aptnotes's profile picture. https://otx.alienvault.com/user/aptnotes   http://keybase.io/aptnotes

APT notes

@aptnotes

https://otx.alienvault.com/user/aptnotes http://keybase.io/aptnotes

APT notes reposted

Have you ever wondered what are the main sources of Windows vulns in kernel mode. I went through Microsoft's CVE portal over the past three years to find out which Windows km components have been patched most frequently - consuming company's resources. aibaranov.github.io/windrivers/


APT notes reposted

Incredible. CERT India published a list of file hash IOCs as an image and have also turned off right-click on their website 🤣 smh 💀

BushidoToken's tweet image. Incredible. CERT India published a list of file hash IOCs as an image and have also turned off right-click on their website 🤣 smh 💀

APT notes reposted

When a vendor shares IOC's in an image so you can't copy paste the SHA256

vxunderground's tweet image. When a vendor shares IOC's in an image so you can't copy paste the SHA256

APT notes reposted

NEW: @apple announces #LockdownMode, a major change to iPhone security that promises to help high risk users + other actions to hold the mercenary spyware industry to account nr.apple.com/d2I3Q1s4s0 My thread w context & details 👇


APT notes reposted

For at least a decade, an interlocking set of Indian APT groups has been hacking lawyers & litigants on behalf of Western private eyes. Their goal? Winning lawsuits & arbitration battles. @specialreports takes a look at India's cyber mercenary industry. reuters.com/investigates/s…


Just added the 500th report to #aptnotes! #infosec #DFIR


oh cool and it looks like our Github webhook died, off to fix that -- anywho -- we merged the tools fix from github.com/Taskr repo this morning #infosec #DFIR #aptnotes


apologies all for the masso backlog -- things have been crazy busy in the "things we get paid to do" category -- we are working through it and trying to sort out better forms of automation #DFIR #infosec #aptnotes


Dear dear #infosec vendors, here’s an idea: maybe you could make a PDF version of your reporting so it’s easier to save for posterity. I know of a group that would really appreciate not having to modify things by hand so it doesn’t look like vomit #DFIR


ADVISORY: We have identified a new version of the Turla group’s Neuron malware which has been modified to evade previous detection methods. See our updated report here ncsc.gov.uk/alerts/turla-g…



ADVISORY: We have identified a new version of the Turla group’s Neuron malware which has been modified to evade previous detection methods. See our updated report here ncsc.gov.uk/alerts/turla-g…



APT notes reposted

We've released the APT3 Adversary Emulation Plan based on ATT&CK. These plans help describe a threat group's behavior for the purposes of testing security. Special thanks to @ckorban, Doug Miller, Adam Pennington, and @its_a_feature_ for their work attack.mitre.org/wiki/Adversary…


we concur

If you are writing or consuming reports that include assessments of adversary campaigns or activity groups be sure to read the Diamond Model activeresponse.org/wp-content/upl…



please be gracious with us - we are dealing with some fun time shortage and technology issues atm - we love you, Happy New Year #infosec #DFIR #aptnotes


Loading...

Something went wrong.


Something went wrong.