home.social

#rapid7 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rapid7, aggregated by home.social.

  1. #Rapid7 published some analysis of #malware likely dropped through the Notepad++ issue.
    One of the loaders used by the malware is built with #Microsoft Warbird, a kernel-level code protection framework used by Windows. @cirosec blogged about how this framework could be abused a while back and also published a PoC on GitHub.
    I'm one of the authors of that research. We included some thoughts on detection in the article but if there's any further questions about the technique or anything, ask away :)

    #notepad #chrysalis #ioc #apt #warbird

  2. #Rapid7 published some analysis of #malware likely dropped through the Notepad++ issue.
    One of the loaders used by the malware is built with #Microsoft Warbird, a kernel-level code protection framework used by Windows. @cirosec blogged about how this framework could be abused a while back and also published a PoC on GitHub.
    I'm one of the authors of that research. We included some thoughts on detection in the article but if there's any further questions about the technique or anything, ask away :)

    #notepad #chrysalis #ioc #apt #warbird

  3. #Rapid7 published some analysis of #malware likely dropped through the Notepad++ issue.
    One of the loaders used by the malware is built with #Microsoft Warbird, a kernel-level code protection framework used by Windows. @cirosec blogged about how this framework could be abused a while back and also published a PoC on GitHub.
    I'm one of the authors of that research. We included some thoughts on detection in the article but if there's any further questions about the technique or anything, ask away :)

    #notepad #chrysalis #ioc #apt #warbird

  4. #Rapid7 published some analysis of #malware likely dropped through the Notepad++ issue.
    One of the loaders used by the malware is built with #Microsoft Warbird, a kernel-level code protection framework used by Windows. @cirosec blogged about how this framework could be abused a while back and also published a PoC on GitHub.
    I'm one of the authors of that research. We included some thoughts on detection in the article but if there's any further questions about the technique or anything, ask away :)

    #notepad #chrysalis #ioc #apt #warbird

  5. #Rapid7 published some analysis of #malware likely dropped through the Notepad++ issue.
    One of the loaders used by the malware is built with #Microsoft Warbird, a kernel-level code protection framework used by Windows. @cirosec blogged about how this framework could be abused a while back and also published a PoC on GitHub.
    I'm one of the authors of that research. We included some thoughts on detection in the article but if there's any further questions about the technique or anything, ask away :)

    #notepad #chrysalis #ioc #apt #warbird

  6. Collecting Linux Ingress Authentication Events using Rapid7 Universal Event Formats

    superuser-ltd.github.io/2019/I

    Continuation of:

    Collecting Windows Ingress Authentication Events using Rapid7 Universal Event Formats

    superuser-ltd.github.io/2019/I

    #infosec #logging #logcollection #siem #rapid7