Taylor Parizo · @taylorparizo
175 followers · 247 posts · Server infosec.exchange

My network is getting hammered by SSH scanners lately. Possibly checking for CVE-2023-25136. The IP below has sent over 2k flows in a day and Greynoise tags it as an SSH Bruteforcer and worm.
Another IP originating from Russia (92.63.197[.]82) has also sent just over 2k flows. Historical analysis shows it targeting previous SSH vulnerabilities.

#cve_2023_25136 #ssh #netflow #firewalla #ips #signalsintelligence #vulnerability

Last updated 1 year ago

OSINT AURORA · @osintaurora
684 followers · 1342 posts · Server mstdn.social

🗞️ NCSC’s first bulletin of the month emphasized how adversaries collect much of their information about the via open source (), with only a small percentage from clandestine/covert collection methodologies (spies, , etc.).

news.clearancejobs.com/2023/01

#signalsintelligence #osint #intelligence #unitedstates

Last updated 2 years ago

Richard Bejtlich · @taosecurity
1548 followers · 89 posts · Server infosec.exchange

In addition to superb collection during the 1920 war with Russia, the Poles were also masters of other aspects of :

#signalsintelligence #informationwarfare

Last updated 2 years ago

Taylor Parizo · @taylorparizo
145 followers · 118 posts · Server infosec.exchange

Netflow analysis is honestly an art. So many artifacts to pivot off of to create a trail of connections. Finding out who and what got compromised, C2 beacon connections, and if you're lucky enough you may find the C2 controller (which I did).

Tools I can't go without: Augury, Maxmind, @DomainTools , Censys

#signalsintelligence #threathunting #netflowanalysis #cobaltstrike

Last updated 2 years ago

· @Newstarget
1960 followers · 17917 posts · Server brighteon.social
· @Newstarget
2027 followers · 18145 posts · Server brighteon.social
· @NaturalNews
5593 followers · 25363 posts · Server brighteon.social
· @NaturalNews
5863 followers · 26921 posts · Server brighteon.social