home.social

#gethunting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #gethunting, aggregated by home.social.

fetched live
  1. To aid you in your Threat Hunting journey, check out this Threat Profile based on behaviors associated with Amadey! There are two Community Hunt Packages that can get you started! Now get hunting!

    Amadey
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  2. To aid you in your Threat Hunting journey, check out this Threat Profile based on behaviors associated with Amadey! There are two Community Hunt Packages that can get you started! Now get hunting!

    Amadey
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  3. To aid you in your Threat Hunting journey, check out this Threat Profile based on behaviors associated with Amadey! There are two Community Hunt Packages that can get you started! Now get hunting!

    Amadey
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  4. To aid you in your Threat Hunting journey, check out this Threat Profile based on behaviors associated with Amadey! There are two Community Hunt Packages that can get you started! Now get hunting!

    Amadey
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  5. To aid you in your Threat Hunting journey, check out this Threat Profile based on behaviors associated with Amadey! There are two Community Hunt Packages that can get you started! Now get hunting!

    Amadey
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  6. And of course, another great resource that you can use for your Intel-Driven threat hunting efforts from MITRE ATT&CK. There is enough intel here to create a bunch of different hypotheses and hunt queries!

    Salt Typhoon
    attack.mitre.org/groups/G1045/

    #huntoftheday #gethunting

  7. And of course, another great resource that you can use for your Intel-Driven threat hunting efforts from MITRE ATT&CK. There is enough intel here to create a bunch of different hypotheses and hunt queries!

    Salt Typhoon
    attack.mitre.org/groups/G1045/

    #huntoftheday #gethunting

  8. And of course, another great resource that you can use for your Intel-Driven threat hunting efforts from MITRE ATT&CK. There is enough intel here to create a bunch of different hypotheses and hunt queries!

    Salt Typhoon
    attack.mitre.org/groups/G1045/

    #huntoftheday #gethunting

  9. And of course, another great resource that you can use for your Intel-Driven threat hunting efforts from MITRE ATT&CK. There is enough intel here to create a bunch of different hypotheses and hunt queries!

    Salt Typhoon
    attack.mitre.org/groups/G1045/

    #huntoftheday #gethunting

  10. First, we have created a Hunt Package Collection based on hashtag#SaltTyphoon behaviors which you can find here! There is a Community Edition hunt package in there that can get your hunting started!

    Salt Tyhpoon Hunt Package Collection
    hunter.cyborgsecurity.io/resea)

    #huntoftheday #gethunting

  11. First, we have created a Hunt Package Collection based on hashtag#SaltTyphoon behaviors which you can find here! There is a Community Edition hunt package in there that can get your hunting started!

    Salt Tyhpoon Hunt Package Collection
    hunter.cyborgsecurity.io/resea)

    #huntoftheday #gethunting

  12. First, we have created a Hunt Package Collection based on hashtag#SaltTyphoon behaviors which you can find here! There is a Community Edition hunt package in there that can get your hunting started!

    Salt Tyhpoon Hunt Package Collection
    hunter.cyborgsecurity.io/resea)

    #huntoftheday #gethunting

  13. First, we have created a Hunt Package Collection based on hashtag#SaltTyphoon behaviors which you can find here! There is a Community Edition hunt package in there that can get your hunting started!

    Salt Tyhpoon Hunt Package Collection
    hunter.cyborgsecurity.io/resea)

    #huntoftheday #gethunting

  14. Not to beat a dead horse, but deleting shadow copies is a very common behavior that many ransomware strains use. So if you are on the hunt, let us help you with this Community Hunt Package!

    Shadow Copies Deletion Using Operating Systems Utilities
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  15. Not to beat a dead horse, but deleting shadow copies is a very common behavior that many ransomware strains use. So if you are on the hunt, let us help you with this Community Hunt Package!

    Shadow Copies Deletion Using Operating Systems Utilities
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  16. Not to beat a dead horse, but deleting shadow copies is a very common behavior that many ransomware strains use. So if you are on the hunt, let us help you with this Community Hunt Package!

    Shadow Copies Deletion Using Operating Systems Utilities
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  17. Not to beat a dead horse, but deleting shadow copies is a very common behavior that many ransomware strains use. So if you are on the hunt, let us help you with this Community Hunt Package!

