Cybersecurity Essentials

Mitre ATT&CK

The cybersecurity market already top $100 billion per year and will reach $300 billion by 2024. With that kind of money at stake, this market is one of the hottest areas for IT innovation.

Top news of the week: 27.04.2021.

#PulseSecure
#BHAsia
#MTrends
#BlackHat
#securitytools
#securitytech
#CyberAttack
#NetworkSecurity

Mitre Attack

@likethecoins shared
On Apr 22, 2021
RT @meansec: You may have noticed that we are responding faster to security events here @splunk. That isn't by accident. Here's some practical advice on detections and hunting by my team on the #PulseSecure excitement. https://t.co/XZ5mxBIUIR
Open
Monitoring Pulse Connect Secure With Splunk (CISA Emergency Directive 21-03)

Monitoring Pulse Connect Secure With Splunk (CISA Emergency Directive 21-03)

Over the past few weeks, there has been increasing chatter regarding adversary groups exploiting multiple vulnerabilities in the Pulse Connect Secure (PCS) virtual private network (VPN) ...

@MITREattack shared
On Apr 23, 2021
RT @hackerxbella: Just released a blog on the @MITREattack evaluations with @jeff_pollard2. For insights on how to think about the results of these evaluations, check it out: https://t.co/q4yPXbHvFH
Open
"Winning" MITRE ATT&CK, Losing Sight Of Customers

"Winning" MITRE ATT&CK, Losing Sight Of Customers

We didn’t need to check the results of the MITRE ATT&CK Carbanak+FIN7 evaluation when they were released, since within minutes of being live, we already had an email from a vendor touting ...

@kjhiggins shared
On Apr 23, 2021
Free security tools will be a thing at #BHAsia, as per usual. Here are some of the coolest ones that will be released there: https://t.co/ia7MV8Pnyr via @jaivijayan
Open
10 Free Security Tools at Black Hat Asia 2021

10 Free Security Tools at Black Hat Asia 2021

Researchers are set to demonstrate a plethora of tools for conducting pen tests, vulnerability assessments, data forensics, and a wide range of other use cases.

@olafhartong shared
On Apr 24, 2021
RT @ionstorm: Who is ready for a high performance Sysmon EDR based on Powershell? ✅MITRE ATT&CK ✅Yara Scanning ✅Kill Parent and all Child Processes ✅Kill Network Connections ✅Firewall Processes ✅Kill Parent/Child Processes ✅Notifications https://t.co/XKU2J3tXze .\install_edr.ps1 https://t.co/xJmb6b9UnR
Open
sysmon-edr

sysmon-edr

Contribute to ion-storm/sysmon-edr development by creating an account on GitHub.

@redcanary shared
On Apr 25, 2021
RT @likethecoins: My team is hiring a Senior Intelligence Analyst! 🙂 Please check out the job description and apply if you're interested. Note that the preferred qualifications are **not required**! https://t.co/TwWQi8UHCt
Open
Senior Intelligence Analyst

Senior Intelligence Analyst

Challenges You Will Solve We all face many threats and the threat landscape is constantly changing. The Red Canary Intelligence Team conducts in-depth analysis to provide context and help ...

@CSOonline shared
On Apr 22, 2021
Top ways attackers gained access to Windows networks in 2020 https://t.co/YNln4kFaF1 1. Using PowerShell and Windows Command Shell 2. Signed binary process execution using Rundll32 & Mshta 3. Creating and modifying system processes @redcanary #NetworkSecurity #CyberAttack
Open
Most common cyberattack techniques on Windows networks for 2020

Most common cyberattack techniques on Windows networks for 2020

Recent research breaks down the preferred techniques attackers use to gain access to Windows networks. Use this information to monitor your logs for these methods.

@daveherrald shared
On Apr 23, 2021
RT @stonerpsu: Just in time for some pre-weekend reading, here are some thoughts we at @SplunkSec wanted to share in conjunction with CISA's analyst report on SUPERNOVA and masquerading splunklogger.exe @splunk https://t.co/F0CeBsMIHK
Open
SUPERNOVA Redux, with a Generous Portion of Masquerading

SUPERNOVA Redux, with a Generous Portion of Masquerading

A review of the Pulse Secure attack where the threat actor connected to the network via a the Pulse Secure virtual private network (VPN), moved laterally to its SolarWinds Orion server, ...

@Mandiant shared
On Apr 22, 2021
How long do you think it takes to put together an #MTrends report? Find out in our podcast...and stick around for highlights from this year's report: https://t.co/tqUD1vYdd1 https://t.co/eq2Vi45CLH
Open
Behind the Scenes: The Making of an M-Trends Report

Behind the Scenes: The Making of an M-Trends Report

On this episode of our Eye on Security podcast, we offer folks a behind-the-scenes look at what goes into the making of our annual M-Trends report.