Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Malware News pinned «Guys with premium telegram account, boost please: https://t.me/malwr?boost»
What is the term used to describe the process of reverse-engineering malware to understand its inner workings?
Final Results
27%
Sandboxing
59%
Decompilation
11%
Obfuscation
3%
Code Injection
👍3
NetworkMiner 2.8.1 Released

I am happy to announce the release of NetworkMiner 2.8.1 today! This new release brings a VNC parser to NetworkMiner, so that screenshots, keystrokes and clipboard data can be extracted from unencrypted VNC traffic. NetworkMiner 2.8.1 additionally includes parsers for command-and-control (C2) protoc...

https://www.netresec.com/?page=Blog&month=2023-10&post=NetworkMiner-2-8-1-Released


🎖@malwr
👍1
This media is not supported in your browser
VIEW IN TELEGRAM
Long hand crime kit used for car keyfob signal amplification.


🎖@malwr
👍1
Free SIEM to augment existing SIEM.
Currently we have SIEM (SAAS Solution) that covers all of our servers, switches, routers firewalls.

We do not collect logs for any of our workstations (3000 workstations) and I would like to have something but we do not have any budget to increase our existing SIEM capacity. I just want to have something incase I need to review logs on a workstations.

I was looking at Wazuh but it does not look like it will scale well with that many workstations.

Any recommendations?
🗣Critical_Egg_913

I'm going to be different and say, you don't need a siem to handle workstations. Get alerts out of your EDR and then use Velociraptor to query for logs and other events on workstations.
👤mustacheride3

I just ran across gravwell.io I'm currently testing it out in a lab but it looks promising. It is free up to 14gb/day
👤semipvt

Graylog. Open Source Splunk.
👤SLC_CA


🎖@malwr