home.social

#outofthewoods — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #outofthewoods, aggregated by home.social.

fetched live
  1. Good day everyone!

    I had another great conversation with Scott Poley as we were recording Cyborg Security's #OutoftheWoods #podcast and he brought an interesting article to the table that covered the #Snowflake incident. Authored by Mandiant (part of Google Cloud), the article titled UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion.

    Here are some things we mentioned:
    1. What problem Snowflake solves, which is much more than a database solution but provides a creative way to look at the data you are storing.
    2. Logs are only as useful as you make them: This article provides some great examples of the commands that the attacker issued but if the logs were only stored locally then you run the risk of the adversary clearing tracks. IF you are ingesting these logs proactively you stand a better chance at being able to hunt for and detect on these actions.
    3. Not all attacks involve a heavy reliance on living-off-the-land binaries. I know I mention those alot and those are near and dear to my heart, but the attacker leveraged tools that were exclusive to the Snowflake infrastructure.

    Another great conversation in the books and I look forward to the next one! Enjoy and Happy Hunting!

    UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion
    cloud.google.com/blog/topics/t

    Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #Intel471

  2. Good day everyone!

    I had another great conversation with Scott Poley as we were recording Cyborg Security's #OutoftheWoods #podcast and he brought an interesting article to the table that covered the #Snowflake incident. Authored by Mandiant (part of Google Cloud), the article titled UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion.

    Here are some things we mentioned:
    1. What problem Snowflake solves, which is much more than a database solution but provides a creative way to look at the data you are storing.
    2. Logs are only as useful as you make them: This article provides some great examples of the commands that the attacker issued but if the logs were only stored locally then you run the risk of the adversary clearing tracks. IF you are ingesting these logs proactively you stand a better chance at being able to hunt for and detect on these actions.
    3. Not all attacks involve a heavy reliance on living-off-the-land binaries. I know I mention those alot and those are near and dear to my heart, but the attacker leveraged tools that were exclusive to the Snowflake infrastructure.

    Another great conversation in the books and I look forward to the next one! Enjoy and Happy Hunting!

    UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion
    cloud.google.com/blog/topics/t

    Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #Intel471