#soc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #soc, aggregated by home.social.
-
2026-08-14 RDP #Honeypot IOCs - 2343 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
178.128.32.226 - 1161
45.137.17.18 - 480
155.117.13.211 - 336Top ASNs:
AS14061 - 1161
AS214570 - 480
AS16276 - 336Top Accounts:
hello - 2253
Administr - 33
Test - 18Top ISPs:
DigitalOcean, LLC - 1161
PISHGAM1 - 480
OVH SAS - 336Top Clients:
Unknown - 2343Top Software:
Unknown - 2343Top Keyboards:
Unknown - 2343Top IP Classification:
hosting & proxy - 1290
Unknown - 828
hosting - 213Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-14 RDP #Honeypot IOCs - 1562 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
178.128.32.226 - 774
45.137.17.18 - 320
155.117.13.211 - 224Top ASNs:
AS14061 - 774
AS214570 - 320
AS16276 - 224Top Accounts:
hello - 1502
Administr - 22
Test - 12Top ISPs:
DigitalOcean, LLC - 774
PISHGAM1 - 320
OVH SAS - 224Top Clients:
Unknown - 1562Top Software:
Unknown - 1562Top Keyboards:
Unknown - 1562Top IP Classification:
hosting & proxy - 860
Unknown - 552
hosting - 142Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-14 RDP #Honeypot IOCs - 781 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
178.128.32.226 - 387
45.137.17.18 - 160
155.117.13.211 - 112Top ASNs:
AS14061 - 387
AS214570 - 160
AS16276 - 112Top Accounts:
hello - 751
Administr - 11
Test - 6Top ISPs:
DigitalOcean, LLC - 387
PISHGAM1 - 160
OVH SAS - 112Top Clients:
Unknown - 781Top Software:
Unknown - 781Top Keyboards:
Unknown - 781Top IP Classification:
hosting & proxy - 430
Unknown - 276
hosting - 71Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-13 RDP #Honeypot IOCs - 10335 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 7467
178.128.32.226 - 1044
155.117.13.211 - 888Top ASNs:
AS24940 - 7467
AS14061 - 1044
AS16276 - 888Top Accounts:
hello - 10242
Test - 24
Administr - 12Top ISPs:
Hetzner Online GmbH - 7467
DigitalOcean, LLC - 1044
OVH SAS - 888Top Clients:
Unknown - 10335Top Software:
Unknown - 10335Top Keyboards:
Unknown - 10335Top IP Classification:
hosting - 8307
hosting & proxy - 1110
Unknown - 903Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-13 RDP #Honeypot IOCs - 6890 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 4978
178.128.32.226 - 696
155.117.13.211 - 592Top ASNs:
AS24940 - 4978
AS14061 - 696
AS16276 - 592Top Accounts:
hello - 6828
Test - 16
Administr - 8Top ISPs:
Hetzner Online GmbH - 4978
DigitalOcean, LLC - 696
OVH SAS - 592Top Clients:
Unknown - 6890Top Software:
Unknown - 6890Top Keyboards:
Unknown - 6890Top IP Classification:
hosting - 5538
hosting & proxy - 740
Unknown - 602Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-13 RDP #Honeypot IOCs - 3445 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 2489
178.128.32.226 - 348
155.117.13.211 - 296Top ASNs:
AS24940 - 2489
AS14061 - 348
AS16276 - 296Top Accounts:
hello - 3414
Test - 8
Administr - 4Top ISPs:
Hetzner Online GmbH - 2489
DigitalOcean, LLC - 348
OVH SAS - 296Top Clients:
Unknown - 3445Top Software:
Unknown - 3445Top Keyboards:
Unknown - 3445Top IP Classification:
hosting - 2769
hosting & proxy - 370
Unknown - 301Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-12 RDP #Honeypot IOCs - 3636 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 2847
155.117.13.211 - 390
103.178.235.50 - 150Top ASNs:
AS24940 - 2847
AS16276 - 390
AS140810 - 150Top Accounts:
hello - 3516
Domain - 27
Test - 18Top ISPs:
Hetzner Online GmbH - 2847
OVH SAS - 390
VPSTTT - 150Top Clients:
Unknown - 3636Top Software:
Unknown - 3636Top Keyboards:
Unknown - 3636Top IP Classification:
hosting - 3072
Unknown - 393
