#mitreattack — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mitreattack, aggregated by home.social.
-
Ищем lateral movement нейросетью, обученной на синтетических данных
Можно ли научить детектор атак, ни разу не показав ему настоящую атаку? Звучит как противоречие. Если хочешь, чтобы нейросеть находила боковое движение, ей вроде бы надо показать боковое движение. Я сделал наоборот: сгенерировал целую корпоративную сеть с её историей входов, устроил в этом выдуманном мире нападение и обучил на нём сети. Ни одной настоящей строки в обучении. Весь мир описан конфигом на 135 строк, каждая сеть весит четыре тысячи параметров и учится за секунды на ноутбуке; лучший результат дали шесть таких сетей, обученных на шести разных выдуманных мирах. Потом я выпустил их на настоящие данные: журналы аутентификации Лос-Аламосской лаборатории, 1.65 миллиарда событий, с размеченными учениями красной команды. И это сработало. Сети выстраивают 3.6 миллиона окон по подозрительности, и в верхних двадцати трёх строках списка стоят шестнадцать настоящих атак и семь ложных тревог: аналитику остаётся открыть эти строки. Пороговому счётчику, чтобы добраться до шестнадцатой атаки на тех же данных, нужно сто шестьдесят одна тысяча ложных тревог. По AUC синтетика вошла в диапазон исследовательских работ, обученных на настоящих размеченных данных, хотя сравнивать их в лоб нельзя, и я объясню почему. Чуда всё равно не случилось. Зато случилось другое: я дважды написал красивый вывод и дважды забрал его назад, когда эксперимент его опроверг. И нашёл петлю, ради которой вообще стоит писать генератор: ошибка детектора показывает конкретную машину, ты понимаешь, какого явления нет в твоём выдуманном мире, дописываешь две строки конфига, и ошибка исчезает.
https://habr.com/ru/articles/1081092/
#боковоедвижение #lateralmovement #синтетическиеданные #генерациятестовыхданных #обнаружениевторжений #журналыаутентификации #LANL #MITREATTACK #LSTM #TDCV2
-
Ищем lateral movement нейросетью, обученной на синтетических данных
Можно ли научить детектор атак, ни разу не показав ему настоящую атаку? Звучит как противоречие. Если хочешь, чтобы нейросеть находила боковое движение, ей вроде бы надо показать боковое движение. Я сделал наоборот: сгенерировал целую корпоративную сеть с её историей входов, устроил в этом выдуманном мире нападение и обучил на нём сети. Ни одной настоящей строки в обучении. Весь мир описан конфигом на 135 строк, каждая сеть весит четыре тысячи параметров и учится за секунды на ноутбуке; лучший результат дали шесть таких сетей, обученных на шести разных выдуманных мирах. Потом я выпустил их на настоящие данные: журналы аутентификации Лос-Аламосской лаборатории, 1.65 миллиарда событий, с размеченными учениями красной команды. И это сработало. Сети выстраивают 3.6 миллиона окон по подозрительности, и в верхних двадцати трёх строках списка стоят шестнадцать настоящих атак и семь ложных тревог: аналитику остаётся открыть эти строки. Пороговому счётчику, чтобы добраться до шестнадцатой атаки на тех же данных, нужно сто шестьдесят одна тысяча ложных тревог. По AUC синтетика вошла в диапазон исследовательских работ, обученных на настоящих размеченных данных, хотя сравнивать их в лоб нельзя, и я объясню почему. Чуда всё равно не случилось. Зато случилось другое: я дважды написал красивый вывод и дважды забрал его назад, когда эксперимент его опроверг. И нашёл петлю, ради которой вообще стоит писать генератор: ошибка детектора показывает конкретную машину, ты понимаешь, какого явления нет в твоём выдуманном мире, дописываешь две строки конфига, и ошибка исчезает.
