home.social

#thrunting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #thrunting, aggregated by home.social.

fetched live
  1. Oh, and for those that didn't know, the good side lost the battle against the unironic use of the term #thrunting . It appears it's here to stay.

  2. Oh, and for those that didn't know, the good side lost the battle against the unironic use of the term #thrunting . It appears it's here to stay.

  3. Oh, and for those that didn't know, the good side lost the battle against the unironic use of the term #thrunting . It appears it's here to stay.

  4. Just downloaded and about to start playing around with a cloud security tool.

    In my opinion there is no better way to threat hunt that to emulate adversarial activity, note all indicators using whatever tools are available, and then begin forming hypothesis about how to use these indicators and start developing leads.

    Also a hot take, I'm immediately suspicious of any Blue Teamer who claims to not enjoy playing with Red Team tools. If this doesn't bring even a bit of joy, why even work in security.

    github.com/NetSPI/aws_consoler

    #cybersecurity #threathunting #thrunting

  5. Just downloaded and about to start playing around with a cloud security tool.

    In my opinion there is no better way to threat hunt that to emulate adversarial activity, note all indicators using whatever tools are available, and then begin forming hypothesis about how to use these indicators and start developing leads.

    Also a hot take, I'm immediately suspicious of any Blue Teamer who claims to not enjoy playing with Red Team tools. If this doesn't bring even a bit of joy, why even work in security.

    github.com/NetSPI/aws_consoler

    #cybersecurity #threathunting #thrunting

  6. Check out! New sharing community for Threat Hunters, from some amazing people I greatly respect @letswastetime and @Jotunvillur

    HEARTH (Hunting Exchange And Research Threat Hub)!

    Hey thrunters! A new open-source home to:
    - Share hunt ideas
    - Learn from others
    - Level up together

    Built by hunters, for hunters 🎯
    threathuntingcommunity.com

    #threathunting #thrunting #infosec #HEARTH

  7. Check out! New sharing community for Threat Hunters, from some amazing people I greatly respect @letswastetime and @Jotunvillur

    HEARTH (Hunting Exchange And Research Threat Hub)!

    Hey thrunters! A new open-source home to:
    - Share hunt ideas
    - Learn from others
    - Level up together

    Built by hunters, for hunters 🎯
    threathuntingcommunity.com

    #threathunting #thrunting #infosec #HEARTH

  8. A co-worker of mine the other day referred to Threat Hunting as Thrunting, and now I want to make Thrunting an actual cyber security term so very badly.

    #cyber #cybersecurity #threathunting #thrunting

  9. A co-worker of mine the other day referred to Threat Hunting as Thrunting, and now I want to make Thrunting an actual cyber security term so very badly.

    #cyber #cybersecurity #threathunting #thrunting

  10. A co-worker of mine the other day referred to Threat Hunting as Thrunting, and now I want to make Thrunting an actual cyber security term so very badly.

    #cyber #cybersecurity #threathunting #thrunting

  11. IntelOwl an Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API. It integrates a number of analyzers available online and a lot of cutting-edge malware analysis tools.

    github.com/intelowlproject/Int

    #threathunting #threatintel #thrunting #opensourceTI

  12. I totally forgot about this place!! But hey maybe I should be involved again.

    To my #CTI #SOC folks out there, what do you do with the massive scanning IP threat feeds? Are you ingesting them into SIEM for alerting?

    If you are ingesting bot IPs and scanning IPs, what confidence and severity level do you set your threshold to ingest high fidelity indicators?

    I want to know what everyone’s thoughts and strategies are on ingesting low-yield indicators.

    #threatintel
    #ioc
    #soc
    #threathunting
    #thrunting

  13. It is Thrunting Thursday - what are you looking for today?

    I'll be looking for .lnk files that spawn processes with a child or grandchild process that is cmd or powershell - especially originating from non C:\ drives

    #thrunting #threathunting #blueteam #detection

  14. Kudos to virustotal for the cheatsheet they dropped today (blog.virustotal.com/2022/12/vt). They already had their various search modifiers documented, but this gives a dense set of concrete examples of how they can be used in realistic threat hunting queries. #CTI #VTI #virustotal #thrunting

  15. A colleague of mine discovered a pattern in the downloaded stage 3 SocGholish payload. We've seen a few examples of this file in the most recent campaign where they use special characters in their file name such as:

    Chromе.Uрdatе.zip

    We've noticed a pattern though - in all of our SIEM queries the TargetFilePath always had the characters 'dat' as a filename.

    As such we wrote a simple Sigma rule that can identify that file name. This of course is only useful for this current campaign and the TA can easily adjust file names - but it may be helpful for threat hunting!

    TargetFileName|contains:
    - "dat\\ufffd\\ufffd.zip"

    github.com/joshnck/Sigma_Rules

    #SocGholish #thrunting #threathunting #ioc

  16. #infosec #thrunting all y'all getting huffy about your timelines like
  17. hey #infosec if you ain't posting my little pony memes today you ain't #thrunting hard enough for a Friday
  18. @cphax your posts are trapped in infosec.exchange. I saw your post because you used these hashtags. when you post good content, using proper hashtags broadcasts across the instances.

    I mean use #infosec when you're talking about a blog post or your #thrunting, but not if you're posting up favorite my little pony characters. It's not 'infosec'...

  19. I'm reading "The Art of Cyberwarfare" and I'll let you know how it goes! It seems like a great book so far, and has given me a lot of ideas...

    Chapter 7 is Open Source Threat Hunting! I haven't heard of ThreatNote before; use it to keep track of information and details gathered.
    Do I get to say #thrunting now?

    #infosecbookclub #infosec

  20. Data from recent #batloader campaigns leveraging digitally signed #malware impersonating popular software:

    🧲​ Lure sites:
    anyofferdesk[.]com
    offerdistancezoom[.]com
    offerslack[.]com
    teamofferview[.]com
    luminar4[.]com
    winrarlabs[.]com
    getsnotes[.]com

    🖊️​ Digital Certificates:
    "Digital Designs FL LLC"
    "Glacier Digital Ads Inc"
    "Danjo Digital LLC"

    🌐 ​C2s:
    24xpixeladvertising[.]com
    t1pixel[.]com
    photo-editor-mark[.]com

    ❓​ What's next?
    Batloader is malware-as-a-service that's been observed delivering InfoStealers or in some cases dual-use agents (atera, zoom) along with #cobaltstrike for #ransomware purposes

    🔗​ VT query for files signed by these certificates: virustotal.com/gui/search/sign

    #ThreatIntel #ThreatIntelligence #Thrunting