Christoffer S. · @cstromblad
1052 followers · 1023 posts · Server ioc.exchange

Really liked this post by Roza Maille at Trustedsec about how one could get into Detection Engineering. Especially liked the idea of focussing on core knowledge areas rather than specific things like Yara.

Also very useful with plenty of links to relevant resources for getting deeper into it all.

trustedsec.com/blog/on-the-roa

[ ]

#detectionengineering #trustedsec

Last updated 2 years ago

Christoffer S. · @cstromblad
1034 followers · 994 posts · Server ioc.exchange

Any thoughts on how many Credential Stealer families rely on using the Telegram API Bot endpoint for exfiltrating / copying information from infected devices?

Trying to assess the potential for leveraging that observation for some simple detection rules of potential stealer infections.

Any hot takes?

[ ]

#threatintel #detectionengineering #credentialstealer

Last updated 2 years ago

Megan Roddie · @megan
273 followers · 91 posts · Server infosec.exchange

If you're looking for great content and haven't subscribed to @techy substack, go do it now: detectionengineering.net/

Always look forward to seeing the weekly newsletter arrive in my inbox!

#detectionengineering

Last updated 3 years ago

Renaud Lifchitz :verified: · @nono2357
251 followers · 1100 posts · Server infosec.exchange
Joe Słowik · @jfslowik
2718 followers · 1286 posts · Server infosec.exchange

When you're trying to socialize a unified taxonomy and your mind just continually goes to this:

#cti #threathunting #detectionengineering

Last updated 3 years ago

Matt Franz · @mdfranz
223 followers · 463 posts · Server infosec.exchange

Although tThat anology about "teenagers having sex" (more talk than action going) may no longer work like it do for GenX, my hunch is that 75% of organizations are not doing "Detection as Code" yet in their

#siem #detectionengineering

Last updated 3 years ago

Matt Franz · @mdfranz
223 followers · 460 posts · Server infosec.exchange
· @reswob
74 followers · 210 posts · Server infosec.exchange

This is a great post with awesome details for
twitter.com/jsecurity101/statu

Not sure if they are on this medium...

#blueteam #detectionengineering

Last updated 3 years ago

Matt Franz · @mdfranz
223 followers · 455 posts · Server infosec.exchange
Matt Franz · @mdfranz
222 followers · 447 posts · Server infosec.exchange
Br3akp0int · @Br3akp0int
33 followers · 12 posts · Server infosec.exchange

Windows Registry is one of the powerful features of Windows OS that being tweak and abused by Threat actors. In this Splunk Threat Research blog we described common MITRE ATT&CK TTP’s that leverages win registry ( 8/14) including its detections, testing and analysis. 😊 #BlueTeam

splunk.com/en_us/blog/security

#Atomicredteam #splunk #malware #strt #detectionengineering

Last updated 3 years ago

Joe Słowik · @jfslowik
2597 followers · 1006 posts · Server infosec.exchange

Almost exactly a year ago I had the opportunity to present at @hacks4pancakes 's to talk two of my passions: and !
youtu.be/laF5Yl2RALg

#pancakescon #detectionengineering #lego

Last updated 3 years ago

Taylor Parizo · @taylorparizo
156 followers · 156 posts · Server infosec.exchange

It feels so good having a functioning lab again. rules started firing after I launched a Python server and downloaded a PE file. At some point I'll learn but for now network logs are good enough.

#suricata #yara #detectionengineering #incidentresponse #virtualbox

Last updated 3 years ago

Taylor Parizo · @taylorparizo
156 followers · 156 posts · Server infosec.exchange

It feels so good having a functioning lab again. rules started firing after I launched a Python server and downloaded a PE file. At some point I'll learn but for now network logs are good enough.

#suricata #yara #detectionengineering #incidentresponse #virtualbox

Last updated 3 years ago

Now is a good time for you to drop couple of in your chats. You might get lucky...

#aws #canarytokens #slack #detectionengineering #spotthebirdie

Last updated 3 years ago

Megan Roddie · @megan
37 followers · 3 posts · Server infosec.exchange

Well now that I'm here it's probably about time I start marketing my book coming out this spring. Really excited about this project, been having a great time working with Jason (@cog) and Gary on it. Will have posts over the coming weeks teasing some stuff leading up to its release in late Spring. There are some wonderful blog posts out there on DE, but based on our market research, this is going to be the first comprehensive book on DE and is designed to be a practical, hands-on guide. Super duper excited to share more over the coming weeks and eventually launch the book for everyone to get their hands on!

#detectionengineering

Last updated 3 years ago

Joe Słowik · @jfslowik
2417 followers · 725 posts · Server infosec.exchange

Hey if you need somone on the or and front, I'm VERY MUCH listening right now. You can find my CV here (pylos.co/wp-content/uploads/20) and some of my past public presentations (pylos.co/presentations/) and written items (pylos.co/papers-publications-a).

I'm especially partial to roles in / and critical infrastructure!

#cti #threatintel #threathunting #detectionengineering #ics #ot

Last updated 3 years ago

Richard Ackroyd · @ackroyd
123 followers · 24 posts · Server infosec.exchange

Find articles like this really interesting. I think signature based detection techniques hand in hand with unsupervised machine learning is the way forward (and obviously already leveraged by market leaders). If anyone knows of similar write ups let me know! Need some Christmas reading… blog.developer.adobe.com/using

#detectionengineering

Last updated 3 years ago

Colin Cowie · @th3_protoCOL
557 followers · 110 posts · Server infosec.exchange

New reporting on by Palo Alto's Unit42!
🔗unit42.paloaltonetworks.com/th

Key points:

🗓️​ Threat activity starting in late November
➡️​ Download of renamed Putty
➡️​ Anydesk execution from `C:\ProgramData\`
➡️​ Account creation (`admon`)
➡️​ Credential Dumping via Task Manager
🛡️​ Detection/Hunting Op: `w3wp` process abuse

#proxynotshell #threatintel #cti #detectionengineering

Last updated 3 years ago