My network is getting hammered by SSH scanners lately. Possibly checking for CVE-2023-25136. The IP below has sent over 2k flows in a day and Greynoise tags it as an SSH Bruteforcer and worm.
Another IP originating from Russia (92.63.197[.]82) has also sent just over 2k flows. Historical analysis shows it targeting previous SSH vulnerabilities.
#cve_2023_25136 #SSH #Netflow #Firewalla #IPS #SignalsIntelligence #Vulnerability
#cve_2023_25136 #ssh #netflow #firewalla #ips #signalsintelligence #vulnerability
🗞️ NCSC’s first bulletin of the month emphasized how adversaries collect much of their information about the #UnitedStates via open source #intelligence (#OSINT), with only a small percentage from clandestine/covert collection methodologies (spies, #signalsintelligence, etc.).
https://news.clearancejobs.com/2023/01/31/every-opsec-failure-gives-u-s-adversaries-more-osint/
#signalsintelligence #osint #intelligence #unitedstates
In addition to superb #signalsintelligence collection during the 1920 war with Russia, the Poles were also masters of other aspects of #informationwarfare:
#signalsintelligence #informationwarfare
Netflow analysis is honestly an art. So many artifacts to pivot off of to create a trail of connections. Finding out who and what got compromised, C2 beacon connections, and if you're lucky enough you may find the C2 controller (which I did).
Tools I can't go without: Augury, Maxmind, @DomainTools , Censys
#SignalsIntelligence #ThreatHunting #NetflowAnalysis #CobaltStrike
#signalsintelligence #threathunting #netflowanalysis #cobaltstrike
Biden's handlers couldn't care less about the Constitution.
#signalsintelligence #executiveorder #Bidendomesticspying
Biden's handlers couldn't care less about the Constitution.
#signalsintelligence #executiveorder #Bidendomesticspying
Biden's handlers couldn't care less about the Constitution.
#signalsintelligence #executiveorder #Bidendomesticspying
Biden's handlers couldn't care less about the Constitution.
#signalsintelligence #executiveorder #Bidendomesticspying