Using IoC unconventionally. Part 1. Threat hunting
Using IoC in a non-standard way. Part 1. Threat hunting 🧐 When we talk about indicators of compromise, we usually mean a reactive approach to defense: a securit…
Using IoC in a non-standard way. Part 1. Threat hunting 🧐 When we talk about indicators of compromise, we usually mean a reactive approach to defense: a securit…
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simples…
Continuing to reproduce the attack from the post above 🔼 3️⃣ Creating a public API Gateway trigger (screenshot 1) At the end, we need to expose the function to…
☁️ AWS backdoor as a service: persistence in the cloud via Lambda The cloud threat landscape is constantly evolving, and attackers are increasingly abusing legi…
Useful Friday post 🫥 During threat research, there is often an urgent need to examine a malicious file/URL/domain. In this post, we have gathered the tools we a…
Curing a problem 🔧 Recently, researchers from ARMO presented a paper and PoC for the Curing malware, which uses the io_uring interface to bypass monitoring of f…
Generating a COM vtable in IDA 🐍 While analyzing one of the Snake Keylogger variants, we needed to figure out which managed methods the native module calls thro…
Deep Dive into Imports: Continuing to Explore Static Resolution Techniques 🕵️♂️ Earlier we discussed how static import resolution can be implemented. However…
All Hackers Go To Cloud ☁️💻 During the investigation of an incident in a fully encrypted infrastructure, we identified an autonomous web server hosting the clie…
HTML attachments as a phishing tool 🤑 Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting wit…
IoCs-detox: protecting TI from false indicators ✋ Imagine this: your SOC team receives a fresh feed of compromise indicators. The list contains hundreds of new…
Trust but verify, or How to choose TI sources wisely 😏 In the life of the vast majority of SOC centers, there comes a time when you need to supplement your tool…