home.social

#mitreattack — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mitreattack, aggregated by home.social.

fetched live
  1. Ищем lateral movement нейросетью, обученной на синтетических данных

    Можно ли научить детектор атак, ни разу не показав ему настоящую атаку? Звучит как противоречие. Если хочешь, чтобы нейросеть находила боковое движение, ей вроде бы надо показать боковое движение. Я сделал наоборот: сгенерировал целую корпоративную сеть с её историей входов, устроил в этом выдуманном мире нападение и обучил на нём сети. Ни одной настоящей строки в обучении. Весь мир описан конфигом на 135 строк, каждая сеть весит четыре тысячи параметров и учится за секунды на ноутбуке; лучший результат дали шесть таких сетей, обученных на шести разных выдуманных мирах. Потом я выпустил их на настоящие данные: журналы аутентификации Лос-Аламосской лаборатории, 1.65 миллиарда событий, с размеченными учениями красной команды. И это сработало. Сети выстраивают 3.6 миллиона окон по подозрительности, и в верхних двадцати трёх строках списка стоят шестнадцать настоящих атак и семь ложных тревог: аналитику остаётся открыть эти строки. Пороговому счётчику, чтобы добраться до шестнадцатой атаки на тех же данных, нужно сто шестьдесят одна тысяча ложных тревог. По AUC синтетика вошла в диапазон исследовательских работ, обученных на настоящих размеченных данных, хотя сравнивать их в лоб нельзя, и я объясню почему. Чуда всё равно не случилось. Зато случилось другое: я дважды написал красивый вывод и дважды забрал его назад, когда эксперимент его опроверг. И нашёл петлю, ради которой вообще стоит писать генератор: ошибка детектора показывает конкретную машину, ты понимаешь, какого явления нет в твоём выдуманном мире, дописываешь две строки конфига, и ошибка исчезает.

    habr.com/ru/articles/1081092/

    #боковоедвижение #lateralmovement #синтетическиеданные #генерациятестовыхданных #обнаружениевторжений #журналыаутентификации #LANL #MITREATTACK #LSTM #TDCV2

  2. Ищем lateral movement нейросетью, обученной на синтетических данных

    Можно ли научить детектор атак, ни разу не показав ему настоящую атаку? Звучит как противоречие. Если хочешь, чтобы нейросеть находила боковое движение, ей вроде бы надо показать боковое движение. Я сделал наоборот: сгенерировал целую корпоративную сеть с её историей входов, устроил в этом выдуманном мире нападение и обучил на нём сети. Ни одной настоящей строки в обучении. Весь мир описан конфигом на 135 строк, каждая сеть весит четыре тысячи параметров и учится за секунды на ноутбуке; лучший результат дали шесть таких сетей, обученных на шести разных выдуманных мирах. Потом я выпустил их на настоящие данные: журналы аутентификации Лос-Аламосской лаборатории, 1.65 миллиарда событий, с размеченными учениями красной команды. И это сработало. Сети выстраивают 3.6 миллиона окон по подозрительности, и в верхних двадцати трёх строках списка стоят шестнадцать настоящих атак и семь ложных тревог: аналитику остаётся открыть эти строки. Пороговому счётчику, чтобы добраться до шестнадцатой атаки на тех же данных, нужно сто шестьдесят одна тысяча ложных тревог. По AUC синтетика вошла в диапазон исследовательских работ, обученных на настоящих размеченных данных, хотя сравнивать их в лоб нельзя, и я объясню почему. Чуда всё равно не случилось. Зато случилось другое: я дважды написал красивый вывод и дважды забрал его назад, когда эксперимент его опроверг. И нашёл петлю, ради которой вообще стоит писать генератор: ошибка детектора показывает конкретную машину, ты понимаешь, какого явления нет в твоём выдуманном мире, дописываешь две строки конфига, и ошибка исчезает.

    habr.com/ru/articles/1081092/

    #боковоедвижение #lateralmovement #синтетическиеданные #генерациятестовыхданных #обнаружениевторжений #журналыаутентификации #LANL #MITREATTACK #LSTM #TDCV2

