There are a plethora of features in wireshark (or any one tool) and in my view, spending time to learn one or two but learning it to its fullest is the best way to excel.
Also, sorry, no one asked for me advice, I felt like mentioning so that if folks who are just getting into security read this, they shouldn't feel overwhelmed.
π€kaizen_kid
π@malwr
reddit
PCAP Analysis
Hi there. I am just starting to learn about PCAP analysis/forensics. I am experienced in Windows OS forensics and never really worked with PCAPs...
π1
First Morello prototype architecture silicon (memory safety at a hardware level)
π£unaligned_access
π@malwr
π£unaligned_access
π@malwr
Time to chip in for #100DaysofYARA, this rule is a (fun) example that looks for a structure (#Regin VFS) instead of data.
Structures (often config) are useful to validate your understanding of malware functionality and for more resilient rules. But be careful with boundaries :)
π£Int2e_
π@malwr
Structures (often config) are useful to validate your understanding of malware functionality and for more resilient rules. But be careful with boundaries :)
π£Int2e_
π@malwr
Forwarded from CVE Notify
We do not possess any samples from Lockbit Ransomware group. A new sample from Lockbit has not appeared on @abuse_ch since December, 2021.
We asked Lockbit for a new sample - they have provided us with a sample directly from their panel.
Download here: https://samples.vx-underground.org/samples/Families/
π£vxunderground
π@malwr
We asked Lockbit for a new sample - they have provided us with a sample directly from their panel.
Download here: https://samples.vx-underground.org/samples/Families/
π£vxunderground
π@malwr
After the Pro version earlier this week, I just released a new version of MacroPack Community!
#infosec #MacroPack
https://github.com/sevagas/macro_pack
π£EmericNasi
π@malwr
#infosec #MacroPack
https://github.com/sevagas/macro_pack
π£EmericNasi
π@malwr
GitHub
GitHub - sevagas/macro_pack: macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documentsβ¦
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments...
π±1
About the WhisperGate, it's quite simple to setup the IDA Pro + Bochs to examine the MBR and I showed it step-by-step few slides in an introductory talk at HTIB Amsterdam 2019. Just it case you want to check slides:
https://exploitreversing.files.wordpress.com/2021/12/hitb_ams_2019-1.pdf
#malware #idapro
π£ale_sp_brazil
π@malwr
https://exploitreversing.files.wordpress.com/2021/12/hitb_ams_2019-1.pdf
#malware #idapro
π£ale_sp_brazil
π@malwr
Are you an admin with EXE blocked by #AppLocker? You can bypass the protection without any execution traces in the AppLocker Log! Load your DLL, steal the token from spooler and create the child process.
C source code and the compiled binary, as usual: https://github.com/gtworek/PSBits/tree/master/AppLockerBypass
π£0gtweet
π@malwr
C source code and the compiled binary, as usual: https://github.com/gtworek/PSBits/tree/master/AppLockerBypass
π£0gtweet
π@malwr
Best searchπengines for Pentesters and Security Professionals.
β google .com
β Shodan .io
β Censys .io
β Hunter .io
β redhuntlabs .com
β fullhunt .io
β onyphe .io
β fofa .so
β socradar .io
β synapsint .com
β binaryedge .io
β ivre .rocks
β crt .sh
β spyse .com
β vulners .com
β PublicWWW .com
β Pulsedive .com
β ZoomEye .org
β intelx .io
β WiGLE .net
β reposify .com
β viz. greynoise .io
π£NandanLohitaksh
π@malwr
β google .com
β Shodan .io
β Censys .io
β Hunter .io
β redhuntlabs .com
β fullhunt .io
β onyphe .io
β fofa .so
β socradar .io
β synapsint .com
β binaryedge .io
β ivre .rocks
β crt .sh
β spyse .com
β vulners .com
β PublicWWW .com
β Pulsedive .com
β ZoomEye .org
β intelx .io
β WiGLE .net
β reposify .com
β viz. greynoise .io
π£NandanLohitaksh
π@malwr
For those following the news, the WhisperGate campaign (as initially described by Microsoft) has been quite impactful. Today, my blog for corporate has gone live regarding this wiper campaign, with the analysis of all four stages. Additionally, I uploaded the binary of stage 4 to VirusTotal, MalShare, and MalwareBazaar, making it accessible for all. The links are given below.
Link: https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/return-of-pseudo-ransomware.html
βΉοΈ Sent from one of our members
π@malwr
Link: https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/return-of-pseudo-ransomware.html
βΉοΈ Sent from one of our members
π@malwr
Trellix
Return of Pseudo Ransomware
Insights into the recent ransomware campaign targeting Ukraine.
An old sample of the Lamberts (probably #WhiteLambert) appeared on VirusTotal.
This driver file intel440x.sys is also mentioned by name on the infamous drv_list.txt from The Shadow Brokers' leak. The logic itself is contained inside a compressed resource.
https://www.virustotal.com/gui/file/1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b
π£_CPResearch_
π@malwr
This driver file intel440x.sys is also mentioned by name on the infamous drv_list.txt from The Shadow Brokers' leak. The logic itself is contained inside a compressed resource.
https://www.virustotal.com/gui/file/1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b
π£_CPResearch_
π@malwr
[1/n] Today I'm sharing the details of a research done by vaber_b, legezo, Ilya Borisov and myself on a UEFI firmware implant found in the wild, dubbed #MoonBounce. We assess that this formerly unknown threat is the work of the infamous #APT41. A π§΅
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
π£_marklech_
π@malwr
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
π£_marklech_
π@malwr
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
https://github.com/infosecn1nja/Red-Teaming-Toolkit
π£Dinosn
π@malwr
https://github.com/infosecn1nja/Red-Teaming-Toolkit
π£Dinosn
π@malwr
GitHub
GitHub - infosecn1nja/Red-Teaming-Toolkit: This repository contains cutting-edge open-source security tools (OST) for a red teamerβ¦
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter. - infosecn1nja/Red-Teaming-Toolkit
My research work from last year summarized in the blog post: Evolved phishing: Device registration trick adds to phishersβ toolbox for victims without MFA
https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
π£Pawp81
π@malwr
https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
π£Pawp81
π@malwr
Microsoft Security Blog
Evolved phishing: Device registration trick adds to phishersβ toolbox for victims without MFA | Microsoft Security Blog
We uncovered a large-scale, multi-phase campaign that adds a novel technique to traditional phishing tactics by joining an attacker-operated device to an organizationβs network to further propagate the campaign.
3.0: The Next Chapter. Today, weβre proud to announce the release of Binary Ninja 3.0. More than 6 months in the making, Binary Ninja 3.0 represents a huge leap forward in analysis and usability. Pseudo C decompilation, stack view and an overhauled UI https://binary.ninja/2022/01/27/3.0-the-next-chapter.html
π£vector35
π@malwr
π£vector35
π@malwr