    Shadow Copies Deletion Using Operating Systems Utilities
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  18. If this article got you thinking about LOLBINs, take this great information and make it actionable with this Community Hunt Package! It covers the execution of common LOLBINs directly related to discovery activity! Now Get Hunting!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  19. If this article got you thinking about LOLBINs, take this great information and make it actionable with this Community Hunt Package! It covers the execution of common LOLBINs directly related to discovery activity! Now Get Hunting!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  20. If this article got you thinking about LOLBINs, take this great information and make it actionable with this Community Hunt Package! It covers the execution of common LOLBINs directly related to discovery activity! Now Get Hunting!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  21. If this article got you thinking about LOLBINs, take this great information and make it actionable with this Community Hunt Package! It covers the execution of common LOLBINs directly related to discovery activity! Now Get Hunting!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  22. If this article got you thinking about LOLBINs, take this great information and make it actionable with this Community Hunt Package! It covers the execution of common LOLBINs directly related to discovery activity! Now Get Hunting!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  23. Apologies for the delay, didn't mean to leave all your threat hunters hanging! According to the researchers, #Anubis #ransomware runs the following command to inhibit system recovery (T1490) " vssadmin delete shadows /for=norealvolume /all /quiet". This is a common behavior from ransomware strains but you can use this Community Hunt Package to help discover that activity in your environment! Go find evil and get hunting!

    Shadow Copies Deletion Using Operating Systems Utilities

    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting!

  24. Apologies for the delay, didn't mean to leave all your threat hunters hanging! According to the researchers, #Anubis #ransomware runs the following command to inhibit system recovery (T1490) " vssadmin delete shadows /for=norealvolume /all /quiet". This is a common behavior from ransomware strains but you can use this Community Hunt Package to help discover that activity in your environment! Go find evil and get hunting!

    Shadow Copies Deletion Using Operating Systems Utilities

    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting!

  25. Apologies for the delay, didn't mean to leave all your threat hunters hanging! According to the researchers, #Anubis #ransomware runs the following command to inhibit system recovery (T1490) " vssadmin delete shadows /for=norealvolume /all /quiet". This is a common behavior from ransomware strains but you can use this Community Hunt Package to help discover that activity in your environment! Go find evil and get hunting!

    Shadow Copies Deletion Using Operating Systems Utilities

    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting!

  26. Apologies for the delay, didn't mean to leave all your threat hunters hanging! According to the researchers, #Anubis #ransomware runs the following command to inhibit system recovery (T1490) " vssadmin delete shadows /for=norealvolume /all /quiet". This is a common behavior from ransomware strains but you can use this Community Hunt Package to help discover that activity in your environment! Go find evil and get hunting!

    Shadow Copies Deletion Using Operating Systems Utilities

    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting!

  27. Apologies for the delay, didn't mean to leave all your threat hunters hanging! According to the researchers, #Anubis #ransomware runs the following command to inhibit system recovery (T1490) " vssadmin delete shadows /for=norealvolume /all /quiet". This is a common behavior from ransomware strains but you can use this Community Hunt Package to help discover that activity in your environment! Go find evil and get hunting!

    Shadow Copies Deletion Using Operating Systems Utilities

    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting!

  28. If RMM tool abuse is something you are concerned about check out this community hunt package! This hunt package is designed to identify when a service is created to run AnyDesk, which was a tactic the adversary used in this report! Hope you enjoy and Happy Hunting!

    AnyDesk Service Installation - Potentially Malicious RMM Tool Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  29. If RMM tool abuse is something you are concerned about check out this community hunt package! This hunt package is designed to identify when a service is created to run AnyDesk, which was a tactic the adversary used in this report! Hope you enjoy and Happy Hunting!

    AnyDesk Service Installation - Potentially Malicious RMM Tool Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  30. If RMM tool abuse is something you are concerned about check out this community hunt package! This hunt package is designed to identify when a service is created to run AnyDesk, which was a tactic the adversary used in this report! Hope you enjoy and Happy Hunting!

    AnyDesk Service Installation - Potentially Malicious RMM Tool Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  31. If RMM tool abuse is something you are concerned about check out this community hunt package! This hunt package is designed to identify when a service is created to run AnyDesk, which was a tactic the adversary used in this report! Hope you enjoy and Happy Hunting!

