Summary
— A collection of infosec links to Tools & Tips, Threat Research, and more! The focus trends toward DFIR and threat intelligence, but general information security and hacking-related topics are included as well. This list is not vetted nor intended to be an exhaustive source. Keeping up with the enormous volume of security-related information is a daunting task, but this is my way of filtering the most useful items and improving the signal to noise ratio. Happy Reading!
Industry Reports, News, and Miscellany
- SANS Reading Room: Effectively Addressing Advanced Threats
- Kaspersky: Incident Response report 2018
- Purple Teaming ICS Networks: Part 2 of 3
- Banking Trojans: A Reference Guide to the Malware Family Tree
- Incident trends report (October 2018 – April 2019)
- Day-1 Skills That Cybersecurity Hiring Managers Are Looking For
Threat Research – Malware, Phishing, and other Campaigns in the Wild
- More_eggs, Anyone? Threat Actor ITG08 Strikes Again
- Ransomware Strains in a Post-GandCrab Environment
- Tracking Down a Big Phish
- TA505 At It Again: Variety is the Spice of ServHelper and FlawedAmmyy
- China Chopper still active 9 years later
- RAT Ratatouille: Backdooring PCs with leaked RATs
- Malware Samples Compiling Their Next Stage on Premise
- Inside the APT28 DLL Backdoor Blitz
- CB TAU Threat Intelligence Notification: Trickbot Banking Trojan Continues to Evolve
- Hancitor/Amadey (8.26.2019): .vbs script analysis
Tools and Tips
- Merlin v0.8.0 Released
- Exploiting AWS ECR and ECS with the Cloud Container Attack Tool (CCAT)
- How to Write Good Tweets
- Packet Strider (v0.1): A network packet forensics tool for SSH
- osctrl: A fast and efficient osquery management solution
- Malware Analysis Pipeline in AWS (part 1)
- Analysis of the JSE malware
- Kerberos Attacks Cheatsheet
- Advanced Splunk Searching for Security Hunting and Alerting (video)
- Android – Locating Location Data: The Tile App
- MISP v2.4.114 released (aka the community care package release)
- https://www.misp-project.org/2019/08/31/MISP.2.4.114.released.html
Breaches, Government, and Law Enforcement
- Jack Dorsey’s Twitter account got hacked
- A very deep dive into iOS Exploit chains found in the wild
- Ryuk Ransomware Impacts Long Island’s Rockville Centre School District
- Ransomware Bites Dental Data Backup Firm
Vulnerabilities and Exploits
- A Vulnerability in Google Chrome Could Allow for Arbitrary Code Execution\
- Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability
- Hiding in Plain Text: Jenkins Plugin Vulnerabilities
- Windows Process Injection: Asynchronous Procedure Call (APC)
- MiniDumpWriteDump via COM+ Services DLL