home.social

#threathunting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threathunting, aggregated by home.social.

  1. CISA Deploys Cyber Decoys to Disrupt Attackers

    CISA is shaking things up in the cybersecurity world with a clever tactic: deploying cyber decoys to lure in and expose attackers, making it easier to detect and respond to threats. By using these low-cost, high-impact decoys, critical infrastructure owners and operators can stay one step ahead of intruders.

    osintsights.com/cisa-deploys-c

    #CyberDecoys #Cisa #EmergingThreats #DetectionAndResponse #ThreatHunting

  2. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  3. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  4. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  5. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  6. What does Mythic C2 look like across the public Internet?

    Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.

    The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.

    This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: censys.com/blog/mythic-c2/

    #ThreatIntelligence #ThreatHunting #C2 #CensysARC

  7. Your CFO’s phone has been compromised. The alert is only the beginning.

    For incident responders, the next challenge is investigation:

    ✴️ What infrastructure was involved?
    ✴️What was it doing at the time?
    ✴️Are there related IOCs we should go hunt for?

    In this new DFIR walkthrough, Alex Gartner follows two hypothetical mobile incidents, one Android, one iPhone, to show how responders can move from an initial indicator to the broader infrastructure and context needed to understand scope.

    Follow the DFIR journey: censys.com/blog/so-your-cfos-p

    #DFIR #IncidentResponse #SecOps #ThreatHunting #Cybersecurity #Censys

  8. Then it asks what your TARGET is: BSD, Windows, Linux, macOS, Android, container, cloud, down to distro/version. Then you get offered scenarios: do you want to figure out what ran, what got created, where someone poked around, what got exfil'd, pull memory, build a timeline, hunt persistence. Basically branching investigation paths depending on the case. #ThreatHunting #IncidentResponse 🧵

  9. 🛡️ HAVOC C2 — DEFENDER CHEAT SHEET

    Havoc is a powerful Command & Control framework used in authorized red-team operations. 🔴⚡ Understanding how C2 infrastructure, agents and communications behave can also help defenders recognize suspicious activity and improve detection. 🔍

    Learn the framework. Hunt the signals. Strengthen your defenses. 🔐

    💬 Comment “HAVOC” if you want more cybersecurity cheat sheets.

    #HavocC2 #CyberSecurity #RedTeam #BlueTeam #ThreatHunting

  10. # Lunes 15/12 14hs - Seminario “Gathering Threat Intelligence from Encrypted Network Traffic” Prof. Ondřej Ryšavý, Brno University of Technology (BUT), República Checa.

    Tenemos el agrado de invitarlos a la charla que brindará el Prof. Ondřej Ryšavý que nos visita desde la Brno University of Technology (BUT) de la República Checa.

    Esta visita se da en el marco de una cooperación activa entre BUT y el DC/ICC en temas de seguridad informática (aunque no exclusivamente), con lo cual este seminario es también una oportunidad para aquellos investigadores, docentes y alumnos que deseen sumarse a las iniciativas en curso.

    🗓 lunes 15 de diciembre

    🕑 14:00 hs.

    📍 Sala 1606, Pabellón 0+infinito, Ciudad Universitaria, Buenos Aires, Argentina. geo:-34.54396,-58.44038?z=16

    🌐 Idioma: Inglés.

    Título: Gathering Threat Intelligence from Encrypted Network Traffic

    Abstract: Encrypted communication now dominates network environments, reducing the visibility of defenders and demanding new approaches that derive security intelligence without decrypting content. This presentation unifies three complementary research directions into a single, end-to-end framework for threat identification, behavior profiling, and malware attribution.

    First, it introduces a privacy-preserving methodology for latent behavior modeling of TLS traffic. This methodology uses autoencoder-based profiling, extended flow-level metadata, and federated learning for distributed training across sites. The results demonstrate that encrypted traffic can be characterized statistically and semantically without access to the payload, enabling scalable anomaly detection while reducing the risk of data exposure. The second part focuses on threat detection through IoC-driven context enrichment. In this approach, Indicators of Activity (IoAs) extracted from hosts are matched against fuzzy IoC sets derived from malware. This enables family-level correlation, threshold-based scoring, and experimentation in semi-controlled infected environments. Lastly, the presentation explores JA3/JA4+ TLS fingerprinting as a higher-resolution layer for application and malware discrimination. An experimental evaluation using sandbox-generated datasets reveals patterns of uniqueness, coverage, and collisions across multiple malware families and benign applications. This demonstrates how fingerprinting can facilitate attribution and classification in encrypted networks.

