Have you heard about the public repository of Suricata rules Attack Detection?
Have you heard about the public repository of Suricata rules Attack Detection? Yes, that's meeee Within the large PT Expert Security Center team, there is a sep…
[ ARCHIVE ]
Have you heard about the public repository of Suricata rules Attack Detection? Yes, that's meeee Within the large PT Expert Security Center team, there is a sep…
A word about the obfuscated batch file... We're publishing this post as a follow-up to the recent one about the EXE hidden under a hex dump in a Base64 request…
📫 X-Filtering of User Data In the process of analyzing email traffic, we periodically encounter the implementation of unusual malicious techniques. Today we wan…
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
Methods for Masking a Virtual Environment 😷 During malware analysis, you may encounter samples that will not function fully in a virtual environment. This is be…
Everyone says: learn the basics! But how do you use them afterward? For example, like this 👇 1. Base64 — an encoding algorithm that can encode any data as a seq…
TLS on the network: what to do 🤷♂️ You are a powerful network traffic analysis engine. You work for the benefit of the information security system, grinding th…
How not to fight obfuscation 🫤 Automatic configuration extraction simplifies the identification of new C2s. We reverse a malware family, find the configuration…
🔎 Quick-and-dirty network research, or How to find a new, previously undiscovered activity of a known group in 15 minutes While analyzing external expertise on…
Hackers' Telegram Cart According to the latest trends (e.g., Lazy Koala), attackers are increasingly resorting to data exfiltration or C2 channels via the Teleg…
Missed the moment a phishing attachment was launched again? 📩 So what? The accountant is sure it was an "invoice" from a trusted bank. It's time to teach SIEM s…
💻 While investigating an incident, we discovered a useful artifact, smb_context C:\Windows\SysWOW64\smb_context.log — the SMB event log from a well-known antivi…