blueteamalerts | Unsorted

Telegram-канал blueteamalerts - Blue Team Alerts

-

Bringing the latest Blue Team news and information fresh to your Telegram inbox! 🔮 Red Teamer? Checkout @redteamalerts Submissions/feedback/questions: @skamath Low quality bot posts are manually removed.

Subscribe to a channel

Blue Team Alerts

A malicious campaign targeting verticals in the governmental monetary and financial sectors in Asia. This campaign poses as a central bank of an Asian nation to compel a victim to open an attachment containing a malicious HTA file. Once the HTA file is executed, it contains a JavaScript RAT
https://ift.tt/3bB5Sw1

Discuss on Reddit: https://ift.tt/3bKAUSq
@blueteamalerts

Читать полностью…

Blue Team Alerts

Sign over Your Hashes – Stealing NetNTLM Hashes via Outlook Signatures
https://ift.tt/2KlH5kw

Discuss on Reddit: https://ift.tt/2KmKxeK
@blueteamalerts

Читать полностью…

Blue Team Alerts

Analyzing Qakbot using Brim’s No-code threat hunting
https://ift.tt/3sq5EOp

Discuss on Reddit: https://ift.tt/2LAuyu7
@blueteamalerts

Читать полностью…

Blue Team Alerts

Microsoft Defender Attack Surface Reduction recommendations
https://ift.tt/2XzoN2i

Discuss on Reddit: https://ift.tt/3oIjQQz
@blueteamalerts

Читать полностью…

Blue Team Alerts

Chrome Browser Cloud Management - Google Chrome Enterprise Help
https://ift.tt/35A2wp9

Discuss on Reddit: https://ift.tt/3nHLJHc
@blueteamalerts

Читать полностью…

Blue Team Alerts

Lil Pwny 2.0.0 - Fast offline auditing of AD passwords using Python
https://ift.tt/39tDkSC

Discuss on Reddit: https://ift.tt/39siByp
@blueteamalerts

Читать полностью…

Blue Team Alerts

Intel® Threat Detection Technology (Intel® TDT) Product Brief - provides Hardware-based Accelerated Memory Scanning (AMS) and Advanced Platform Telemetry.
https://ift.tt/2XBJH0z

Discuss on Reddit: https://ift.tt/2Lkpb29
@blueteamalerts

Читать полностью…

Blue Team Alerts

Abusing cloud services to fly under the radar: full TTPs and IoCs of a suspected Chinese actor who targeted semiconductors and airlines - also known as Chimera in open source
https://ift.tt/39n9UFD

Discuss on Reddit: https://ift.tt/2LjPk16
@blueteamalerts

Читать полностью…

Blue Team Alerts

Microsoft recently informed Mimecast that Mimecast-issued certificate provided to certain customers to authenticate Mimecast Sync and Recover, Continuity Monitor, and IEP products to Microsoft 365 Exchange Web Services has been compromised by a sophisticated threat act
https://ift.tt/35yBEWK

Discuss on Reddit: https://ift.tt/3sszIJk
@blueteamalerts

Читать полностью…

Blue Team Alerts

Abusing cloud services to fly under the radar - NCC Group and Fox-IT have been tracking a threat group with a wide set of interests, from intellectual property (IP) from victims in the semiconductors industry through to passenger data from the airline industry who regularly use cloud services.
https://ift.tt/39n9UFD

Discuss on Reddit: https://ift.tt/3q9pOKw
@blueteamalerts

Читать полностью…

Blue Team Alerts

MAN1, Moskal, Hancitor and a side of ransomware
https://ift.tt/38zD3hH

Discuss on Reddit: https://ift.tt/35uSBS5
@blueteamalerts

Читать полностью…

Blue Team Alerts

The DFIR Report: Trickbot Still Alive and Well
https://ift.tt/2LjC9gk

Discuss on Reddit: https://ift.tt/39lcEDt
@blueteamalerts

Читать полностью…

Blue Team Alerts

Reserve Bank of New Zealand Responds to Malicious Data Breach
The Reserve Bank of New Zealand bank has confirmed a data breach of sensitive information. They had called out High op risk due to tech obsolescence and under investment in security across platform in May'20. Since, they've had to halt training in August due to DDoS attacks & are currently battling a data breach through a 3rd party file hosting partner.Though the method of compromise is yet to be revealed, the partner in question appears to be Accellion.