https://habr.com/ru/articles/1081092/
#боковоедвижение #lateralmovement #синтетическиеданные #генерациятестовыхданных #обнаружениевторжений #журналыаутентификации #LANL #MITREATTACK #LSTM #TDCV2
-
Ищем lateral movement нейросетью, обученной на синтетических данных
Можно ли научить детектор атак, ни разу не показав ему настоящую атаку? Звучит как противоречие. Если хочешь, чтобы нейросеть находила боковое движение, ей вроде бы надо показать боковое движение. Я сделал наоборот: сгенерировал целую корпоративную сеть с её историей входов, устроил в этом выдуманном мире нападение и обучил на нём сети. Ни одной настоящей строки в обучении. Весь мир описан конфигом на 135 строк, каждая сеть весит четыре тысячи параметров и учится за секунды на ноутбуке; лучший результат дали шесть таких сетей, обученных на шести разных выдуманных мирах. Потом я выпустил их на настоящие данные: журналы аутентификации Лос-Аламосской лаборатории, 1.65 миллиарда событий, с размеченными учениями красной команды. И это сработало. Сети выстраивают 3.6 миллиона окон по подозрительности, и в верхних двадцати трёх строках списка стоят шестнадцать настоящих атак и семь ложных тревог: аналитику остаётся открыть эти строки. Пороговому счётчику, чтобы добраться до шестнадцатой атаки на тех же данных, нужно сто шестьдесят одна тысяча ложных тревог. По AUC синтетика вошла в диапазон исследовательских работ, обученных на настоящих размеченных данных, хотя сравнивать их в лоб нельзя, и я объясню почему. Чуда всё равно не случилось. Зато случилось другое: я дважды написал красивый вывод и дважды забрал его назад, когда эксперимент его опроверг. И нашёл петлю, ради которой вообще стоит писать генератор: ошибка детектора показывает конкретную машину, ты понимаешь, какого явления нет в твоём выдуманном мире, дописываешь две строки конфига, и ошибка исчезает.
https://habr.com/ru/articles/1081092/
#боковоедвижение #lateralmovement #синтетическиеданные #генерациятестовыхданных #обнаружениевторжений #журналыаутентификации #LANL #MITREATTACK #LSTM #TDCV2
-
📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs
Live on every vulnerability page of https://vulnerability.circl.lu
Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.
Paper: https://arxiv.org/abs/2607.25572
Code: https://github.com/vulnerability-lookup/VulnTrain#CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama
-
📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs
Live on every vulnerability page of https://vulnerability.circl.lu
Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.
Paper: https://arxiv.org/abs/2607.25572
Code: https://github.com/vulnerability-lookup/VulnTrain#CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama
-
📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs
Live on every vulnerability page of https://vulnerability.circl.lu
Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.
Paper: https://arxiv.org/abs/2607.25572
Code: https://github.com/vulnerability-lookup/VulnTrain#CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama
-
📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs
Live on every vulnerability page of https://vulnerability.circl.lu
Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.
Paper: https://arxiv.org/abs/2607.25572
Code: https://github.com/vulnerability-lookup/VulnTrain#CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama
-
📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs
Live on every vulnerability page of https://vulnerability.circl.lu
Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.
Paper: https://arxiv.org/abs/2607.25572
Code: https://github.com/vulnerability-lookup/VulnTrain#CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama
-
🚀 Vulnerability-Lookup 5.5.0 is out!
🔐 Full Role-Based Access Control replaces the legacy admin flags
🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
🇪🇺 EUVD ID allocation pipeline
🛠️ Feeder supervision, new VEX sources & feeders👉 https://www.vulnerability-lookup.org/2026/07/24/vulnerability-lookup-5-5-0/
#VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK
-
🚀 Vulnerability-Lookup 5.5.0 is out!
🔐 Full Role-Based Access Control replaces the legacy admin flags
🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
🇪🇺 EUVD ID allocation pipeline
🛠️ Feeder supervision, new VEX sources & feeders👉 https://www.vulnerability-lookup.org/2026/07/24/vulnerability-lookup-5-5-0/
#VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK
-
🚀 Vulnerability-Lookup 5.5.0 is out!
🔐 Full Role-Based Access Control replaces the legacy admin flags
🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
🇪🇺 EUVD ID allocation pipeline
🛠️ Feeder supervision, new VEX sources & feeders👉 https://www.vulnerability-lookup.org/2026/07/24/vulnerability-lookup-5-5-0/
#VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK
-
🚀 Vulnerability-Lookup 5.5.0 is out!
🔐 Full Role-Based Access Control replaces the legacy admin flags
🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
🇪🇺 EUVD ID allocation pipeline
🛠️ Feeder supervision, new VEX sources & feeders👉 https://www.vulnerability-lookup.org/2026/07/24/vulnerability-lookup-5-5-0/
#VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK
-
🚀 Vulnerability-Lookup 5.5.0 is out!
🔐 Full Role-Based Access Control replaces the legacy admin flags
🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
🇪🇺 EUVD ID allocation pipeline
🛠️ Feeder supervision, new VEX sources & feeders👉 https://www.vulnerability-lookup.org/2026/07/24/vulnerability-lookup-5-5-0/
#VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK
-
----------------
🎯 AI
===================Sygnia: AI-Supercharged 72-Hour Cloud Attack Investigation
Sygnia published findings from an incident response engagement where a threat actor compromised an AWS-based environment, progressing from initial access to broad cloud compromise in approximately 72 hours. The case is notable not for novel techniques, but for the apparent use of AI to accelerate familiar cloud attack methods.
