Microsoft Quick Assist is Under Attack: What You Need to Know
Microsoft Quick Assist is a great tool for streamlining IT support. Unfortunately, itโs also becoming a popular target for hackers trying to break into you...
Did you know there are ๐ญ๐ฐ๐จ ๐ฏ๐๐ซ๐ฌ๐ข๐จ๐ง๐ฌ ๐จ๐ ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ฎ๐ข๐๐ค ๐๐ฌ๐ฌ๐ข๐ฌ๐ญ, one of which doesn't log anything?
On ๐๐๐ด ๐ญ๐ฏ ๐ฎ๐ ๐ญ๐ฎ ๐ฃ๐ ๐๐ฆ๐ง, I am presenting on MSQA, how we're seeing it used in attacks. More importantly, how to perform investigations into MSQA.
๐
๐ซ๐๐ ๐ญ๐จ ๐๐ญ๐ญ๐๐ง๐ - register here:
ow.ly/TvlR50WxW5A
08.08.2025 13:36 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
YouTube video by BSidesROC
BSidesROC 2025 - Microsoft Quick Assist - Tyler Hudak
This past weekend I had the opportunity and speak at B-Sides Rochester (NY).
My talk was on forensically analyzing Microsoft Quick Assist and the issues associated with attempting to do so. If anyone is interested:
- Slides: github.com/secshoggoth/...
- Video: www.youtube.com/watch?v=l9Kq...
26.03.2025 12:39 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 0
Microsoft Quick Assist Remote Monitoring
Learn how attackers exploit Microsoft Quick Assist, a default Windows tool, in scams and social engineering attacks. Discover detection tips, analysis methods, and strategies to protect your business ...
I've had to analyze several MS Quick Assist compromises and found challenges during each one. Threat Hunting for malicious activity thru QA is not easy either.
So I wrote a blog post on what to look for: inversion6.com/resources/bl...
#dfir #forensics #incidentresponse #threathunting
29.01.2025 13:51 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
Inversion6 Launches Comprehensive Incident Response Service
Global cybersecurity firm launches expanded service to help companies respond and recover from cyber threats.
Today marks the official launch of the Inversion6 Incident Response (IR) team, and I couldn't be more excited! Ready to tackle challenges, protect, and respond like never before. Letโs go!
#IncidentResponse #CyberSecurity #DFIR
inversion6.com/resources/ne...
21.01.2025 14:48 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
My fallback plan is being a cranberry farmer or running a tiki bar in the Caribbean.
10.01.2025 17:30 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Now there is so much to learn and understand. Granted, there is also more training, free content, technology, and education. But in a way that may make it more overwhelming.
To anyone jumping into the depths of this ocean now, you have my sympathies but I also share your excitement. (2/2)
10.01.2025 14:49 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
I do not envy those coming into Information Security now.
When I started, there were no formal programs, no degrees, and little training. It was the wild west and we were making a lot of it up as we went. In a way, it was easier. (1/2)
10.01.2025 14:49 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Feels like an appropriate response to me.
10.01.2025 14:44 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
What is everyone's favorite place for a starting sysmon config template?
10.12.2024 18:08 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Save or ๐ฑ๐ผ๐ฐ๐๐บ๐ฒ๐ป๐ ๐๐ต๐ฒ๐ถ๐ฟ ๐บ๐ฒ๐๐๐ฎ๐ด๐ฒ๐ (screenshots, etc.) to help law enforcement if they are brought in.
๐๐ฒ๐ ๐ต๐ฒ๐น๐ฝ from someone you trust. Contact law enforcement. They can help stop this.
I know this may be embarrassing, but they have the resources to help you out.
13.11.2024 15:10 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
๐๐น๐ผ๐ฐ๐ธ ๐ฎ๐ป๐ฑ ๐ฟ๐ฒ๐ฝ๐ผ๐ฟ๐ ๐๐ต๐ฒ๐ถ๐ฟ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐.
They will try to message you on every platform they can find using different accounts.
