Cybersecurity Essentials

Mitre ATT&CK

The cybersecurity market already top $100 billion per year and will reach $300 billion by 2024. With that kind of money at stake, this market is one of the hottest areas for IT innovation.

Top news of the week: 02.03.2021.

#cybersecurity
#CTI
#threatdetection
#Githubification
#Solorigate
#SplunkSecurity
#Microsoft
#Lazarus
#APT
#CISOs

Mitre Attack

@splunk shared
On Mar 1, 2021
New month, new #SplunkSecurity staff picks. Yep, that’s just how the cookie crumbles around here. Speaking of snacks, we’d recommend you have one (or two) on hand while you explore some of our favorite security-centric reads. Check ‘em out here: https://t.co/76BDOpy45W https://t.co/kL4JsZZhby
Open
Staff Picks for Splunk Security Reading February 2021

Staff Picks for Splunk Security Reading February 2021

These monthly postings will feature the favorite security-centric presentations, white papers and customer case studies from various peeps in the Splunk (or not) security world that WE ...

@rickhholland shared
On Feb 26, 2021
“Microsoft open sources CodeQL queries used to hunt for Solorigate activity” https://t.co/shxUue0WKD
Open
Microsoft open sources CodeQL queries used to hunt for Solorigate activity

Microsoft open sources CodeQL queries used to hunt for Solorigate activity

We are sharing the CodeQL queries that we used to analyze our source code at scale and rule out the presence of the code-level indicators of compromise (IoCs) and coding patterns associated ...

@PatrickCMiller shared
On Mar 2, 2021
A Cyber Threat Intelligence Self-Study Plan: Part 1 https://t.co/dwGw5kJDJL
Open
A Cyber Threat Intelligence Self-Study Plan: Part 1

A Cyber Threat Intelligence Self-Study Plan: Part 1

There are many ways to learn. While some people prefer to have a live instructor in a course, others are great at doing self-study. I…

@likethecoins shared
On Feb 27, 2021
RT @CrowdStrike: Read “New Ransomware Tactic: Adversaries Target ESXi Servers” in the @CrowdStrike blog → https://t.co/FH9jRwjion #cybersecurity https://t.co/RIxGLcGY6P
Open
Hypervisor Jackpotting: CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact

Hypervisor Jackpotting: CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact

By deploying ransomware on ESXi hosts, adversaries quickly increased the scope of affected systems, further pressuring victims to pay the ransom demands.

@PatrickCMiller shared
On Mar 1, 2021
Lazarus targets defense industry with ThreatNeedle https://t.co/JIRji39eAi
Open
Lazarus targets defense industry with ThreatNeedle

Lazarus targets defense industry with ThreatNeedle

In mid-2020, we realized that Lazarus was launching attacks on the defense industry using the ThreatNeedle cluster, an advanced malware cluster of Manuscrypt (a.k.a. NukeSped).

@PatrickCMiller shared
On Feb 26, 2021
XDR is coming: 5 steps CISOs should take today https://t.co/4lKaimH4Ky
Open
XDR is coming: 5 steps CISOs should take today

XDR is coming: 5 steps CISOs should take today

Beyond threat detection and response, CISOs should think of XDR as an opportunity to modernize the SOC, automating processes, and improving staff productivity. Here's your XDR game plan for ...

@CSOonline shared
On Feb 26, 2021
By asking the right questions and using just a few available tools, it's possible to detect someone who might someday do something to compromise enterprise #cybersecurity. https://t.co/yubRLAdjtf @TechJohnEdwards #jobinterview #newhires #insiderthreat
Open
Security job candidate background checks: What you can and can't do

Security job candidate background checks: What you can and can't do

Enterprise cybersecurity begins with a trustworthy staff. Here's how to ensure that current and prospective team members aren't hiding any skeletons.

@Mandiant shared
On Mar 1, 2021
SOCs are necessary, but the burnout these employees currently experience will cause most security teams to suffer. Accurate and actionable threat intel through #MandiantAdvantage could save them time as they defend their environments: https://t.co/FTRzfO8Xv7 https://t.co/6dzQqGZiuB
Open
Want to keep track of the latest insights and news?

Want to keep track of the latest insights and news?

However, when SOC teams and business leaders start to lose confidence in one another, their effectiveness is likely to suffer and change will be required. This change will take …