David Szili's Avatar

David Szili

@davidszili.bsky.social

AlzetteInfoSec Managing Partner | BSidesLux Ex-Organizer | SANS Principal Instructor | Posts are mine, all mine!

118 Followers  |  115 Following  |  2 Posts  |  Joined: 23.11.2024
Posts Following

Posts by David Szili (@davidszili.bsky.social)

Preview
Threat-Hunting-and-Detection/Defense Evasion/Microsoft Recommended Driver Block List.md at main Β· Cyb3r-Monk/Threat-Hunting-and-Detection Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language). - Cyb3r-Monk/Threat-Hunting-and-Detection

Detection for Microsoft Recommended Driver Block List

github.com/Cyb3r-Monk/T...

#ThreatHunting #DetectionEngineering

13.12.2024 12:06 β€” πŸ‘ 14    πŸ” 3    πŸ’¬ 0    πŸ“Œ 1
LEAPPs.org

#DFIR Thought of the day: Open Source tools are evolving and are incredibly valuable in investigations

OS tools are often developed to fill gaps in commercial tools. One is the LEAPP project by @abrignoni.com. Incredible new functionality with LAVA LEAPPs.org

11.12.2024 11:55 β€” πŸ‘ 7    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

11 days. That’s how long I survived #whamageddon this year… it was a good run.

11.12.2024 22:07 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
jewishatlanta[.]org showing a "verify you are human" notification with a box to check/click on.

jewishatlanta[.]org showing a "verify you are human" notification with a box to check/click on.

If you click the checkbox, your copy/paste cache will have the malicious PowerShell script for you to paste in a Run window.

If you click the checkbox, your copy/paste cache will have the malicious PowerShell script for you to paste in a Run window.

The copy/paste PowerShell script that downloads and runs more malicious script hosted on gardenworksproject[.]org.

The copy/paste PowerShell script that downloads and runs more malicious script hosted on gardenworksproject[.]org.

Traffic from an infection filtered in Wireshark.

Traffic from an infection filtered in Wireshark.

2024-12-06 (Friday): jewishatlanta[.]org compromised and showing a #ClickFix style notification to copy/paste PowerShell script. The resulting #malware infection uses the #BOINC project with some (not all) of the same indicators as noted in July 2024 at www.huntress.com/blog/fake-br... and elsewhere

07.12.2024 08:30 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Soo... A little bit of awareness is probably a good idea :p

We can delete MDI sensors from the Defender portal and do so in bulk via the internal API

It might be a good idea to set up a detection for this:

CloudAppEvents
| where ActionType == "SensorDeleted"

07.12.2024 00:05 β€” πŸ‘ 20    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0
Screenshot of the email showing a TAR archive as an email attachment.

Screenshot of the email showing a TAR archive as an email attachment.

The TAR archive and its content, a Windows EXE file for AgentTesla

The TAR archive and its content, a Windows EXE file for AgentTesla

An update to the Windows registry showing the malware persistent on an infected Windows host.

An update to the Windows registry showing the malware persistent on an infected Windows host.

Traffic from an infection filtered in Wireshark to show the FTP data exfiltration traffic.

Traffic from an infection filtered in Wireshark to show the FTP data exfiltration traffic.

2024-12-04 (Wednesday): #AgentTesla variant using #FTP for data exfiltration. A sanitized copy of the email distributing the malware, a #pcap from an infection run, the associated malware samples, and a list of indicators are available at www.malware-traffic-analysis.net/2024/12/04/i...

05.12.2024 01:14 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0
Preview
Humble Tech Book Bundle: Hacking 2024 by No Starch (pay what you want and help charity) Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!

Hey hey, a No Starch Bundle that supports the ACLU and the EFF. You know what to do.

www.humblebundle.com...

04.12.2024 06:30 β€” πŸ‘ 7    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Post image

DownDetector has published a summary of the largest IT outages of the year. Believe it or not, CrowdStrike is not on top.

www.ookla.com/articles/lar...

03.12.2024 13:43 β€” πŸ‘ 11    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Post image Post image Post image Post image

Our SIEGECAST: "Be Your Enemy", dives into actionable strategies that take your Blue Team operations to the next level.

Dive in: redsiege.com/be-your-enemy
Video breakdown Included.

Which of these tactics are you already using?

