I am independent, you want the truth?
Laying off workers to run Super Bowl ads should not be a growth driver. @CrowdStrike
Laying off workers to buy into ChatGPT should not be a growth driver. @Microsoft
Laying off workers should never be a growth driver. @Google
4
8
28
2,911
Johnny 3.14159265358979323846264338327950288419... retweeted
We just published a report on EVERYTHING that @HuntressLabs SOC is seeing for post-exploitation from #ScreenConnect CVE-2024-1708/CVE-2024-1709.
huntress.com/blog/slashandgr…
There's A LOT of it. We're talking:
- Adversaries Deploying Ransomware (LockBit and others)
- Classic LOLbin enumeration and reconnaissance
- Dropping cryptocurrency miners (masquerading as SentinelOne)
- Installing other persistence and backdoors (SimpleHelp C2, SSH, Remote Desktop, new users, reverse shells)
This includes all the technical details and tradecraft for each variety of these attacks. Please go look through this.
If I may be so bold, I think this is seriously the biggest and most-comprehensive release of the active threat intel that we've seen shared publicly so far.
6
133
511
123,236
Johnny 3.14159265358979323846264338327950288419... retweeted
Wenn Du die wichtigsten Unternehmen Europas schützen möchtest, dann komm in unser SOC Team. Wir setzen auf die besten Security Experten der Branche. Schreib mir gerne eine DM.
I'm planning to integrate additional sources into my #Sentinel#AnalyticsRule search engine.
You write and publish ANR?
You want those included?
Then please answer with the link to your repository.
analyticsrules.exchange/
We have restored our papers on oligomorphic, polymorphic, and metaphoric viruses.
Path: /papers/Other/Code Mutation
Have a nice day (or evening). We will see all of you tomorrow. Cheers,
vx-underground.org
4
21
158
25,272
Johnny 3.14159265358979323846264338327950288419... retweeted
Lots of people are new to M365/Microsoft Entra ID forensics, so I thought I would put together a completely free & open-source forensics 'kit' to learn. First, somewhere to store your data, Kusto Free tier is perfect, zero cost and no card required - aka.ms/kustofree
You cannot thank these guys enough putting so much effort and time in enabling all of us newbies.
So let's start with @reprise_99: Thanks so much!
#infosec#forensics#threatintel
👇👇👇
Lots of people are new to M365/Microsoft Entra ID forensics, so I thought I would put together a completely free & open-source forensics 'kit' to learn. First, somewhere to store your data, Kusto Free tier is perfect, zero cost and no card required - aka.ms/kustofree
1
101
Johnny 3.14159265358979323846264338327950288419... retweeted
Microsoft has observed a new version of the BlackCat ransomware being used in recent campaigns. This version includes the open-source communication framework tool Impacket, which threat actors use to facilitate lateral movement in target environments.
4
205
508
189,480
Johnny 3.14159265358979323846264338327950288419... retweeted
Microsoft has been published a #TokenTheft playbook which includes investigation checklist, hunting queries, response/recovery task list but also accompanying decision tree. A must read for every #AzureAD, #Entra, #SecOps admin and architect.
learn.microsoft.com/en-us/se…
Duetsche Bank and ING Bank have both had customer data stolen by Clop Ransomware via a third party vendor.
Neither has been posted yet.
@DeutscheBank@ING_news
33
Johnny 3.14159265358979323846264338327950288419... retweeted
The Microsoft Defender Threat Intelligence team just launched their official GitHub Community. Technical solutions for common incident response and threat hunting scenarios to help the SOC maximize Microsoft Threat Intelligence in Defender TI. github.com/Azure/MDTI-Soluti…
ALT Github Cat GIF
1
107
Johnny 3.14159265358979323846264338327950288419... retweeted