Key Findings
• The intrusion expanded across applications, cloud infrastructure, source-control systems, CI/CD pipelines, and runtime services
• No zero-day exploits or novel malware were observed. Every technique mapped to established MITRE ATT&CK behaviors
• Multiple artifacts suggested AI-assisted or agentic workflows: attacker-created scripts, structured reporting artifacts, and highly parallel activity
• The threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities
• The primary defensive challenge was the speed and scale of execution, not the novelty of individual techniquesWhere AI Changed the Equation
The report identifies several indicators of AI involvement:
• Rapid generation of environment-specific scripts and tooling
• Structured, formatted reporting artifacts consistent with AI-generated output
• Highly parallel discovery and exploitation activities across multiple surfaces
• Compressed timeline for reconnaissance, adaptation, and operational execution inconsistent with purely manual operationsAttack Path
1. Initial access to AWS environment
2. Credential harvesting and secrets discovery
3. Lateral movement across applications and cloud services
4. Persistence through compromised identity and deployment workflows
5. Expansion into source-control and CI/CD systems
6. Impact across cloud, identity, and application layersEach credential acquisition restarted the cycle.
Defensive Gaps
• Fragmented visibility across cloud, identity, and application layers
• Monitoring gaps that delayed detection and correlation
• Absence of predefined incident response procedures
• Weak secrets management and identity governance
• Overly permissive cloud and CI/CD permissionsRemediation
Sygnia recommends adapting IR playbooks for AI-enabled threats, prioritizing broad containment over precision when speed matters, rotating credentials aggressively, treating identity as the primary security boundary, and automating defensive responses. Infrastructure rebuilds may be necessary for broadly compromised environments.
Known weaknesses get exploited faster and at broader scale when AI assistance is available. End-to-end visibility and predefined containment procedures are prerequisites, not aspirations.
🔹 AI #CloudSecurity #IncidentResponse #Sygnia #MITREATTACK
🔗 Source: https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/
-
📢🔔 Just 1 more day to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more day to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more day to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more day to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more day to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more week to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more week to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more week to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more week to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more week to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 2 more weeks to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 2 more weeks to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 2 more weeks to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 2 more weeks to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
5/5 Lateral Movement Assessment
Using valid administrator credentials, the attacker leveraged remote execution utilities to access additional internal hosts.
Observed Attack Chain:
PHPStudy Exploitation
→ Discovery
→ Payload Deployment
→ C2 Establishment
→ Persistence
→ Credential Access
→ Network Discovery
→ Lateral MovementThis intrusion demonstrates how a single vulnerable web application can rapidly evolve into broader internal compromise.
-
1/5 Threat Activity Analysis
Source: Attack simulation telemetry analysis.
Initial access was achieved through exploitation of a vulnerable PHPStudy deployment. The attacker executed reconnaissance commands to identify the current user context, network configuration, ARP cache, and external connectivity.
Assessment: The activity indicates validation of code execution capabilities prior to payload deployment.
ATT&CK: T1190, T1082, T1016
-
1/5 Threat Activity Analysis
Source: Attack simulation telemetry analysis.
Initial access was achieved through exploitation of a vulnerable PHPStudy deployment. The attacker executed reconnaissance commands to identify the current user context, network configuration, ARP cache, and external connectivity.
Assessment: The activity indicates validation of code execution capabilities prior to payload deployment.
ATT&CK: T1190, T1082, T1016
-
📢🔔 Just 1 more month to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more month to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more month to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more month to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more month to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
Why the MITRE ATT&CK Framework Actually Works: https://levelup.gitconnected.com/why-the-mitre-att-ck-framework-actually-works-29ac26d2d20c
-
Why the MITRE ATT&CK Framework Actually Works: https://levelup.gitconnected.com/why-the-mitre-att-ck-framework-actually-works-29ac26d2d20c
-
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux
-
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux
-
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux
-
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux
-
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux
-
A red-team wiper emulating Sandworm (GRU Unit 74455) has been published - a 90-line Go binary demonstrating LotL execution across 121 MITRE ATT&CK techniques including T1490, T1561.001, and T1070.001.
Full report:
https://www.technadu.com/sandworm-gru-unit-74455-red-team-wiper-released-as-training-sample/614498/Follow @technadu for more threat intel updates.
#Sandworm #GRU74455 #MITREATTACK #RedTeam #BlueTeam #Infosec #WiperMalware
-
A red-team wiper emulating Sandworm (GRU Unit 74455) has been published - a 90-line Go binary demonstrating LotL execution across 121 MITRE ATT&CK techniques including T1490, T1561.001, and T1070.001.
Full report:
https://www.technadu.com/sandworm-gru-unit-74455-red-team-wiper-released-as-training-sample/614498/Follow @technadu for more threat intel updates.
