Br3akp0int · @Br3akp0int
33 followers · 12 posts · Server infosec.exchange

Windows Registry is one of the powerful features of Windows OS that being tweak and abused by Threat actors. In this Splunk Threat Research blog we described common MITRE ATT&CK TTP’s that leverages win registry ( 8/14) including its detections, testing and analysis. 😊 #BlueTeam

splunk.com/en_us/blog/security

#Atomicredteam #splunk #malware #strt #detectionengineering

Last updated 3 years ago

Br3akp0int · @Br3akp0int
3 followers · 1 posts · Server infosec.exchange

Sharing blog related to malware analysis and detections. In this article we include some tip how you can use fakesmtp server to see the exfiltrated data in attacker side. 😀

splunk.com/en_us/blog/security

1. modify smtp setup, disable smtp SSL

2. then setup your fake or dummy smtp server. In this analysis I use this great tool .

github.com/rnwood/smtp4dev

after the setup, you have the attacker's view as it sends the screenshot, keylogs and browser databases/info (in .zip) to your fake smtp.

for analytics here is the link of the analytic story research.splunk.com/stories/ag

#strt #agenttesla #smtpdev #splunk #malware #int3 #reverseengineering #blueteam #cybersecurity #incidentresponse

Last updated 3 years ago

Br3akp0int · @Br3akp0int
33 followers · 12 posts · Server infosec.exchange

Sharing blog related to malware analysis and detections. In this article we include some tip how you can use fakesmtp server to see the exfiltrated data in attacker side. 😀

splunk.com/en_us/blog/security

1. modify smtp setup, disable smtp SSL

2. then setup your fake or dummy smtp server. In this analysis I use this great tool .

github.com/rnwood/smtp4dev

after the setup, you have the attacker's view as it sends the screenshot, keylogs and browser databases/info (in .zip) to your fake smtp.

for analytics here is the link of the analytic story research.splunk.com/stories/ag

#strt #agenttesla #smtpdev #splunk #malware #int3 #reverseengineering #blueteam #cybersecurity #incidentresponse

Last updated 3 years ago