  3. Ищем lateral movement нейросетью, обученной на синтетических данных

    Можно ли научить детектор атак, ни разу не показав ему настоящую атаку? Звучит как противоречие. Если хочешь, чтобы нейросеть находила боковое движение, ей вроде бы надо показать боковое движение. Я сделал наоборот: сгенерировал целую корпоративную сеть с её историей входов, устроил в этом выдуманном мире нападение и обучил на нём сети. Ни одной настоящей строки в обучении. Весь мир описан конфигом на 135 строк, каждая сеть весит четыре тысячи параметров и учится за секунды на ноутбуке; лучший результат дали шесть таких сетей, обученных на шести разных выдуманных мирах. Потом я выпустил их на настоящие данные: журналы аутентификации Лос-Аламосской лаборатории, 1.65 миллиарда событий, с размеченными учениями красной команды. И это сработало. Сети выстраивают 3.6 миллиона окон по подозрительности, и в верхних двадцати трёх строках списка стоят шестнадцать настоящих атак и семь ложных тревог: аналитику остаётся открыть эти строки. Пороговому счётчику, чтобы добраться до шестнадцатой атаки на тех же данных, нужно сто шестьдесят одна тысяча ложных тревог. По AUC синтетика вошла в диапазон исследовательских работ, обученных на настоящих размеченных данных, хотя сравнивать их в лоб нельзя, и я объясню почему. Чуда всё равно не случилось. Зато случилось другое: я дважды написал красивый вывод и дважды забрал его назад, когда эксперимент его опроверг. И нашёл петлю, ради которой вообще стоит писать генератор: ошибка детектора показывает конкретную машину, ты понимаешь, какого явления нет в твоём выдуманном мире, дописываешь две строки конфига, и ошибка исчезает.

    habr.com/ru/articles/1081092/

    #боковоедвижение #lateralmovement #синтетическиеданные #генерациятестовыхданных #обнаружениевторжений #журналыаутентификации #LANL #MITREATTACK #LSTM #TDCV2

  4. 📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs

    Live on every vulnerability page of vulnerability.circl.lu

    Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.

    Paper: arxiv.org/abs/2607.25572
    Code: github.com/vulnerability-looku

    #CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama

  5. 📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs

    Live on every vulnerability page of vulnerability.circl.lu

    Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.

    Paper: arxiv.org/abs/2607.25572
    Code: github.com/vulnerability-looku

    #CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama

  6. 📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs

    Live on every vulnerability page of vulnerability.circl.lu

    Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.

    Paper: arxiv.org/abs/2607.25572
    Code: github.com/vulnerability-looku

    #CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama

  7. 📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs

    Live on every vulnerability page of vulnerability.circl.lu

    Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.

    Paper: arxiv.org/abs/2607.25572
    Code: github.com/vulnerability-looku

    #CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama

  8. 📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs

    Live on every vulnerability page of vulnerability.circl.lu

    Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.

    Paper: arxiv.org/abs/2607.25572
    Code: github.com/vulnerability-looku

    #CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama

  9. 🚀 Vulnerability-Lookup 5.5.0 is out!

    🔐 Full Role-Based Access Control replaces the legacy admin flags
    🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
    🇪🇺 EUVD ID allocation pipeline
    🛠️ Feeder supervision, new VEX sources & feeders

    👉 vulnerability-lookup.org/2026/

    #VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK

  10. 🚀 Vulnerability-Lookup 5.5.0 is out!

    🔐 Full Role-Based Access Control replaces the legacy admin flags
    🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
    🇪🇺 EUVD ID allocation pipeline
    🛠️ Feeder supervision, new VEX sources & feeders

    👉 vulnerability-lookup.org/2026/

    #VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK

  11. 🚀 Vulnerability-Lookup 5.5.0 is out!

    🔐 Full Role-Based Access Control replaces the legacy admin flags
    🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
    🇪🇺 EUVD ID allocation pipeline
    🛠️ Feeder supervision, new VEX sources & feeders

    👉 vulnerability-lookup.org/2026/

    #VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK

  12. 🚀 Vulnerability-Lookup 5.5.0 is out!

    🔐 Full Role-Based Access Control replaces the legacy admin flags
    🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
    🇪🇺 EUVD ID allocation pipeline
    🛠️ Feeder supervision, new VEX sources & feeders

    👉 vulnerability-lookup.org/2026/

    #VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK

  13. 🚀 Vulnerability-Lookup 5.5.0 is out!