Blocking and reporting them means its more likely their accounts will be taken down.
13.11.2024 15:10 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Don't send them anything and ๐ฑ๐ผ๐ป'๐ ๐ฝ๐ฎ๐ ๐๐ต๐ฒ๐บ ๐ฎ๐ป๐ ๐บ๐ผ๐ป๐ฒ๐.
If you pay them, it won't go away. They will just ask for more.
If you did pay them money, try to ๐ฟ๐ฒ๐๐ฒ๐ฟ๐๐ฒ ๐๐ต๐ฒ ๐๐ฟ๐ฎ๐ป๐๐ฎ๐ฐ๐๐ถ๐ผ๐ป. You may have to call your bank, but the faster you do it the more likely the reversal can happen.
13.11.2024 15:10 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Yesterday I received a call from a friend who was a victim of sextortion. This is all too common but fortunately there are things you can do if you fall victim to this.
Remember ๐๐ผ๐ ๐ฎ๐ฟ๐ฒ ๐ป๐ผ๐ ๐ฎ๐ ๐ณ๐ฎ๐๐น๐. The person doing this is truly one of the worst types of criminals. You are a victim.
๐งต
13.11.2024 15:10 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
What's one more social media site to check out?
13.11.2024 13:49 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
DFIR by day, DFIR by night.
Former vet tech.
Violinist, Salty, Tired, Meme Enthusiast.
The best deals on board games, card games, miniature games, RPGs and more!
Items marked with #ad are affiliate links and we earn from qualifying purchases.
Adversary Services @xforce
https://h4wkst3r.github.io
He/Him, chonky cis hetero white dude.
Infosec practitioner. Maker. Westie dad.
Eduard Bernstein socialist.
Prozac user. Benzo beneficiary.
Despite my staggering lack of ambition and drive I have landed in a pretty good place in life
Security researcher with a camera | @FalconForce.nl | Microsoft MVP | Snow man role model | https://youtube.com/@olafhartong
SANS Fellow, CTO of Backshore Communications, GIAC GSE #13, SABR member, golden age arcade restorer. Peaks Island, Maine
Infosec pro gone with a broad profile. I try to post mostly infosec and not politics. Hard task. Posts are my own. Get in touch.
DFIR, security, networking, all things tech, OneWheel, Radinn, travel, LEGO, and probably a whole lot more in small and sporadic bits. (Squirrel!)
Fierce and unapologetic ally. He/him/his.
- Cybersecurity since 1998
- Information Security jack of all trades
- Hacker
https://www.darkoperator.com
Blue teamer, defensive security, digital forensics, incident response, personal productivity, GTD, paperless, metalhead. ๐ธ๐ช
Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, PacketCache, #PolarProxy and RawCap.
Website: https://www.netresec.com/
Mastodon: @netresec@infosec.exchange
Penetration Testing, Red Teaming, Incident Response, Managed Detection, Digital Forensics, Security Training, Managed Bug Bounty, Cyber Training Range
Security Research, Threat Intelligence, Malware Analysis, Embedded Systems, Misc. Hackery and Shenanigans.
Infosec enthusiast. Pop culture junkie. Rebel Scum, apparently. Carl Sagan fan, floating around on this pale blue dot. Bodily autonomy couldnโt be more fundamentally important to protect at all costs. Pro-choice. Ally. #resist
Security Researcher, DFIR, Intel, and cats.
Sr. Director of SOC at Huntress. Ex-Mandiant/FireEye. Bringing security to the Fortune 5,000,000.
I enjoy security, technology, learning, books, & the great outdoors.
Trying to be human & kind.
Opinions = mine. He/Him/Hรคn
https://github.com/JimSycurity
https://www.adminsdholder.com
ใใใฏ่ไบบใFriends with Brews podcast. My cat is my hero. Law doesn't matter if no one enforces it.
Mastodon: https://social.lol/@scottwillsey
Web: https://scottwillsey.com
Podcast: https://friendswithbrews.com