#thrunting — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #thrunting, aggregated by home.social.
-
Oh, and for those that didn't know, the good side lost the battle against the unironic use of the term #thrunting . It appears it's here to stay.
-
Oh, and for those that didn't know, the good side lost the battle against the unironic use of the term #thrunting . It appears it's here to stay.
-
Oh, and for those that didn't know, the good side lost the battle against the unironic use of the term #thrunting . It appears it's here to stay.
-
Just downloaded and about to start playing around with a cloud security tool.
In my opinion there is no better way to threat hunt that to emulate adversarial activity, note all indicators using whatever tools are available, and then begin forming hypothesis about how to use these indicators and start developing leads.
Also a hot take, I'm immediately suspicious of any Blue Teamer who claims to not enjoy playing with Red Team tools. If this doesn't bring even a bit of joy, why even work in security.
-
Just downloaded and about to start playing around with a cloud security tool.
In my opinion there is no better way to threat hunt that to emulate adversarial activity, note all indicators using whatever tools are available, and then begin forming hypothesis about how to use these indicators and start developing leads.
Also a hot take, I'm immediately suspicious of any Blue Teamer who claims to not enjoy playing with Red Team tools. If this doesn't bring even a bit of joy, why even work in security.
-
Check out! New sharing community for Threat Hunters, from some amazing people I greatly respect @letswastetime and @Jotunvillur
HEARTH (Hunting Exchange And Research Threat Hub)!
Hey thrunters! A new open-source home to:
- Share hunt ideas
- Learn from others
- Level up togetherBuilt by hunters, for hunters 🎯
https://threathuntingcommunity.com -
Check out! New sharing community for Threat Hunters, from some amazing people I greatly respect @letswastetime and @Jotunvillur
HEARTH (Hunting Exchange And Research Threat Hub)!
Hey thrunters! A new open-source home to:
- Share hunt ideas
- Learn from others
- Level up togetherBuilt by hunters, for hunters 🎯
https://threathuntingcommunity.com -
Hack.lu 2023: Velocity Raptor: Accelerating Velociraptor Hunting With Tenzir - Matthias Vallentin
https://www.youtube.com/watch?v=2ghZbkk8XS4
#Velociraptor #DFIR #Tenzir #ThreatHunting #Thrunting #Speed #Velocity
-
Hack.lu 2023: Velocity Raptor: Accelerating Velociraptor Hunting With Tenzir - Matthias Vallentin
https://www.youtube.com/watch?v=2ghZbkk8XS4
#Velociraptor #DFIR #Tenzir #ThreatHunting #Thrunting #Speed #Velocity
-
Hack.lu 2023: Velocity Raptor: Accelerating Velociraptor Hunting With Tenzir - Matthias Vallentin
https://www.youtube.com/watch?v=2ghZbkk8XS4
#Velociraptor #DFIR #Tenzir #ThreatHunting #Thrunting #Speed #Velocity
-
A co-worker of mine the other day referred to Threat Hunting as Thrunting, and now I want to make Thrunting an actual cyber security term so very badly.
-
A co-worker of mine the other day referred to Threat Hunting as Thrunting, and now I want to make Thrunting an actual cyber security term so very badly.
-
A co-worker of mine the other day referred to Threat Hunting as Thrunting, and now I want to make Thrunting an actual cyber security term so very badly.
-
Achieving PEAK Performance: Introducing the PEAK Threat Hunting Framework
-
Achieving PEAK Performance: Introducing the PEAK Threat Hunting Framework
-
Achieving PEAK Performance: Introducing the PEAK Threat Hunting Framework
-
Threathound: An IR (Incident Response) and threat hunting tool
Check ✅️ it out: -
Threathound: An IR (Incident Response) and threat hunting tool
Check ✅️ it out: -
Threathound: An IR (Incident Response) and threat hunting tool
Check ✅️ it out: -
IntelOwl an Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API. It integrates a number of analyzers available online and a lot of cutting-edge malware analysis tools.
-
I totally forgot about this place!! But hey maybe I should be involved again.