    🔐 Full Role-Based Access Control replaces the legacy admin flags
    🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
    🇪🇺 EUVD ID allocation pipeline
    🛠️ Feeder supervision, new VEX sources & feeders

    👉 vulnerability-lookup.org/2026/

    #VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK

  14. ----------------

    🎯 AI
    ===================

    Sygnia: AI-Supercharged 72-Hour Cloud Attack Investigation

    Sygnia published findings from an incident response engagement where a threat actor compromised an AWS-based environment, progressing from initial access to broad cloud compromise in approximately 72 hours. The case is notable not for novel techniques, but for the apparent use of AI to accelerate familiar cloud attack methods.

    Key Findings
    • The intrusion expanded across applications, cloud infrastructure, source-control systems, CI/CD pipelines, and runtime services
    • No zero-day exploits or novel malware were observed. Every technique mapped to established MITRE ATT&CK behaviors
    • Multiple artifacts suggested AI-assisted or agentic workflows: attacker-created scripts, structured reporting artifacts, and highly parallel activity
    • The threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities
    • The primary defensive challenge was the speed and scale of execution, not the novelty of individual techniques

    Where AI Changed the Equation

    The report identifies several indicators of AI involvement:
    • Rapid generation of environment-specific scripts and tooling
    • Structured, formatted reporting artifacts consistent with AI-generated output
    • Highly parallel discovery and exploitation activities across multiple surfaces
    • Compressed timeline for reconnaissance, adaptation, and operational execution inconsistent with purely manual operations

    Attack Path

    1. Initial access to AWS environment
    2. Credential harvesting and secrets discovery
    3. Lateral movement across applications and cloud services
    4. Persistence through compromised identity and deployment workflows
    5. Expansion into source-control and CI/CD systems
    6. Impact across cloud, identity, and application layers

    Each credential acquisition restarted the cycle.

    Defensive Gaps
    • Fragmented visibility across cloud, identity, and application layers
    • Monitoring gaps that delayed detection and correlation
    • Absence of predefined incident response procedures
    • Weak secrets management and identity governance
    • Overly permissive cloud and CI/CD permissions

    Remediation

    Sygnia recommends adapting IR playbooks for AI-enabled threats, prioritizing broad containment over precision when speed matters, rotating credentials aggressively, treating identity as the primary security boundary, and automating defensive responses. Infrastructure rebuilds may be necessary for broadly compromised environments.

    Known weaknesses get exploited faster and at broader scale when AI assistance is available. End-to-end visibility and predefined containment procedures are prerequisites, not aspirations.

    🔹 AI #CloudSecurity #IncidentResponse #Sygnia #MITREATTACK

    🔗 Source: sygnia.co/blog/inside-an-ai-as

  15. 5/5 Lateral Movement Assessment

    Using valid administrator credentials, the attacker leveraged remote execution utilities to access additional internal hosts.

    Observed Attack Chain:

    PHPStudy Exploitation
    → Discovery
    → Payload Deployment
    → C2 Establishment
    → Persistence
    → Credential Access
    → Network Discovery
    → Lateral Movement

    This intrusion demonstrates how a single vulnerable web application can rapidly evolve into broader internal compromise.

    #ThreatIntel #CTI #MITREATTACK

  16. 1/5 Threat Activity Analysis

    Source: Attack simulation telemetry analysis.

    Initial access was achieved through exploitation of a vulnerable PHPStudy deployment. The attacker executed reconnaissance commands to identify the current user context, network configuration, ARP cache, and external connectivity.

    Assessment: The activity indicates validation of code execution capabilities prior to payload deployment.

    ATT&CK: T1190, T1082, T1016

    #ThreatIntel #CyberSecurity #MITREATTACK

  17. 1/5 Threat Activity Analysis

    Source: Attack simulation telemetry analysis.

    Initial access was achieved through exploitation of a vulnerable PHPStudy deployment. The attacker executed reconnaissance commands to identify the current user context, network configuration, ARP cache, and external connectivity.

    Assessment: The activity indicates validation of code execution capabilities prior to payload deployment.