hosting & proxy - 153Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-12 RDP #Honeypot IOCs - 2424 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 1898
155.117.13.211 - 260
103.178.235.50 - 100Top ASNs:
AS24940 - 1898
AS16276 - 260
AS140810 - 100Top Accounts:
hello - 2344
Domain - 18
Test - 12Top ISPs:
Hetzner Online GmbH - 1898
OVH SAS - 260
VPSTTT - 100Top Clients:
Unknown - 2424Top Software:
Unknown - 2424Top Keyboards:
Unknown - 2424Top IP Classification:
hosting - 2048
Unknown - 262
hosting & proxy - 102Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-12 RDP #Honeypot IOCs - 1212 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 949
155.117.13.211 - 130
103.178.235.50 - 50Top ASNs:
AS24940 - 949
AS16276 - 130
AS140810 - 50Top Accounts:
hello - 1172
Domain - 9
Test - 6Top ISPs:
Hetzner Online GmbH - 949
OVH SAS - 130
VPSTTT - 50Top Clients:
Unknown - 1212Top Software:
Unknown - 1212Top Keyboards:
Unknown - 1212Top IP Classification:
hosting - 1024
Unknown - 131
hosting & proxy - 51Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Three attacks this week didn't break the network trust signals a SOC leans on. They just hid inside them.
A 633-server proxy network (CanOworms) so a state actor and a card fraudster leave through the same clean IP. Midnight Blizzard on hotel Wi-Fi captive portals serving a fake M365 login. And a PoC running code on Cloudflare's own edge.
The address tells you where traffic sits, not who's driving it.
-
Three attacks this week didn't break the network trust signals a SOC leans on. They just hid inside them.
A 633-server proxy network (CanOworms) so a state actor and a card fraudster leave through the same clean IP. Midnight Blizzard on hotel Wi-Fi captive portals serving a fake M365 login. And a PoC running code on Cloudflare's own edge.
The address tells you where traffic sits, not who's driving it.
-
2026-08-11 RDP #Honeypot IOCs - 1338 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 822
178.128.32.226 - 330
157.66.48.32 - 60Top ASNs:
AS16276 - 822
AS14061 - 360
AS150895 - 60Top Accounts:
hello - 1260
Test - 18
Administr - 9Top ISPs:
OVH SAS - 822
DigitalOcean, LLC - 360
VPSPA - 60Top Clients:
Unknown - 1338Top Software:
Unknown - 1338Top Keyboards:
Unknown - 1338Top IP Classification:
Unknown - 834
hosting & proxy - 336
hosting - 156Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-11 RDP #Honeypot IOCs - 892 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 548
178.128.32.226 - 220
157.66.48.32 - 40Top ASNs:
AS16276 - 548
AS14061 - 240
AS150895 - 40Top Accounts:
hello - 840
Test - 12
Administr - 6Top ISPs:
OVH SAS - 548
DigitalOcean, LLC - 240
VPSPA - 40Top Clients:
Unknown - 892Top Software:
Unknown - 892Top Keyboards:
Unknown - 892Top IP Classification:
Unknown - 556
hosting & proxy - 224
hosting - 104Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-11 RDP #Honeypot IOCs - 446 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 274
178.128.32.226 - 110
157.66.48.32 - 20Top ASNs:
AS16276 - 274
AS14061 - 120
AS150895 - 20Top Accounts:
hello - 420
Test - 6
Administr - 3Top ISPs:
OVH SAS - 274
DigitalOcean, LLC - 120
VPSPA - 20Top Clients:
Unknown - 446Top Software:
Unknown - 446Top Keyboards:
Unknown - 446Top IP Classification:
Unknown - 278
hosting & proxy - 112
hosting - 52Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Investigation Scenario 🔎
You received an alert that one of your honeydocs was opened on a network other than your own.
What do you look for to investigate whether an attacker exfiltrated this file from your network?
-
Investigation Scenario 🔎
You received an alert that one of your honeydocs was opened on a network other than your own.
What do you look for to investigate whether an attacker exfiltrated this file from your network?
-
2026-08-10 RDP #Honeypot IOCs - 3084 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 1098
206.189.58.63 - 825
134.199.148.184 - 591Top ASNs:
AS14061 - 1908
AS16276 - 1098
AS396982 - 36Top Accounts:
hello - 3015
Test - 12
Domain - 9Top ISPs:
DigitalOcean, LLC - 1908
OVH SAS - 1098
Google LLC - 36Top Clients:
Unknown - 3084Top Software:
Unknown - 3084Top Keyboards:
Unknown - 3084Top IP Classification:
hosting - 1533
Unknown - 1101
hosting & proxy - 444Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-10 RDP #Honeypot IOCs - 2056 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 732
206.189.58.63 - 550
134.199.148.184 - 394Top ASNs:
AS14061 - 1272
AS16276 - 732
AS396982 - 24Top Accounts:
hello - 2010
Test - 8
Domain - 6Top ISPs:
DigitalOcean, LLC - 1272
OVH SAS - 732
Google LLC - 24Top Clients:
Unknown - 2056Top Software:
Unknown - 2056Top Keyboards:
Unknown - 2056Top IP Classification:
hosting - 1022
Unknown - 734
hosting & proxy - 296Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-10 RDP #Honeypot IOCs - 1028 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 366
206.189.58.63 - 275
134.199.148.184 - 197Top ASNs:
AS14061 - 636
AS16276 - 366
AS396982 - 12Top Accounts:
hello - 1005
Test - 4
Domain - 3Top ISPs:
DigitalOcean, LLC - 636
OVH SAS - 366
Google LLC - 12Top Clients:
Unknown - 1028Top Software:
Unknown - 1028Top Keyboards:
Unknown - 1028Top IP Classification:
hosting - 511
Unknown - 367
hosting & proxy - 148Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-09 RDP #Honeypot IOCs - 4638 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
206.189.58.63 - 2286
134.199.148.184 - 1020
155.117.13.211 - 621Top ASNs:
AS14061 - 3381
AS16276 - 621
AS8075 - 510Top Accounts:
hello - 4530
Administr - 15
eltons - 15Top ISPs:
DigitalOcean, LLC - 3381
OVH SAS - 621
Microsoft Corporation - 510Top Clients:
Unknown - 4638Top Software:
Unknown - 4638Top Keyboards:
Unknown - 4638Top IP Classification:
hosting - 3939
Unknown - 684
hosting & proxy - 15Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-09 RDP #Honeypot IOCs - 3092 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
206.189.58.63 - 1524
134.199.148.184 - 680
155.117.13.211 - 414Top ASNs:
AS14061 - 2254
AS16276 - 414
AS8075 - 340Top Accounts:
hello - 3020
Administr - 10
eltons - 10Top ISPs:
DigitalOcean, LLC - 2254
OVH SAS - 414
Microsoft Corporation - 340Top Clients:
Unknown - 3092Top Software:
Unknown - 3092Top Keyboards:
Unknown - 3092Top IP Classification:
hosting - 2626
Unknown - 456
hosting & proxy - 10Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-09 RDP #Honeypot IOCs - 1546 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
206.189.58.63 - 762
134.199.148.184 - 340
155.117.13.211 - 207Top ASNs:
AS14061 - 1127
AS16276 - 207
AS8075 - 170Top Accounts:
hello - 1510
Administr - 5
eltons - 5Top ISPs:
DigitalOcean, LLC - 1127
OVH SAS - 207
Microsoft Corporation - 170Top Clients:
Unknown - 1546Top Software:
Unknown - 1546Top Keyboards:
Unknown - 1546Top IP Classification:
hosting - 1313
Unknown - 228
hosting & proxy - 5Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-08 RDP #Honeypot IOCs - 2091 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 726
170.64.227.228 - 642
206.189.58.63 - 564Top ASNs:
AS14061 - 1236
AS16276 - 726
AS396982 - 30Top Accounts:
hello - 2007
Domain - 18
zgrab - 6Top ISPs:
DigitalOcean, LLC - 1236
OVH SAS - 726
Google LLC - 30Top Clients:
Unknown - 2091Top Software:
Unknown - 2091Top Keyboards:
Unknown - 2091Top IP Classification:
hosting - 1320
Unknown - 765
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-08 RDP #Honeypot IOCs - 1394 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 484
170.64.227.228 - 428
206.189.58.63 - 376Top ASNs:
AS14061 - 824
AS16276 - 484
AS396982 - 20Top Accounts:
hello - 1338
Domain - 12
zgrab - 4Top ISPs:
DigitalOcean, LLC - 824
OVH SAS - 484
Google LLC - 20Top Clients:
Unknown - 1394Top Software:
Unknown - 1394Top Keyboards:
Unknown - 1394Top IP Classification:
hosting - 880
Unknown - 510
proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-08 RDP #Honeypot IOCs - 697 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 242
170.64.227.228 - 214
206.189.58.63 - 188Top ASNs:
AS14061 - 412
AS16276 - 242
AS396982 - 10Top Accounts:
hello - 669
Domain - 6
zgrab - 2Top ISPs:
DigitalOcean, LLC - 412
OVH SAS - 242
Google LLC - 10Top Clients:
Unknown - 697Top Software:
Unknown - 697Top Keyboards:
Unknown - 697Top IP Classification:
hosting - 440
Unknown - 255
proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
AI is not your biggest cyber threat.
Your shitty patching process probably is.
A slightly sarcastic take on AI hype, CISOs, security theatre, broken processes, legacy IT, SOC reality and why automation changes the speed of attacks more than the nature of the problem.
https://0ut3r.space/2026/08/08/ai-is-not-your-biggest-cyber-threat/
#cybersecurity #infosec #AI #CISO #BlueTeam #RedTeam #SOC #SecurityEngineering
-
AI is not your biggest cyber threat.
Your shitty patching process probably is.
A slightly sarcastic take on AI hype, CISOs, security theatre, broken processes, legacy IT, SOC reality and why automation changes the speed of attacks more than the nature of the problem.
https://0ut3r.space/2026/08/08/ai-is-not-your-biggest-cyber-threat/
#cybersecurity #infosec #AI #CISO #BlueTeam #RedTeam #SOC #SecurityEngineering
-
2026-08-07 RDP #Honeypot IOCs - 537 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
170.64.227.228 - 240
155.117.13.211 - 138
134.199.168.195 - 60Top ASNs:
AS14061 - 300
AS16276 - 138
AS396982 - 36Top Accounts:
hello - 450
Domain - 18
Test - 18Top ISPs:
DigitalOcean, LLC - 300
OVH SAS - 138
Google LLC - 36Top Clients:
Unknown - 537Top Software:
Unknown - 537Top Keyboards:
Unknown - 537Top IP Classification:
hosting - 372
Unknown - 138
hosting & proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-07 RDP #Honeypot IOCs - 358 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
170.64.227.228 - 160
155.117.13.211 - 92
134.199.168.195 - 40Top ASNs:
AS14061 - 200
AS16276 - 92
AS396982 - 24Top Accounts:
hello - 300
Domain - 12
Test - 12Top ISPs:
DigitalOcean, LLC - 200
OVH SAS - 92
Google LLC - 24Top Clients:
Unknown - 358Top Software:
Unknown - 358Top Keyboards:
Unknown - 358Top IP Classification:
hosting - 248
Unknown - 92
hosting & proxy - 8Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-07 RDP #Honeypot IOCs - 179 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
170.64.227.228 - 80
155.117.13.211 - 46
134.199.168.195 - 20Top ASNs:
AS14061 - 100
AS16276 - 46
AS396982 - 12Top Accounts:
hello - 150
Domain - 6
Test - 6Top ISPs:
DigitalOcean, LLC - 100
OVH SAS - 46
Google LLC - 12Top Clients:
Unknown - 179Top Software:
Unknown - 179Top Keyboards:
Unknown - 179Top IP Classification:
hosting - 124
Unknown - 46
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-06 RDP #Honeypot IOCs - 6621 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
27.71.229.97 - 5592
155.117.13.211 - 618
64.23.178.90 - 225Top ASNs:
AS38731 - 5592
AS16276 - 618
AS14061 - 318Top Accounts:
hello - 6528
Test - 18
mrrsdwhn - 12Top ISPs:
VIETTEL - 5592
OVH SAS - 618
DigitalOcean, LLC - 318Top Clients:
Unknown - 6621Top Software:
Unknown - 6621Top Keyboards:
Unknown - 6621Top IP Classification:
Unknown - 6213
hosting & proxy - 228
hosting - 162Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Recommendations on Naming Threat Actors.
The MISP standard has been updated including the new tracking of naming origin from security vendor.
#cti #threatintelligence #soc #cybersecurity #threatintel
🔗 https://www.misp-standard.org/rfc/threat-actor-naming.html#name-misp-galaxy-threat-actor-na
-
🖥️ Do you really need a web portal for incident response?
@[email protected] demonstrates how a #PowerShell-based terminal UI can manage Microsoft Defender incidents, investigate alerts, and automate security workflows.
👉 youtu.be/CTUDgmjFleQ?si=cbM...
#CyberSecurity #PSConfEU #SOC
- YouTube -
2026-08-05 RDP #Honeypot IOCs - 29778 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
27.71.229.97 - 29670
134.199.168.195 - 30
45.142.193.18 - 12Top ASNs:
AS38731 - 29670
AS14061 - 30
AS396982 - 27Top Accounts:
hello - 29712
Test - 18
Domain - 9Top ISPs:
VIETTEL - 29670
DigitalOcean, LLC - 30
Google LLC - 27Top Clients:
Unknown - 29778Top Software:
Unknown - 29778Top Keyboards:
Unknown - 29778Top IP Classification:
Unknown - 29679
hosting - 78
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Одна страничка для ответа на вопросы про FPGA и рассыпуху на городских ярмарках
На всяких народных гуляниях типа MakerFaire и OpenSauce меня постоянно спрашивают при виде FPGA “Это Ардуино / Raspberry Pi?” Причем когда я отвечаю “нет”, у людей появляется выражение лица будто я им нагрубил. Я раньше не понимал, с чем это связано, но теперь думаю, что цель такого вопроса - просто показать свою эрудицию, а я эту цель обламываю. Кроме этого минимум у одной дамы было такое выражение лица, что она наверное подумала, что я сумасшедший. Теперь при использований микросхем малой степени интеграции появляется второй вопрос “разве все эти микросхемы не устарели и не были заменены Ардуино?” Короче для Technology Showcase в Mountain View в этот четверг я решил сделать вот такую одну страничку и просто молча давать ее людям, которые задают эти два вопроса. Первая сторона:
https://habr.com/ru/articles/1064600/
#FPGA #городские_ярмарки #Maker_Faire #CMOS_4000 #Arduino #raspberri_pi #open_sauce #Technology_Showcase #ASIC #SoC
-
SOC incident analysis. Letsdefend, SOC342 ‑ CVE‑2025‑53770 SharePoint ToolShell Auth Bypass and RCE
В этой статье я покажу пошаговое руководство для решения практического задания для SOC с Letsdefend — SOC342 CVE‑2025‑53770 SharePoint ToolShell Auth Bypass and RCE. Само задание представляет собой расследование эксплуатации критической уязвимости, наша задача понять как началась атака, что делал злоумышленник и какие индикаторы компрометации есть.
-
Investigation Scenario 🔎
While reviewing Amcache.hve, you notice C:\Users\Public\Libraries\SyncHost.exe executed once, but no corresponding Prefetch file exists despite Prefetch being enabled. The file is not present at that location.
What do you look for to investigate whether an incident occurred?
Bonus Exercise: List several of the potential explanations for this behavior
-
"AI traffic" in your logs isn't one thing to allow or block. It's four, and they don't share a risk profile:
- first-party vendor APIs (api.openai.com): near-certainly legit
- model hosting (Hugging Face, Replicate): runs strangers' code, treat like cloud
- GPU clouds (CoreWeave, Lambda): rentable boxes
- crawlers (GPTBot, ClaudeBot): verify against the vendor's published IP feed, not the user-agentA taxonomy any analyst can use:
https://www.reput.io/blog/classifying-ai-infrastructure -
Архитектурный паттерн «LangGraph, гибридный RAG + Сигнатурный движок»: универсальный граф для потоковых данных
Мы попытались автоматизировать первую линию SOC . Захотелось объединить гибкость ЛЛМ и надежность сигнатурных движков. Поместилось все это в один асинхронный граф. Под капотом гибридный RAG (Vector + BM25), zero‑cost фича для экономии токенов и параллельный сигнатурный анализ. Статья об архитектуре , а не готовом решении. Мы тестировали пайплайн на логах кибербезопасности, но концепция получилась модульной и универсальной. Логи лишь выступают как пример для демонстрации. Представленный граф можно адаптировать под разбор отзывов, фильтрацию спама или модерацию внутренних документов компании.
https://habr.com/ru/articles/1063584/
#python #langgraph #aiагенты #analysis #pipeline #llm #rag #cybersecurity #soc #паттерн
-
Локальный запуск LLM для SOC: сколько инцидентов обработает одна GPU? Часть 2
Всем привет! На связи Сергей Иванов, аналитик технологий машинного обучения R‑Vision. В первой части эксперимента мы выяснили, как на производительность локальной LLM влияют длина контекста, количество параллельных запросов и объем генерируемого ответа. Стресс‑тесты позволили определить границы конфигурации Qwen3.5–122B‑A10B‑GPTQ, vLLM и NVIDIA RTX PRO 6000 Blackwell Max‑Q с 96 GB видеопамяти. Однако предельная конкурентность и скорость генерации сами по себе еще не показывают, насколько такая конфигурация подходит для реального SOC. В промышленном сценарии запросы поступают не равномерно и не изолированно. Они создаются карточками инцидентов, шагами ИИ‑оркестратора и действиями аналитиков, а порядок их выполнения определяется логикой расследования. Во второй части эксперимента мы перешли от лабораторных измерений к моделированию реальной работы SOC. Мы оценили, как GPU справляется с инференсом LLM при разной численности команды и интенсивности потока инцидентов — от спокойной смены до пиковых ситуаций с массовым поступлением новых инцидентов. Важно отметить, что в эксперименте использовались не специально подготовленные тестовые примеры, а анонимизированные реальные инциденты из практики нашего внутреннего SOC. Отдельно остановимся на режиме рассуждений. В сценарии интеграции LLM в конвейер R‑Vision SOAR мы сознательно использовали модель с отключенным thinking mode (режимом рассуждений). Ниже на результатах реальных экспериментов покажем, почему именно такой режим оказался наиболее эффективным для задач SOC.
https://habr.com/ru/companies/rvision/articles/1063478/
#llm #soc #gpu #автоматизация_SOC #nvidia_rtx_pro_6000_blackwell #vllm #qwen35 #AI_в_SOC #инференс_llm #selfhosted_llm
-
So I'm looking at a bad board out of (I think) a 4-burner electric cooktop. The date on the board is 2014. And this thing has a 32-bit, 50 MHz SOC with so many features and I/O channels and everything else that it's practically criminal. It can't have but 4 burner control knobs as input, and I doubt there was any kind of pixel-mapped display in it.
It's even the absolute top part number in this MCU's range.
This thing could emulate any 16-bit system you could name with half its transistors tied behind its back, and here it is serving as a glorified 4-channel PID controller.
-
2026-07-22 RDP #Honeypot IOCs - 236 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
51.77.190.75 - 199
31.70.99.149 - 5
45.142.193.145 - 4Top ASNs:
AS16276 - 199
AS396982 - 12
AS63949 - 6Top Accounts:
hello - 207
Test - 4
07va67qh - 4Top ISPs:
OVH SAS - 199
Google LLC - 12
IONOS SE - 5Top Clients:
Unknown - 236Top Software:
Unknown - 236Top Keyboards:
Unknown - 236Top IP Classification:
hosting - 225
Unknown - 6
hosting & proxy - 5Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
MaxPatrol 360: первый взгляд на операционную платформу управления работой SOC
В рамках партнерского взаимодействия с Positive Technologies мы протестировали платформу MaxPatrol 360, и в этой статье расскажем о ее возможностях и особенностях применения в процессах SOC. Еще одна платформа для SOC? Современные центры мониторинга кибербезопасности работают в условиях высокой насыщенности инструментами: SIEM (Security Information and Event Management) собирает события ИБ и выявляет из всего потока подозрения на инциденты; EDR (Endpoint Detection and Response) ловит сложные атаки на конечных точках; NTA (Network Traffic Analysis) анализирует сетевой трафик, а отдельные классы решений помогают с инвентаризацией активов и управлением уязвимостями. При расследовании инцидентов аналитики многих SOC по‑прежнему вынуждены переключаться между несколькими консолями, вручную поддерживать единообразие экспертизы и синхронизировать процессы через почту и мессенджеры. В холдингах и корпорациях с географически распределенной инфраструктурой возникают дополнительные сложности: часть информации теряется, подходы к детектированию и реагированию начинают различаться от филиала к филиалу, от сети к сети, от контура к контуру, за которыми следит SOC. Продукт Positive Technologies MaxPatrol 360 появился как ответ на этот разрыв между набором инструментов и цельной операционной картиной. Он решает задачи централизованного управления расследованиями, запуска защитных мер, управления экспертизой и не только. Обо всем по порядку.
https://habr.com/ru/companies/innostage/articles/1061782/
#MaxPatrol_360 #soc #positive_technologies #irp #soar #maxpatrol_siem
-
𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺?
https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
-
🍏🔍 Oh, the #excitement of Apple's #SOC 3 #audit reports, where you get to read about #security #certifications without actually learning anything new. It's like being invited to a party where the only entertainment is watching paint dry on a wall, all while being smothered with Apple's favorite #buzzwords. 🎉📄
https://support.apple.com/guide/certifications/apple-private-cloud-compute-soc-3-audit-apc95a31b9d8/web #Apple #tech #news #HackerNews #ngated -
Investigation Scenario 🔎
Alert: Microsoft Defender for Endpoint: Behavior:Win32/SuspClickFix.F detected on a Windows 11 workstation.
No additional context is provided. What artifacts would you examine first to determine whether the user executed the ClickFix command?
To go further, what would you look for to determine whether the alert represents the beginning of an ACR Stealer intrusion?
-
Расширенный аудит Windows. Или с чего начать расследование инцидентов?
Когда я начал разбираться в SOC (Security Operations Center), то довольно быстро понял, что стандартная Windows не дает особого понимания, что вообще внутри нее происходит. События входа, создание процессов, изменение политик – все это просто не пишется либо пишется в достаточно урезанном виде. Здесь я хотел бы показать (конечно, частично), каким вообще образом настроить аудит безопасности Windows 10/11 так, чтобы получить вполне читаемые и полезные события, которые можно будет использовать для расследования инцидентов ИБ. Разберемся, что и зачем мы включаем, что такое Event ID и как потом выглядят события на реальной практике. Все действия будут выполняться на ВМ, дабы не затрагивать хост.
https://habr.com/ru/articles/1061400/
#аудит #аудит_безопасности #информационная_безопасность #системное_администрирование #soc #Windows_аудит #логирование #auditpol #event_id #журнал_безопасности
-
От JTAG к IJTAG: зачем понадобился новый стандарт аппаратного тестирования
Приветствую! На связи Антон Осетров, DFT-разработчик SoC в компании YADRO. В этой статье я хочу рассказать о вызовах в тестировании SoC, о том, как они изменялись со временем и как с этим связан переход от аппаратного интерфейса JTAG к IJTAG.
https://habr.com/ru/companies/yadro/articles/1059778/
#jtag #ijtag #design_for_testability #dft #ieee1500 #снк #soc
-
PQC migration creates ongoing SOC requirements: algorithm downgrade monitoring, vendor PQC readiness tracking, crypto inventory maintenance, quantum-specific threat intel feeds, incident response for mixed classical/PQ environments.
The operational playbook for SOC teams told "prepare for quantum":
https://postquantum.com/post-quantum/soc-quantum-security-pqc-operations/
-
Локальный запуск LLM для SOC: сколько GPU действительно нужно?
Всем привет! На связи Сергей Иванов, аналитик технологий машинного обучения R-Vision. В этой статье разберем, почему для задач SOC можно начинать с одной профессиональной GPU, какие сценарии уже доступны на такой конфигурации и где проходят реальные пределы ее производительности. Материал будет полезен ML-инженерам, работающим с LLM, а также CISO и SOC-командам, которые оценивают применение генеративного ИИ в задачах кибербезопасности.
https://habr.com/ru/companies/rvision/articles/1060184/
#llmмодели #локальный_запуск_llm #vllm #qwen #gpu #NVIDIA_RTX_PRO_6000_Blackwell #soc #soar #ai_в_кибербезопасности