home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

  1. No PE header? No problem.

    @FortiGuardLabs dropped a deep dive into a malware sample dumped without a PE header — like a cybercriminal rage-quit halfway through packing their payload.

    You ever load a binary in IDA and think, “Am I being punk’d?”
    Yeah, it’s one of those samples.

    This sample:

    • Reconstructs its own PE structure at runtime

    • Hides config data in obfuscated blobs

    • Uses anti-sandbox tricks to avoid analysis

    • Drops yet another info-stealer, because originality is dead

    It’s engineered to break basic static analysis and dodge sandboxes like it’s speedrunning DEFCON CTF.

    🔗 Full breakdown:
    fortinet.com/blog/threat-resea

    TL;DR for blue teamers:

    • Static AV signatures won’t help here

    • Watch for suspicious memory allocations + hollowing patterns

    • Endpoint heuristics > file-based detection

    • Log your PowerShell and LOLBins — this thing probably brings friends

    • If your EDR cries when it sees raw shellcode, maybe give it a hug

    #ThreatIntel #MalwareAnalysis #ReverseEngineering #Infosec #PEFilesAreSo2020 #EDREvasion #LOLbins #CyberSecurity #BlueTeam

  2. There so many trainings and certification out there in the infosec field. This one gives a good overview. With that you can make your own training plan.

    #cybersecurity #trainings #blueteam #redteam #infosec #purpleteam #career

    pauljerimy.com/security-certif

  3. The Symantec research team uncovered an espionage campaign from the #APT group they track as #Redfly. The group used multiple tools during the campaign which included the #ShadowPad trojan, #Packerloader, and a key logger. They also abused some #LOLBINs to achieve their goals.

    Redfly masqueraded ShadowPad in a "VMware" directory and gained persistence by creating a service that ran the malware once the computer started and the keylogger stored its captured keystrokes in a directory that included "Intel" in the path. The APT group used the reg.exe to dump credentials from he SYSTEM, SAM, and SECURITY hive. They also used a renamed version of ProcDump to dump credentials from LSASS. Powershell was also used to gather information on the storage devices attached to the system and finally a scheduled task was created to preform side-loading and lateral movement. #HappyHunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday

  4. While most of us celebrate Labor Day let's all try to take a moment to remember those who don't get to spend time with their loved ones today, wherever they may be and whatever they may be doing!

    I don't know how this report slid under my radar but the ESET researched team unveil a "Marioesque" themed adversary, #MoustachedBouncer! They are a cyberespionage group that targets foreign embassies in Belarus with the use of their ISP level access and their tools #NightClub and #Disco. Using their (assumed) unique level of access, they compromise their targets by redirecting them to a fake #Microsoft update site which loads JavaScript code then leads to a zip file being downloaded. The team wasn't able to get the zip file, but they were still able to identify some TTPs and #LOLBINS abuse, such as creating a malicious scheduled task. I hope you enjoy and Happy Hunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #LaborDay

  5. Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday

  6. @hacks4pancakes @Lockdownyourlife @topher
    @TheGibson

    Bought the humble bundle which has two books within that cover certs. One is for the Security+ , which I know is a given to be taking. The other covers the Certified Ethical Hacking v12 #ceh cert, and I'm seeing some negative reviews on that. Do any of you have an opinion on it?

    #certifications #security #opsec #redteam #blueteam