Malware Analysis Series - Part 2, How to Isolate our Homelab with Network Segmentation https://blog.openthreatresearch.com/how_to_isolate_homelab
Open Threat Research Blog
Malware Analysis Series - Part 2, How to Isolate our Homelab with Network Segmentation
Introduction: In part one of this series, we established a solid foundation to begin our malware analysis journey. We successfully stood up two VMs; a Windows(FLARE) machine and a Linux(REMnux) machine. Put them on their own isolated virtual network without…
CVE-2021-33564 Argument Injection in Ruby Dragonfly https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
zxsecurity.co.nz
Ruby Dragonfly - ZX Security
Full spectrum IT security services
Nice analysis » What EDRs Hook on Microsoft Windows i.e. where the gaps exist in terms of telemetry / detection coverage https://www.reddit.com/r/blueteamsec/comments/n8fufb/what_edrs_hook_on_microsoft_windows_ie_where_the
reddit
What EDRs Hook on Microsoft Windows i.e. where the gaps exist in...
Posted in r/blueteamsec by u/digicat • 105 points and 7 comments
Know Your Enemy: Exploiting the Dell BIOS Driver Vulnerability to Defend Against It https://www.crowdstrike.com/blog/cve-2021-21551-learning-through-exploitation/
CrowdStrike.com
CVE-2021-21551: Learning Through Exploitation | CrowdStrike
Using CVE-2021-21551 as an example, learn how adversaries approach weaponizing vulnerabilities, and the technologies that work best to mitigate their tactics.
Advisory X41-2021-002: nginx DNS Resolver Off-by-One Heap Write Vulnerability https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
X41 D-Sec - Penetration Tests and Source Code Audits
nginx DNS Resolver Off-by-One Heap Write Vulnerability
An off-by-one error in ngx_resolver_copy() while processing DNS responses allows a network attacker to write a dot character (‘.’, 0x2E) out of bounds in a heap allocated buffer.
A PoC of Transacted Hollowoing, a PE injection technique (by @hasherezade) https://github.com/hasherezade/transacted_hollowing
GitHub
GitHub - hasherezade/transacted_hollowing: Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and…
Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging - hasherezade/transacted_hollowing
Forensic Analysis: jackcr difr challenge https://digitalitskills.com/forensic-analysis-jackcr-difr-challenge/
Guide to P-code Injection: Changing the intermediate representation of code on the fly in Ghidra https://swarm.ptsecurity.com/guide-to-p-code-injection/
32 bits, 32 gigs, 1 click... Exploitation of a JavaScriptCore WebAssembly Vulnerability https://blog.ret2.io/2021/06/02/pwn2own-2021-jsc-exploit/
RET2 Systems Blog
32 bits, 32 gigs, 1 click...
In this post we will examine a vulnerability in the WebAssembly subsystem of JavaScriptCore, the JavaScript engine used in WebKit and Apple Safari. The issue...
Threat Hunting: Log Monitoring Lab Setup with ELK https://www.hackingarticles.in/threat-hunting-log-monitoring-lab-setup-with-elk/
Hacking Articles
Threat Hunting: Log Monitoring Lab Setup with ELK
Learn Threat hunting with ELK log monitoring lab setup, configuration & analysis for security incident response & threat detection techniques
Revisiting the NSIS-based crypter https://blog.malwarebytes.com/threat-analysis/2021/05/revisiting-the-nsis-based-crypter/
ThreatDown by Malwarebytes
Revisiting the NSIS-based crypter - ThreatDown by Malwarebytes
This blog post was authored by hasherezade NSIS (Nullsoft Scriptable Install System) is a framework dedicated to creating software installers. It…
Malware Can Use This Trick to Bypass Ransomware Defense in Antivirus Solutions https://thehackernews.com/2021/06/malware-can-use-this-trick-to-bypass.html
The Hacker News
Malware Can Use This Trick to Bypass Ransomware Defense in Antivirus Solutions
Malware Can Use This New Trick to Bypass Ransomware Defense in Popular Antivirus Solutions
iOS Malicious Bit Hunter: malicious plug-in detection engine for iOS applications https://securityonline.info/ios-malicious-bit-hunter/
Cybersecurity News
iOS Malicious Bit Hunter: malicious plug-in detection engine for iOS applications
iOS Malicious Bit Hunter can analyze the head of the macho file of the injected dylib dynamic library based on runtime, and can perform behavior analysis
QT: heap overflow in TIFF processing https://bugs.chromium.org/p/project-zero/issues/detail?id=2165
The Nansh0u Campaign – Hackers Arsenal Grows Stronger https://www.guardicore.com/labs/the-nansh0u-campaign-hackers-arsenal-grows-stronger/
Guardicore
The Nansh0u Campaign – Hackers Arsenal Grows Stronger - Guardicore
During the past two months, the Guardicore Labs team has been closely following a China-based campaign which aimed to infect Windows MS-SQL and phpMyAdmin servers worldwide. We have taken a deep look into the inner workings of the campaign – the tools in…
SharpPanda: Chinese APT Group Targets Southeast Asian Government With Previously Unknown Backdoor https://research.checkpoint.com/2021/chinese-apt-group-targets-southeast-asian-government-with-previously-unknown-backdoor/
Check Point Research
SharpPanda: Chinese APT Group Targets Southeast Asian Government With Previously Unknown Backdoor - Check Point Research
Introduction Check Point Research identified an ongoing surveillance operation targeting a Southeast Asian government. The attackers use spear-phishing to gain initial access and leverage old Microsoft Office vulnerabilities together with the chain of in…