To my #CTI #SOC folks out there, what do you do with the massive scanning IP threat feeds? Are you ingesting them into SIEM for alerting?
If you are ingesting bot IPs and scanning IPs, what confidence and severity level do you set your threshold to ingest high fidelity indicators?
I want to know what everyone’s thoughts and strategies are on ingesting low-yield indicators.
-
It is Thrunting Thursday - what are you looking for today?
I'll be looking for .lnk files that spawn processes with a child or grandchild process that is cmd or powershell - especially originating from non C:\ drives
-
New episode of DISCARDED! 🎙️🔮
We’re joined by Rich Gonzalez, Daniel Blackford, and @adorais to talk about what we expect to see from threat actors in this year. Lots of really great insights about actor TTP changes, vulnerability exploitation, MFA bypass, and more. Tune in!
#podcast #cybersecurity #threatintelligence #threatdetection #thrunting
Spotify: https://open.spotify.com/episode/15SwTlR0ziMoHSfSAJVuyC?si=b5268e7df9f744e5
Web: https://www.proofpoint.com/us/podcasts/discarded#123486
-
It is THRUNTING THURSDAY!
What are you hunting for today?
-
Kudos to virustotal for the cheatsheet they dropped today (https://blog.virustotal.com/2022/12/vt-intelligence-cheat-sheet.html). They already had their various search modifiers documented, but this gives a dense set of concrete examples of how they can be used in realistic threat hunting queries. #CTI #VTI #virustotal #thrunting
-
A colleague of mine discovered a pattern in the downloaded stage 3 SocGholish payload. We've seen a few examples of this file in the most recent campaign where they use special characters in their file name such as:
Chromе.Uрdatе.zip
We've noticed a pattern though - in all of our SIEM queries the TargetFilePath always had the characters 'dat' as a filename.
As such we wrote a simple Sigma rule that can identify that file name. This of course is only useful for this current campaign and the TA can easily adjust file names - but it may be helpful for threat hunting!
TargetFileName|contains:
- "dat\\ufffd\\ufffd.zip"https://github.com/joshnck/Sigma_Rules/blob/main/apt_socgholish_fakeupdate.yml
-
#infosec #thrunting all y'all getting huffy about your timelines like -
hey #infosec if you ain't posting my little pony memes today you ain't #thrunting hard enough for a Friday -
@cphax your posts are trapped in infosec.exchange. I saw your post because you used these hashtags. when you post good content, using proper hashtags broadcasts across the instances.
I mean use #infosec when you're talking about a blog post or your #thrunting, but not if you're posting up favorite my little pony characters. It's not 'infosec'...
-
I'm reading "The Art of Cyberwarfare" and I'll let you know how it goes! It seems like a great book so far, and has given me a lot of ideas...
Chapter 7 is Open Source Threat Hunting! I haven't heard of ThreatNote before; use it to keep track of information and details gathered.
Do I get to say #thrunting now? -
Data from recent #batloader campaigns leveraging digitally signed #malware impersonating popular software:
🧲 Lure sites:
anyofferdesk[.]com
offerdistancezoom[.]com
offerslack[.]com
teamofferview[.]com
luminar4[.]com
winrarlabs[.]com
getsnotes[.]com🖊️ Digital Certificates:
"Digital Designs FL LLC"
"Glacier Digital Ads Inc"
"Danjo Digital LLC"🌐 C2s:
24xpixeladvertising[.]com
t1pixel[.]com
photo-editor-mark[.]com❓ What's next?
Batloader is malware-as-a-service that's been observed delivering InfoStealers or in some cases dual-use agents (atera, zoom) along with #cobaltstrike for #ransomware purposes🔗 VT query for files signed by these certificates: https://www.virustotal.com/gui/search/signature%253A%2522Digital%2520Designs%2520FL%2520LLC%2522%2520OR%2520signature%253A%2522Glacier%2520Digital%2520Ads%2520Inc%2522%2520OR%2520signature%253A%2522Danjo%2520Digital%2520LLC%2522/files