#hacking #Infosec #cybersecurity

03.12.2024 18:14 β€” πŸ‘ 5    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - osintmatter/RequestShield: RequestShield is a 100% Free and OpenSource tool designed to analyze HTTP access.logs and identify suspicious HTTP requests and potential security threats. It uses ... RequestShield is a 100% Free and OpenSource tool designed to analyze HTTP access.logs and identify suspicious HTTP requests and potential security threats. It uses factors like geolocation, abuse h...

Security researcher OSINT Matter has released RequestShield, an open-source tool to analyze HTTP access.logs and identify suspicious HTTP requests and potential security threats

github.com/osintmatter/...

03.12.2024 09:46 β€” πŸ‘ 33    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0

🚨 Time’s Running Out! 🚨

Take your DFIR skills to the next level with 35% OFF all our DFIR Labs! πŸ”₯

⏰ Hurryβ€”this deal ends 11/30 at 0500 UTC!

store.thedfirreport.com/collections/...

29.11.2024 14:21 β€” πŸ‘ 8    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Post image

Don't miss out! All of my Applied Network Defense courses are now 25% off until December 3rd at midnight ET. Use the code MAKEMOREBISCUITS to claim your discount. It's our only sale like this all year!

29.11.2024 14:04 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - Censys-Research/censeye Contribute to Censys-Research/censeye development by creating an account on GitHub.

Censys has released Censeye, a tool to identify hosts with characteristics similar to a given target

github.com/Censys-Resea...

28.11.2024 19:24 β€” πŸ‘ 43    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - khyrenz/parseusbs: Parses USB connection artifacts from offline Registry hives Parses USB connection artifacts from offline Registry hives - khyrenz/parseusbs

🚨 #DFIR Tool update 🚨

I’ve updated parseUSBs (again!):
- Now supports mounted #KAPE images
- Improved deduplication of events within secs of each other
- Added extraction of partition style (MBR/GPT) & Filesystem
- Parses alternate S/Ns
- Parses WPDBUSENUM key

github.com/khyrenz/pars...

25.11.2024 22:19 β€” πŸ‘ 28    πŸ” 10    πŸ’¬ 1    πŸ“Œ 0
Screenshot of malicious spam (malspam) with malware file attachment.

Screenshot of malicious spam (malspam) with malware file attachment.

Traffic from the XLoader (Formbook) infection filtered in Wireshark.

Traffic from the XLoader (Formbook) infection filtered in Wireshark.

2024-11-22 (Friday) #XLoader / #Formbook: I've been fired by my non-existent HR department. At least I got a "salary-receipt.exe" bazaar.abuse.ch/sample/003b5...

Tria.ge and Any.Run don't identify the malware, but Joe Sandbox does: www.joesandbox.com/analysis/156...

Also runs in my lab just fine

22.11.2024 19:42 β€” πŸ‘ 17    πŸ” 10    πŸ’¬ 2    πŸ“Œ 0
Preview
Unraveling Raspberry Robin's Layers: Analyzing Obfuscation Techniques and Core Mechanisms A comprehensive analysis of the inner workings of Raspberry Robin | Multiple layers that use numerous techniques to evade detection & analysis

www.zscaler.com/blogs/securi.... This is very interesting :) Nice work Nik!

20.11.2024 02:30 β€” πŸ‘ 11    πŸ” 6    πŸ’¬ 0    πŸ“Œ 2
Post image

Since I'm trying out #Bluesky, I figured I should add in support for it in Unfurl!

The v2024.11.20 release has some minor updates, but the biggest feature is the ability to parse a timestamp from Bluesky post IDs (or atproto TIDs).

Example: dfir.blog/unfurl/?url=...

Give it a try at unfurl.link!

21.11.2024 04:19 β€” πŸ‘ 26    πŸ” 12    πŸ’¬ 0    πŸ“Œ 2

Here is a starter pack of SANS Instructors for all kinds of good infosec stuff.

I’m still collecting more names and will update this list as updated as possible.

go.bsky.app/Q7Sh3W1

17.11.2024 18:38 β€” πŸ‘ 36    πŸ” 10    πŸ’¬ 4    πŸ“Œ 2

Hi everyone! What is this BlueSky thing all about? I still think 300 characters is way too much for ppl, but I will give the benefit of the doubt. What are you folks up to? 😁

23.11.2024 01:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0