    Short Bio:
    Ondřej Ryšavý is an associate professor at Brno University of Technology who specializes in network security monitoring, threat intelligence, and digital forensics. His research focuses on advanced methods for analyzing network telemetry, detecting cyber threats in encrypted traffic, and enhancing forensic readiness in modern infrastructures. He has served as both a principal and co-investigator on numerous international and national research initiatives, contributing to the development of innovative cybersecurity tools, threat hunting methodologies, and privacy-aware analytics

    #FITVUT #FITBUT #VUTBrno #FITVUTBrno #FITBUTBrno #ThreatIntelligence #SeguridadInformática #NetworkIntelligence #NetworkSecurity #cybersecurity #ThreatHunting #UBA #DCUBA #ICCUBA #DCFCENUBA #FCENUBA #ComputaciónUBA #ICCFCENUBA #inteligencia #InteligenciaDeAmenazas #BuenosAires #Argentina #CiudadUniversitariaUBA #CiudadUniversitariaBuenosAires #seminario #charla #cooperaciónInternacional #investigación #CienciasDeLaComputación #ComputerScience

  11. Why Your Security Team Needs Geographic Threat Intelligence Visualization 🗺️
    Traditional security dashboards show you WHAT happened, but not WHERE it's happening or HOW threats are connected geographically. Your SOC analysts are drowning in isolated alerts while missing the bigger picture - attack campaigns that span multiple IPs and locations. This geographic blind spot is costing companies millions in delayed detection and response times.
    🎯 Five Reasons to Use Geographic Threat Intelligence:
    Faster Incident Response - See attack patterns immediately, not after hours of analysis
    Better Resource Allocation - Focus security resources on high-risk geographic areas
    Enhanced Threat Hunting - Spot attack campaigns across multiple IPs and locations
    Improved Prioritization - Group related threats by geography and risk level
    Better Communication - Show executives the threat landscape visually
    Don't let your security team fight blind. Give them the geographic intelligence they need to win the battle against cyber threats.
    #Cybersecurity #ThreatIntelligence #SOC #IncidentResponse #SecurityOperations #CyberDefense #ThreatHunting #SecurityAnalytics #InfoSec #CyberThreats #SecurityTools #DataVisualization #SecurityInnovation #CyberAwareness #SecurityLeadership #RiskManagement #SecurityMonitoring #ThreatDetection #CyberResilience #SecurityStrategy

    chickenpwny.github.io/AzureOrd

  12. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHat USA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're excited to share this transformative Brand Story conversation thanks to our friends at Crogl, Inc. 🙏

    How #AI Can Help Eliminate Alert Fatigue in #Cybersecurity

    Security teams drowning in alerts finally have a lifeline that doesn't compromise their data sovereignty. At #BlackHatUSA 2025, #Crogl CEO monzy merza revealed how they're solving one of cybersecurity's most persistent challenges.

    The harsh reality: Analysts routinely close hundreds of alerts with a single click—not from laziness, but from sheer necessity. As Merza notes, "When you look at the history of #breaches, the signal was there. And somebody ignored it."

    Traditional approaches fail because they expect analysts to become "unicorns"—experts in multiple platforms while remembering complex query languages. Crogl's solution fundamentally reimagines this relationship between human intuition and #machineautomation.

    Key innovations:
    • Semantic knowledge graphs that map relationships across your entire security ecosystem
    • Automated investigations using established kill chain methodologies
    • Natural language processing that converts descriptions into executable security processes
    • Privacy-first architecture that runs air-gapped with no internet dependencies • Response times reduced from weeks to minutes for complex threat hunting

    The result?
    #Analysts focus on strategic #threathunting while AI handles routine investigations—all without moving, duplicating, or exposing your data.

    📺 Watch the video: youtu.be/0GqPtPXD2ik

    🎧 Listen to the podcast: brand-stories-podcast.simpleca

    📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about Crogl: itspm.ag/crogl-103909
    ✦ Catch more stories from Crogl: itspmagazine.com/directory/cro

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #AIinSecurity #AlertFatigue #ThreatHunting #BlackHatUSA #BHUSA25 #SecurityAutomation #DataPrivacy #SOC #SecurityAnalytics

  13. A rich #training #offer at BSides Milano we have top-notch trainings, in some case for the first time in #Italy! All #in-person! The #event will be held from 4 to 8 July 2023. From 4 to 7 we will be focus on #learnitall on the 8 we will deep dive in our #amazing #conference. Ticket will be available from tonight for the trainings. We have an early bird rate until 30th April.
    Are you ready? We are!! join our group SecurityBsidesItalia #linkedin or on #discord lnkd.in/dBu7wkJG for detailed info! #cyber #threatintelligence #threatintel #cloud #redteaming #redteam #blueteam #threathunting #exploitation #secureboot #TTE #multicloud #hybridcloud #voip #Linux #Windows #LTE #baseband #deception #detection #evasion #edr #BSML23 #AWS #Azure #AzureAD #GCP #devops #cicd #RTOS #FalseFlag #HoneyNet #IDAPro #Python #reverseengineering #Ghidra #network #MITRE #TTPs #persistence #commandandcontrol #lateralmovement #osint #obfuscation #malware #malwareanalysis .
    Reserve your your spot!! lnkd.in/dZf-yyPv