Discuss on Reddit: https://ift.tt/2Lp13Lz
@blueteamalerts

Читать полностью…

Blue Team Alerts

Set up your own malware analysis pipeline with Karton - CERT Polska
https://ift.tt/38NFRqj

Discuss on Reddit: https://ift.tt/3bsKVU3
@blueteamalerts

Читать полностью…

Blue Team Alerts

Leonardo S.p.A. Data Breach Analysis
https://ift.tt/39jDTy8

Discuss on Reddit: https://ift.tt/38vhAq8
@blueteamalerts

Читать полностью…

Blue Team Alerts

Running a fake power plant on the internet for a month
https://ift.tt/39zsR8j

Discuss on Reddit: https://ift.tt/38L4Trd
@blueteamalerts

Читать полностью…

Blue Team Alerts

Remcos RAT Revisited: A Colombian Coronavi
https://ift.tt/3i9LRhw

Discuss on Reddit: https://ift.tt/3bI9AnU
@blueteamalerts

Читать полностью…

Blue Team Alerts

Inside of CL0P’s ransomware operation
https://ift.tt/2XCzLUq

Discuss on Reddit: https://ift.tt/2LpHoLM
@blueteamalerts

Читать полностью…

Blue Team Alerts

Building a Custom Malware Analysis Lab Environment - SentinelLabs
https://ift.tt/38igePC

Discuss on Reddit: https://ift.tt/3qkkRyB
@blueteamalerts

Читать полностью…

Blue Team Alerts

John Strand (Senior SANS instructor) - "Pay what you can" course offer
https://wildwesthackinfest.com/training-schedule/ this is a great offer if you want some awesome training :)

Discuss on Reddit: https://ift.tt/3bD3mFO
@blueteamalerts

Читать полностью…

Blue Team Alerts

[RE019] From A to X analyzing some real cases which used recent Emotet samples
https://ift.tt/35D5XeX

Discuss on Reddit: https://ift.tt/39oiO5O
@blueteamalerts

Читать полностью…

Blue Team Alerts

Where to get Defcon DFIR 2018 CTF files?
Does anyone have or know where to get the DEFCON DFIR CTF 2018 files from

Discuss on Reddit: https://ift.tt/35Bo6Ki
@blueteamalerts

Читать полностью…

Blue Team Alerts

Introducing the In-the-Wild Series - This is part 1 of a 6-part series detailing a set of vulnerabilities found by Project Zero being exploited in the wild. To read the other parts of the series, head to the bottom of this post.
https://ift.tt/3qgAvLA

Discuss on Reddit: https://ift.tt/2LKY6EU
@blueteamalerts

Читать полностью…

Blue Team Alerts

Operation Spalax: Targeted malware attacks in Colombia | WeLiveSecurity
https://ift.tt/38DdVXa

Discuss on Reddit: https://ift.tt/3oEKA4f
@blueteamalerts

Читать полностью…

Blue Team Alerts

SUNSPOT Malware: A Technical Analysis
https://ift.tt/3bw77MT

Discuss on Reddit: https://ift.tt/3bvYEcA
@blueteamalerts

Читать полностью…

Blue Team Alerts

New tools for process tampering detection in sysinternals update
https://docs.microsoft.com/en-us/sysinternals/"mapped image of a process doesn’t match the on-disk image file, or the image file is locked for exclusive access"should be really useful for spotting process hollowing.

Discuss on Reddit: https://ift.tt/39jm02t
@blueteamalerts

Читать полностью…

Blue Team Alerts

Blue Team Management Tools
I would like to efficiently manage my team members, but I don't want to use e-mails for task assignment, training, etc. Because it is not an efficient way, and generating reports is time-consuming.Also, I can't use cloud-based tools. So I must deploy management tools or software manually.At this point, which open-source or free tools do you recommend to use for team management forTask assignment,The document, link, a video sharing platform for training,Questions and answers portal like a forum?I will give a try for OpenProject, theHive, and Mattermost. But your recommendations are essential to me.Thanks.

Discuss on Reddit: https://ift.tt/3i3gNzU
@blueteamalerts

Читать полностью…

Blue Team Alerts

Sunburst backdoor – code overlaps with Kazuar
https://ift.tt/35wCOls

Discuss on Reddit: https://ift.tt/38y34Oh
@blueteamalerts

Читать полностью…

Blue Team Alerts

A Golden SAML Journey: Detecting it with Splunk
https://ift.tt/3ox9anJ

Discuss on Reddit: https://ift.tt/2Loue1g
@blueteamalerts

Читать полностью…

Blue Team Alerts

Building an RDP Credential Catcher for Threat Intelligence
https://ift.tt/2XuaA6K

Discuss on Reddit: https://ift.tt/2XFi9HT
@blueteamalerts

Читать полностью…
Subscribe to a channel