    ATT&CK: T1190, T1082, T1016

    #ThreatIntel #CyberSecurity #MITREATTACK

  18. A red-team wiper emulating Sandworm (GRU Unit 74455) has been published - a 90-line Go binary demonstrating LotL execution across 121 MITRE ATT&CK techniques including T1490, T1561.001, and T1070.001.

    Full report:
    technadu.com/sandworm-gru-unit

    Follow @technadu for more threat intel updates.

    #Sandworm #GRU74455 #MITREATTACK #RedTeam #BlueTeam #Infosec #WiperMalware

  19. A red-team wiper emulating Sandworm (GRU Unit 74455) has been published - a 90-line Go binary demonstrating LotL execution across 121 MITRE ATT&CK techniques including T1490, T1561.001, and T1070.001.

    Full report:
    technadu.com/sandworm-gru-unit

    Follow @technadu for more threat intel updates.

    #Sandworm #GRU74455 #MITREATTACK #RedTeam #BlueTeam #Infosec #WiperMalware

  20. A red-team wiper emulating Sandworm (GRU Unit 74455) has been published - a 90-line Go binary demonstrating LotL execution across 121 MITRE ATT&CK techniques including T1490, T1561.001, and T1070.001.

    Full report:
    technadu.com/sandworm-gru-unit

    Follow @technadu for more threat intel updates.

    #Sandworm #GRU74455 #MITREATTACK #RedTeam #BlueTeam #Infosec #WiperMalware

  21. 🚀 MITRE ATT&CK v18 = a major leap in detection depth.

    The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.

    Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.

    MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.

    💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
    Follow @technadu for more #ThreatIntel insights.

    #CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity

  22. 🚀 MITRE ATT&CK v18 = a major leap in detection depth.

    The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.

    Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.

    MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.

    💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
    Follow @technadu for more #ThreatIntel insights.

    #CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity

  23. 🚀 MITRE ATT&CK v18 = a major leap in detection depth.

    The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.

    Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.

    MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.

    💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
    Follow @technadu for more #ThreatIntel insights.

    #CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity

  24. 🚀 MITRE ATT&CK v18 = a major leap in detection depth.

    The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.

    Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.

    MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.

    💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
    Follow @technadu for more #ThreatIntel insights.

    #CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity

  25. 🚀 MITRE ATT&CK v18 = a major leap in detection depth.

    The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.

    Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.

    MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.

    💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
    Follow @technadu for more #ThreatIntel insights.

    #CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity

  26. New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
    Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
    Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
    🛡️ Detection ideas:
    - Monitor consent grants in Entra ID logs.
    - Restrict unverified app registrations.
    - Disable user app creation.
    - Flag Copilot bots using trial tenants or untrusted domains.

    How are you tuning detections for AI-driven OAuth phishing?
    💬 Share your strategies & follow @technadu for more technical threat intel.

    #OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu

  27. New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
    Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
    Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
    🛡️ Detection ideas:
    - Monitor consent grants in Entra ID logs.
    - Restrict unverified app registrations.
    - Disable user app creation.
    - Flag Copilot bots using trial tenants or untrusted domains.

    How are you tuning detections for AI-driven OAuth phishing?
    💬 Share your strategies & follow @technadu for more technical threat intel.

    #OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu

  28. New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
    Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
    Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
    🛡️ Detection ideas:
    - Monitor consent grants in Entra ID logs.
    - Restrict unverified app registrations.
    - Disable user app creation.
    - Flag Copilot bots using trial tenants or untrusted domains.

    How are you tuning detections for AI-driven OAuth phishing?
    💬 Share your strategies & follow @technadu for more technical threat intel.

    #OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu

  29. New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
    Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
    Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
    🛡️ Detection ideas:
    - Monitor consent grants in Entra ID logs.
    - Restrict unverified app registrations.
    - Disable user app creation.
    - Flag Copilot bots using trial tenants or untrusted domains.

    How are you tuning detections for AI-driven OAuth phishing?
    💬 Share your strategies & follow @technadu for more technical threat intel.

    #OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu

  30. New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
    Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
    Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
    🛡️ Detection ideas:
    - Monitor consent grants in Entra ID logs.
    - Restrict unverified app registrations.
    - Disable user app creation.
    - Flag Copilot bots using trial tenants or untrusted domains.

    How are you tuning detections for AI-driven OAuth phishing?
    💬 Share your strategies & follow @technadu for more technical threat intel.

    #OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu