ISC Stormcast For Friday, March 18th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleCall for some logs and/or packets for requests to...
Over the last few daysseveral of my honeypots have reported the following request from an IP address in Germany."> GET //a2billing/customer/templates/default/header.tpl HTTP/1.0q=0.3Connection: TE,...
View ArticleISC Stormcast For Monday, March 21st 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleWhy Users Fall For Ransomware, (Mon, Mar 21st)
We got the following message from our reader Steven: ">Yesterday I received an email regarding STEVEN, Notice to Appear in Court on March 28"> the folder and scanned the .doc.js file with Avast,...
View ArticleApple Updates Everything (Again), (Mon, Mar 21st)
As part of todays product announcements, Apple released new operating systems across its different products. In addition to new features, these updates do address a number of security issues as well....
View ArticleISC Stormcast For Tuesday, March 22nd 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleIP Addresses Triage, (Mon, Mar 21st)
Last week, I was in Germany to attend the TROOPERS security conference and I had the opportunity to follow Chris Truncers talk about passive intelligence gathering. Passive intelligence is a must-do...
View ArticleISC Stormcast For Wednesday, March 23rd 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleAbusing Oracles, (Wed, Mar 23rd)
No, no this has nothing to do with Oracle Corporation! This diary is about abusing encryption and decryption Oracles. First a bit of a background story. Most of the days I do web and mobile application...
View ArticleGetting Ready for Badlock, (Wed, Mar 23rd)
It got a catchy name, it got a logo... so it must be serious. Or at least that is what is implied with the Badlock vulnerabilitythat was pre-announced this week. At this point, there is only a vague...
View ArticleISC Stormcast For Wednesday, March 23rd 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleThe importance of ongoing dialog, (Thu, Mar 24th)
Introduction I recently transitioned into a new role at Palo Alto Networks Unit 42. Since then, Ive published a couple of blog posts describing recent developments in ongoing campaigns [1, 2]. Those...
View ArticleISC Stormcast For Friday, March 25th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC Stormcast For Sunday, March 27th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleImproving Bash Forensics Capabilities, (Mon, Mar 28th)
Bash is the default user shell in most Linux distributions. In case of incidents affecting a UNIX server, they are chances that a Bash shell will be involved. Bash keeps"> $ history | tail -5 1993...
View ArticleISC Stormcast For Tuesday, March 29th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleVBE: Encoded VBS Script, (Tue, Mar 29th)
A file with with extension .vbe is an encoded Visual Basic Script file. I" /> You can find my YARA rule here. Didier Stevens SANS ISC Handler Microsoft MVP Consumer Security blog.DidierStevens.com...
View ArticleSOC Resources for System Management, (Wed, Mar 30th)
I have recently started looking at the MITRE 10 strategies for a SOC (hxxps://www.mitre.org/sites/default/files/publications/pr-13-1028-mitre-10-strategies-cyber-ops-center.pdf). Strategy one in their...
View ArticleISC Stormcast For Wednesday, March 30th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC Stormcast For Thursday, March 31st 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article