Have you heard about the public repository of Suricata rules Attack Detection?
Have you heard about the public repository of Suricata rules Attack Detection? Yes, that's meeee Within the large PT Expert Security Center team, there is a sep…
[ FEED // CHRONO // 267 ITEMS ]
Have you heard about the public repository of Suricata rules Attack Detection? Yes, that's meeee Within the large PT Expert Security Center team, there is a sep…
A word about the obfuscated batch file... We're publishing this post as a follow-up to the recent one about the EXE hidden under a hex dump in a Base64 request…
📫 X-Filtering of User Data In the process of analyzing email traffic, we periodically encounter the implementation of unusual malicious techniques. Today we wan…
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
Methods for Masking a Virtual Environment 😷 During malware analysis, you may encounter samples that will not function fully in a virtual environment. This is be…
How to get to the internet 🚶♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…
Everyone says: learn the basics! But how do you use them afterward? For example, like this 👇 1. Base64 — an encoding algorithm that can encode any data as a seq…
Gsocket: how to find one of the most popular tools 🙂 In the course of investigating numerous incidents involving the compromise of Linux nodes, we often discove…
TLS on the network: what to do 🤷♂️ You are a powerful network traffic analysis engine. You work for the benefit of the information security system, grinding th…
🛠 Reverse Engineering Delphi without IDR When you're actively involved in reverse engineering, sooner or later you encounter an executable file written in Delph…
🟥 ⚔️ 💿 Virtual Disk as the Start of an Attack In early September, experts from the TI cyberintelligence group of the PT ESC department discovered an interesting…
Colonels write first! (🔞) The collection of malicious mass mailings sent in the name of law enforcement agencies has a new addition. In September, several recip…