securitydoggo's profile picture. #infosec #cybersecurity #SIEM #malware #incidentresponse #threathunting #phishing #YARArules I find #APTs, #malware, and #credharvesters 🐕 in a world of 🐟

Security Doggo

@securitydoggo

#infosec #cybersecurity #SIEM #malware #incidentresponse #threathunting #phishing #YARArules I find #APTs, #malware, and #credharvesters 🐕 in a world of 🐟

If you ever changed your #LastPass password iterations count, it never got updated when @LastPass changed their default to 100,100 from 5k. Anyone got a calculator to see how long it would take various iteration amounts to crack?


Security Doggo reposted

Stories from the SOC: #Fortinet authentication bypass observed in the wild. Read: cybersecurity.att.com/blogs/security… via @attcyber

TheHackersNews's tweet image. Stories from the SOC: #Fortinet authentication bypass observed in the wild.

Read: cybersecurity.att.com/blogs/security…

via @attcyber

While I never got the opportunity to meet him in person, I have so many fond memories of chatting with him in DMs and seeing his analysis on the random stuff I tag him in. Sad to lose a hero and such an amazing person in the field.

The SentinelOne team is deeply saddened by the sudden loss of our former teammate, & friend of so many, @VK_Intel. Vitali was a founding member of SentinelLabs & made numerous contributions to the security community. Our thoughts are with his family.

SentinelOne's tweet image. The SentinelOne team is deeply saddened by the sudden loss of our former teammate, & friend of so many, @VK_Intel. Vitali was a founding member of SentinelLabs & made numerous contributions to the security community. Our thoughts are with his family.


Security Doggo reposted

My first blog with @MicrosoftDART! This is a post incident report, talking about some of the TTPs we saw in a recent ransomware incident. This really emphasizes the importance of doing a post ransomware IR. microsoft.com/security/blog/…


Incredible amount of pages on @issuu with a clickable box/link (usually for click here to access document) to 0365 #credharvesters #infosec urlscan.io/search/#page.d…


Something weird happened on my @Malwarebytes - might have borked during an update but the exe became mbam.not and Defender borked out at the same time. Pretty scary when you're doing firewall changes on the home network 🥲


About to present to a crowd about how to succeed in the #cyber world; what knowledge do you think is important for junior folks in the field to know? 1) Imposter syndrome is real and everyone suffers from it 2) Stay uncomfortable 3) Focus on impact over certs and clout #infosec


Security Doggo reposted

1/ The screenshot below is from one of my #Azure Security / IR presentations. Most people laugh at this slide because it seems almost too easy to detect a compromised account this way, right? Guess what happens next. 👇 #CyberSecurity

malmoeb's tweet image. 1/ The screenshot below is from one of my #Azure Security / IR presentations. 

Most people laugh at this slide because it seems almost too easy to detect a compromised account this way, right?

Guess what happens next. 👇 

#CyberSecurity

Security Doggo reposted

NEW: Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits An unpatched Microsoft Exchange Server let both #ransomware actors in; Karma just stole data, while Conti encrypted... 1/15

SophosXOps's tweet image. NEW: Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits

An unpatched Microsoft Exchange Server let both #ransomware actors in; Karma just stole data, while Conti encrypted...

1/15

Anyone have a @virustotal POC? Need a file taken down asap


Security Doggo reposted

Tomorrow (Weds): @jhencinski, @The_Real_BenB, & @united's @SeanAMason discuss the 4 most important #infosec attack trends ... 📨 BEC targeting emails & application data 💸 #Ransomware 🚚 Supply chain targeting 🪙 #Cryptojacking ... in this webcast: brighttalk.com/webcast/18949/… #MDR


Great job @virustotal for taking down that massive list of email addresses that was uploaded last night #infosec


Another day, another compromise. For the love of all things #cyber, please patch. #infosec


Security Doggo reposted

Process Hollowing Alert is now in #SIGMA. Sysmon Event ID 25 with a type of “image is replaced” github.com/SigmaHQ/sigma/…


Another day, another vulnerable external facing application, another #ransomware gang. #cyber #infosec #malware


Seeing what looks to be NIDS picking up backup traffic from servers to backup servers firing off strings for log4shell; also in the packet are a bunch of Microsoft threat names and detection logic - thinking it's like the signature files for Defender. Thoughts?


Security Doggo reposted

We did a deep dive on the #WhisperGate #BleedingBear malware samples. New details on process hollowing technique used by the stage3 injector and method to terminate Windows Defender elastic.github.io/security-resea…


Security Doggo reposted

Our friends from @_CPResearch_ published on Zloader abusing CVE-2020-1599 in recent campaigns. Here you can learn how to leverage VirusTotal Intelligence to monitor malware abusing this vulnerability (by @fcojsantos) blog.virustotal.com/2022/01/monito…

virustotal's tweet image. Our friends from @_CPResearch_ published on Zloader abusing CVE-2020-1599 in recent campaigns. Here you can learn how to leverage VirusTotal Intelligence to monitor malware abusing this vulnerability (by @fcojsantos) blog.virustotal.com/2022/01/monito…

Loading...

Something went wrong.


Something went wrong.