    AnyDesk Service Installation - Potentially Malicious RMM Tool Installation
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  32. AND A HUNT OF THE DAY!?! You know it! Looking at where the malware created their scheduled task you can tell it is a little phishy, but there are more locations that adversaries like to use/abuse! See what you can find in your environment with this! Yes, it is community and I hope it gets you off on your journey if you haven't started OR it adds another tool to your existing toolbox! Happy Hunting!

    Scheduled Task Executing from Abnormal Location
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  33. AND A HUNT OF THE DAY!?! You know it! Looking at where the malware created their scheduled task you can tell it is a little phishy, but there are more locations that adversaries like to use/abuse! See what you can find in your environment with this! Yes, it is community and I hope it gets you off on your journey if you haven't started OR it adds another tool to your existing toolbox! Happy Hunting!

    Scheduled Task Executing from Abnormal Location
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  34. AND A HUNT OF THE DAY!?! You know it! Looking at where the malware created their scheduled task you can tell it is a little phishy, but there are more locations that adversaries like to use/abuse! See what you can find in your environment with this! Yes, it is community and I hope it gets you off on your journey if you haven't started OR it adds another tool to your existing toolbox! Happy Hunting!

    Scheduled Task Executing from Abnormal Location
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  35. AND A HUNT OF THE DAY!?! You know it! Looking at where the malware created their scheduled task you can tell it is a little phishy, but there are more locations that adversaries like to use/abuse! See what you can find in your environment with this! Yes, it is community and I hope it gets you off on your journey if you haven't started OR it adds another tool to your existing toolbox! Happy Hunting!

    Scheduled Task Executing from Abnormal Location
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting #HappyHunting

  36. To compliment the work of the authors, why not take this Community Hunt Package with you to identify when a Powershell encoded command is executed in your environment:

    Powershell Encoded Command Execution
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  37. To compliment the work of the authors, why not take this Community Hunt Package with you to identify when a Powershell encoded command is executed in your environment:

    Powershell Encoded Command Execution
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  38. To compliment the work of the authors, why not take this Community Hunt Package with you to identify when a Powershell encoded command is executed in your environment:

    Powershell Encoded Command Execution
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  39. To compliment the work of the authors, why not take this Community Hunt Package with you to identify when a Powershell encoded command is executed in your environment:

    Powershell Encoded Command Execution
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  40. I had this all ready but forgot to send yesterday! For your #huntoftheday I would recommend conducting an unstructured hunt on processes making network detections that could lead to C2 activity! Enjoy and Happy Hunting!

    #gethunting

  41. I had this all ready but forgot to send yesterday! For your #huntoftheday I would recommend conducting an unstructured hunt on processes making network detections that could lead to C2 activity! Enjoy and Happy Hunting!

    #gethunting

  42. I had this all ready but forgot to send yesterday! For your #huntoftheday I would recommend conducting an unstructured hunt on processes making network detections that could lead to C2 activity! Enjoy and Happy Hunting!

    #gethunting

  43. I had this all ready but forgot to send yesterday! For your #huntoftheday I would recommend conducting an unstructured hunt on processes making network detections that could lead to C2 activity! Enjoy and Happy Hunting!

    #gethunting

  44. And, if you are taking this wonderful intel and using it to threat hunt, why not let us help you! Check out this Community Hunt Package that helps identify when AnyDesk is executed from an abnormal folder. Yes it wasn't mentioned in the article, but there are PLENTY of examples of this abuse in many other articles! Enjoy and Happy Hunting!

    AnyDesk Execution from Abnormal Folder - Potential Malicious Use of RMM Tool
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  45. And, if you are taking this wonderful intel and using it to threat hunt, why not let us help you! Check out this Community Hunt Package that helps identify when AnyDesk is executed from an abnormal folder. Yes it wasn't mentioned in the article, but there are PLENTY of examples of this abuse in many other articles! Enjoy and Happy Hunting!