#Sandworm #GRU74455 #MITREATTACK #RedTeam #BlueTeam #Infosec #WiperMalware
-
A red-team wiper emulating Sandworm (GRU Unit 74455) has been published - a 90-line Go binary demonstrating LotL execution across 121 MITRE ATT&CK techniques including T1490, T1561.001, and T1070.001.
Full report:
https://www.technadu.com/sandworm-gru-unit-74455-red-team-wiper-released-as-training-sample/614498/Follow @technadu for more threat intel updates.
#Sandworm #GRU74455 #MITREATTACK #RedTeam #BlueTeam #Infosec #WiperMalware
-
Red and blue teams breaking down their silos and working in real time—imagine a cybersecurity defense that evolves with every simulated threat. Curious how continuous purple teaming is rewriting the playbook?
#purpleteaming
#cyberdefense
#breachandattacksimulation
#mitreattack
#redteam
#blueteam
#securityautomation
#continuousvalidation
#cybersecuritystrategy -
Red and blue teams breaking down their silos and working in real time—imagine a cybersecurity defense that evolves with every simulated threat. Curious how continuous purple teaming is rewriting the playbook?
#purpleteaming
#cyberdefense
#breachandattacksimulation
#mitreattack
#redteam
#blueteam
#securityautomation
#continuousvalidation
#cybersecuritystrategy -
Red and blue teams breaking down their silos and working in real time—imagine a cybersecurity defense that evolves with every simulated threat. Curious how continuous purple teaming is rewriting the playbook?
#purpleteaming
#cyberdefense
#breachandattacksimulation
#mitreattack
#redteam
#blueteam
#securityautomation
#continuousvalidation
#cybersecuritystrategy -
Red and blue teams breaking down their silos and working in real time—imagine a cybersecurity defense that evolves with every simulated threat. Curious how continuous purple teaming is rewriting the playbook?
#purpleteaming
#cyberdefense
#breachandattacksimulation
#mitreattack
#redteam
#blueteam
#securityautomation
#continuousvalidation
#cybersecuritystrategy -
🚀 MITRE ATT&CK v18 = a major leap in detection depth.
The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.
Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.
MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.
💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
Follow @technadu for more #ThreatIntel insights.#CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity
-
🚀 MITRE ATT&CK v18 = a major leap in detection depth.
The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.
Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.
MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.
💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
Follow @technadu for more #ThreatIntel insights.#CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity
-
🚀 MITRE ATT&CK v18 = a major leap in detection depth.
The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.
Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.
MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.
💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
Follow @technadu for more #ThreatIntel insights.#CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity
-
🚀 MITRE ATT&CK v18 = a major leap in detection depth.
The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.
Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.
MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.
💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
Follow @technadu for more #ThreatIntel insights.#CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity
-
🚀 MITRE ATT&CK v18 = a major leap in detection depth.
The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.
Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.
MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.
💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
Follow @technadu for more #ThreatIntel insights.#CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity
-
New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
🛡️ Detection ideas:
- Monitor consent grants in Entra ID logs.
- Restrict unverified app registrations.
- Disable user app creation.
- Flag Copilot bots using trial tenants or untrusted domains.How are you tuning detections for AI-driven OAuth phishing?
💬 Share your strategies & follow @technadu for more technical threat intel.#OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu
-
New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
🛡️ Detection ideas:
- Monitor consent grants in Entra ID logs.
- Restrict unverified app registrations.
- Disable user app creation.
- Flag Copilot bots using trial tenants or untrusted domains.How are you tuning detections for AI-driven OAuth phishing?
💬 Share your strategies & follow @technadu for more technical threat intel.#OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu
-
New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
🛡️ Detection ideas:
- Monitor consent grants in Entra ID logs.
- Restrict unverified app registrations.
- Disable user app creation.
- Flag Copilot bots using trial tenants or untrusted domains.How are you tuning detections for AI-driven OAuth phishing?
💬 Share your strategies & follow @technadu for more technical threat intel.#OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu
-
New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
🛡️ Detection ideas:
- Monitor consent grants in Entra ID logs.
- Restrict unverified app registrations.
- Disable user app creation.
- Flag Copilot bots using trial tenants or untrusted domains.How are you tuning detections for AI-driven OAuth phishing?
💬 Share your strategies & follow @technadu for more technical threat intel.#OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu
-
New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
🛡️ Detection ideas:
- Monitor consent grants in Entra ID logs.
- Restrict unverified app registrations.
- Disable user app creation.
- Flag Copilot bots using trial tenants or untrusted domains.How are you tuning detections for AI-driven OAuth phishing?
💬 Share your strategies & follow @technadu for more technical threat intel.#OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu