home.social

#threathunting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threathunting, aggregated by home.social.

  1. Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.

    The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
    Full breakdown here: graylog.org/post/suricata-ids-
    #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity

  2. CISA Deploys Cyber Decoys to Disrupt Attackers

    CISA is shaking things up in the cybersecurity world with a clever tactic: deploying cyber decoys to lure in and expose attackers, making it easier to detect and respond to threats. By using these low-cost, high-impact decoys, critical infrastructure owners and operators can stay one step ahead of intruders.

    osintsights.com/cisa-deploys-c

    #CyberDecoys #Cisa #EmergingThreats #DetectionAndResponse #ThreatHunting

  3. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  4. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  5. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  6. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  7. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  8. These are IP netblocks that shouldn’t be trusted ❌

    If you’re not automatically ingesting DROP and/or ASN-DROP, now’s the time to fix that:
    👉 spamhaus.org/blocklists/do-not

    Be proactive. Block the worst of the worst IP traffic.

    #ThreatIntel #SOC #ThreatHunting #BGP #NetworkSecurity #BulletproofHosting #Infosec

  9. These are IP netblocks that shouldn’t be trusted ❌

    If you’re not automatically ingesting DROP and/or ASN-DROP, now’s the time to fix that:
    👉 spamhaus.org/blocklists/do-not

    Be proactive. Block the worst of the worst IP traffic.

    #ThreatIntel #SOC #ThreatHunting #BGP #NetworkSecurity #BulletproofHosting #Infosec

  10. These are IP netblocks that shouldn’t be trusted ❌

    If you’re not automatically ingesting DROP and/or ASN-DROP, now’s the time to fix that:
    👉 spamhaus.org/blocklists/do-not

    Be proactive. Block the worst of the worst IP traffic.

    #ThreatIntel #SOC #ThreatHunting #BGP #NetworkSecurity #BulletproofHosting #Infosec

  11. These are IP netblocks that shouldn’t be trusted ❌

    If you’re not automatically ingesting DROP and/or ASN-DROP, now’s the time to fix that:
    👉 spamhaus.org/blocklists/do-not

    Be proactive. Block the worst of the worst IP traffic.

    #ThreatIntel #SOC #ThreatHunting #BGP #NetworkSecurity #BulletproofHosting #Infosec

  12. These are IP netblocks that shouldn’t be trusted ❌

    If you’re not automatically ingesting DROP and/or ASN-DROP, now’s the time to fix that:
    👉 spamhaus.org/blocklists/do-not

    Be proactive. Block the worst of the worst IP traffic.

    #ThreatIntel #SOC #ThreatHunting #BGP #NetworkSecurity #BulletproofHosting #Infosec