-
Bringing the latest Blue Team news and information fresh to your Telegram inbox! 🔮 Red Teamer? Checkout @redteamalerts Submissions/feedback/questions: @skamath Low quality bot posts are manually removed.
A malicious campaign targeting verticals in the governmental monetary and financial sectors in Asia. This campaign poses as a central bank of an Asian nation to compel a victim to open an attachment containing a malicious HTA file. Once the HTA file is executed, it contains a JavaScript RAT
https://ift.tt/3bB5Sw1
Discuss on Reddit: https://ift.tt/3bKAUSq
@blueteamalerts
Sign over Your Hashes – Stealing NetNTLM Hashes via Outlook Signatures
https://ift.tt/2KlH5kw
Discuss on Reddit: https://ift.tt/2KmKxeK
@blueteamalerts
Analyzing Qakbot using Brim’s No-code threat hunting
https://ift.tt/3sq5EOp
Discuss on Reddit: https://ift.tt/2LAuyu7
@blueteamalerts
Microsoft Defender Attack Surface Reduction recommendations
https://ift.tt/2XzoN2i
Discuss on Reddit: https://ift.tt/3oIjQQz
@blueteamalerts
Chrome Browser Cloud Management - Google Chrome Enterprise Help
https://ift.tt/35A2wp9
Discuss on Reddit: https://ift.tt/3nHLJHc
@blueteamalerts
Lil Pwny 2.0.0 - Fast offline auditing of AD passwords using Python
https://ift.tt/39tDkSC
Discuss on Reddit: https://ift.tt/39siByp
@blueteamalerts
Intel® Threat Detection Technology (Intel® TDT) Product Brief - provides Hardware-based Accelerated Memory Scanning (AMS) and Advanced Platform Telemetry.
https://ift.tt/2XBJH0z
Discuss on Reddit: https://ift.tt/2Lkpb29
@blueteamalerts
Abusing cloud services to fly under the radar: full TTPs and IoCs of a suspected Chinese actor who targeted semiconductors and airlines - also known as Chimera in open source
https://ift.tt/39n9UFD
Discuss on Reddit: https://ift.tt/2LjPk16
@blueteamalerts
Microsoft recently informed Mimecast that Mimecast-issued certificate provided to certain customers to authenticate Mimecast Sync and Recover, Continuity Monitor, and IEP products to Microsoft 365 Exchange Web Services has been compromised by a sophisticated threat act
https://ift.tt/35yBEWK
Discuss on Reddit: https://ift.tt/3sszIJk
@blueteamalerts
Abusing cloud services to fly under the radar - NCC Group and Fox-IT have been tracking a threat group with a wide set of interests, from intellectual property (IP) from victims in the semiconductors industry through to passenger data from the airline industry who regularly use cloud services.
https://ift.tt/39n9UFD
Discuss on Reddit: https://ift.tt/3q9pOKw
@blueteamalerts
MAN1, Moskal, Hancitor and a side of ransomware
https://ift.tt/38zD3hH
Discuss on Reddit: https://ift.tt/35uSBS5
@blueteamalerts
The DFIR Report: Trickbot Still Alive and Well
https://ift.tt/2LjC9gk
Discuss on Reddit: https://ift.tt/39lcEDt
@blueteamalerts
Reserve Bank of New Zealand Responds to Malicious Data Breach
The Reserve Bank of New Zealand bank has confirmed a data breach of sensitive information. They had called out High op risk due to tech obsolescence and under investment in security across platform in May'20. Since, they've had to halt training in August due to DDoS attacks & are currently battling a data breach through a 3rd party file hosting partner.Though the method of compromise is yet to be revealed, the partner in question appears to be Accellion.
Discuss on Reddit: https://ift.tt/2Lp13Lz
@blueteamalerts
Set up your own malware analysis pipeline with Karton - CERT Polska
https://ift.tt/38NFRqj
Discuss on Reddit: https://ift.tt/3bsKVU3
@blueteamalerts
Leonardo S.p.A. Data Breach Analysis
https://ift.tt/39jDTy8
Discuss on Reddit: https://ift.tt/38vhAq8
@blueteamalerts
Running a fake power plant on the internet for a month
https://ift.tt/39zsR8j
Discuss on Reddit: https://ift.tt/38L4Trd
@blueteamalerts
Remcos RAT Revisited: A Colombian Coronavi
https://ift.tt/3i9LRhw
Discuss on Reddit: https://ift.tt/3bI9AnU
@blueteamalerts
Inside of CL0P’s ransomware operation
https://ift.tt/2XCzLUq
Discuss on Reddit: https://ift.tt/2LpHoLM
@blueteamalerts
Building a Custom Malware Analysis Lab Environment - SentinelLabs
https://ift.tt/38igePC
Discuss on Reddit: https://ift.tt/3qkkRyB
@blueteamalerts
John Strand (Senior SANS instructor) - "Pay what you can" course offer
https://wildwesthackinfest.com/training-schedule/ this is a great offer if you want some awesome training :)
Discuss on Reddit: https://ift.tt/3bD3mFO
@blueteamalerts
[RE019] From A to X analyzing some real cases which used recent Emotet samples
https://ift.tt/35D5XeX
Discuss on Reddit: https://ift.tt/39oiO5O
@blueteamalerts
Where to get Defcon DFIR 2018 CTF files?
Does anyone have or know where to get the DEFCON DFIR CTF 2018 files from
Discuss on Reddit: https://ift.tt/35Bo6Ki
@blueteamalerts
Introducing the In-the-Wild Series - This is part 1 of a 6-part series detailing a set of vulnerabilities found by Project Zero being exploited in the wild. To read the other parts of the series, head to the bottom of this post.
https://ift.tt/3qgAvLA
Discuss on Reddit: https://ift.tt/2LKY6EU
@blueteamalerts
Operation Spalax: Targeted malware attacks in Colombia | WeLiveSecurity
https://ift.tt/38DdVXa
Discuss on Reddit: https://ift.tt/3oEKA4f
@blueteamalerts
SUNSPOT Malware: A Technical Analysis
https://ift.tt/3bw77MT
Discuss on Reddit: https://ift.tt/3bvYEcA
@blueteamalerts
New tools for process tampering detection in sysinternals update
https://docs.microsoft.com/en-us/sysinternals/"mapped image of a process doesn’t match the on-disk image file, or the image file is locked for exclusive access"should be really useful for spotting process hollowing.
Discuss on Reddit: https://ift.tt/39jm02t
@blueteamalerts
Blue Team Management Tools
I would like to efficiently manage my team members, but I don't want to use e-mails for task assignment, training, etc. Because it is not an efficient way, and generating reports is time-consuming.Also, I can't use cloud-based tools. So I must deploy management tools or software manually.At this point, which open-source or free tools do you recommend to use for team management forTask assignment,The document, link, a video sharing platform for training,Questions and answers portal like a forum?I will give a try for OpenProject, theHive, and Mattermost. But your recommendations are essential to me.Thanks.
Discuss on Reddit: https://ift.tt/3i3gNzU
@blueteamalerts
Sunburst backdoor – code overlaps with Kazuar
https://ift.tt/35wCOls
Discuss on Reddit: https://ift.tt/38y34Oh
@blueteamalerts
A Golden SAML Journey: Detecting it with Splunk
https://ift.tt/3ox9anJ
Discuss on Reddit: https://ift.tt/2Loue1g
@blueteamalerts
Building an RDP Credential Catcher for Threat Intelligence
https://ift.tt/2XuaA6K
Discuss on Reddit: https://ift.tt/2XFi9HT
@blueteamalerts