    AnyDesk Execution from Abnormal Folder - Potential Malicious Use of RMM Tool
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  46. And, if you are taking this wonderful intel and using it to threat hunt, why not let us help you! Check out this Community Hunt Package that helps identify when AnyDesk is executed from an abnormal folder. Yes it wasn't mentioned in the article, but there are PLENTY of examples of this abuse in many other articles! Enjoy and Happy Hunting!

    AnyDesk Execution from Abnormal Folder - Potential Malicious Use of RMM Tool
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  47. And, if you are taking this wonderful intel and using it to threat hunt, why not let us help you! Check out this Community Hunt Package that helps identify when AnyDesk is executed from an abnormal folder. Yes it wasn't mentioned in the article, but there are PLENTY of examples of this abuse in many other articles! Enjoy and Happy Hunting!

    AnyDesk Execution from Abnormal Folder - Potential Malicious Use of RMM Tool
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  48. Don't think I was going to leave you hanging! If you haven't got this hunt package yet, what are you waiting for? This is probably the top community hunt package I post because the technique is SO common! Let us help you hunt for persistence through the modification of the Windows Run Registry key and other locations. I promise, the NanoCore RAT is not the only malware to use it, so you got multiple threats covers. Enjoy and Happy Hunting!

    Autorun or ASEP Registry Key Modification
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  49. Don't think I was going to leave you hanging! If you haven't got this hunt package yet, what are you waiting for? This is probably the top community hunt package I post because the technique is SO common! Let us help you hunt for persistence through the modification of the Windows Run Registry key and other locations. I promise, the NanoCore RAT is not the only malware to use it, so you got multiple threats covers. Enjoy and Happy Hunting!

    Autorun or ASEP Registry Key Modification
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  50. Don't think I was going to leave you hanging! If you haven't got this hunt package yet, what are you waiting for? This is probably the top community hunt package I post because the technique is SO common! Let us help you hunt for persistence through the modification of the Windows Run Registry key and other locations. I promise, the NanoCore RAT is not the only malware to use it, so you got multiple threats covers. Enjoy and Happy Hunting!

    Autorun or ASEP Registry Key Modification
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  51. Don't think I was going to leave you hanging! If you haven't got this hunt package yet, what are you waiting for? This is probably the top community hunt package I post because the technique is SO common! Let us help you hunt for persistence through the modification of the Windows Run Registry key and other locations. I promise, the NanoCore RAT is not the only malware to use it, so you got multiple threats covers. Enjoy and Happy Hunting!

    Autorun or ASEP Registry Key Modification
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  52. And more good news! I am going to leave you with a community hunt package from our Ransomware Collection for you to stay diligent in your threat hunting efforts! So go get hunting!

    Windows sc Used to Disable Multiple Services in Brief Period - Potential Ransomware
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  53. And more good news! I am going to leave you with a community hunt package from our Ransomware Collection for you to stay diligent in your threat hunting efforts! So go get hunting!

    Windows sc Used to Disable Multiple Services in Brief Period - Potential Ransomware
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  54. And more good news! I am going to leave you with a community hunt package from our Ransomware Collection for you to stay diligent in your threat hunting efforts! So go get hunting!

    Windows sc Used to Disable Multiple Services in Brief Period - Potential Ransomware
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  55. And more good news! I am going to leave you with a community hunt package from our Ransomware Collection for you to stay diligent in your threat hunting efforts! So go get hunting!

    Windows sc Used to Disable Multiple Services in Brief Period - Potential Ransomware
    hunter.cyborgsecurity.io/resea

    #huntoftheday #gethunting

  56. And as a gift for you on Friday, here are TWO community hunt packages you can use to hunt for similar suspicious activity! Happy Hunting!

    Scheduled Task Executing from Abnormal Location

    hunter.cyborgsecurity.io/resea

    This hunt package is designed to capture activity associated with a scheduled task which includes abnormal locations in its details for execution. This is often a mark of persistence or malicious tasks created by malware or attackers. details.

    Potential Maldoc Execution Chain Observed

    hunter.cyborgsecurity.io/resea

    Detect the aftermath of a successfully delivered and executed maldoc (Microsoft Office). A detection indicates an Office document was opened from an email or download/link, spawned a suspicious execution, and attempted to execute code via common Windows binaries (i.e. powershell, cmd, rundll32, etc).

    #huntoftheday #gethunting