Date | Title |
---|
2020-12-31 | End of Year Traffic Analysis Quiz |
2020-11-30 | Decrypting PowerShell Payloads (video) |
2020-12-30 | TLS 1.3 is now supported by about 1 in every 5 HTTPS servers |
2020-12-30 | ISC Stormcast For Wednesday, December 30th 2020 |
2020-12-29 | Want to know what's in a folder you don't have a permission to access? Try asking your AV solution... |
2020-12-29 | ISC Stormcast For Tuesday, December 29th 2020 |
2020-12-28 | ISC Stormcast For Monday, December 28th 2020 |
2020-12-27 | Quickie: Bit Shifting With translate.py |
2020-12-26 | base64dump.py Supported Encodings |
2020-12-25 | Quickie: String Analysis & Maldocs |
2020-12-24 | Malicious Word Document Delivering an Octopus Backdoor |
2020-12-23 | Analysis Dridex Dropper, IoC extraction (guest diary) |
2020-12-23 | ISC Stormcast For Wednesday, December 23rd 2020 |
2020-12-22 | ISC Stormcast For Tuesday, December 22nd 2020 |
2020-12-22 | Malware Victim Selection Through WiFi Identification |
2020-12-21 | What's the deal with openportstats.com? |
2020-12-21 | ISC Stormcast For Monday, December 21st 2020 |
2020-12-20 | Heads-up: VirusTotal Functionality in Sysinternals Tools Not Working |
2020-12-20 | Wireshark 3.4.2 Released |
2020-12-19 | Secure Communication using TLS in Elasticsearch |
2020-12-18 | A slightly optimistic tale of how patching went for CVE-2019-19781 |
2020-12-18 | ISC Stormcast For Friday, December 18th 2020 |
2020-12-17 | "Amazon" invoice that asks to call 1-866-335-0659 "to cancel" an order that you never made is (obviously) a #scam |
2020-12-17 | ISC Stormcast For Thursday, December 17th 2020 |
2020-12-16 | DNS Logs in Public Clouds |
2020-12-16 | ISC Stormcast For Wednesday, December 16th 2020 |
2020-12-15 | ISC Stormcast For Tuesday, December 15th 2020 |
2020-12-15 | Analyzing FireEye Maldocs |
2020-12-14 | ISC Stormcast For Monday, December 14th 2020 |
2020-12-14 | SolarWinds Breach Used to Infiltrate Customer Networks (Solarigate) |
2020-12-13 | KringleCon 2020 |
2020-12-13 | Wireshark 3.4.1 Released |
2020-12-12 | Office 95 Excel 4 Macros |
2020-12-11 | Cisco Jabber Desktop and Mobile Security Advisory Published (CVSS: 9.9): |
2020-12-11 | ISC Stormcast For Friday, December 11th 2020 |
2020-12-10 | Writing Yara Rules for Fun and Profit: Notes from the FireEye Breach Countermeasures |
2020-12-10 | ISC Stormcast For Thursday, December 10th 2020 |
2020-12-10 | Python Backdoor Talking to a C2 Through Ngrok |
2020-12-09 | ISC Stormcast For Wednesday, December 9th 2020 |
2020-12-09 | Recent Qakbot (Qbot) activity |
2020-12-08 | December 2020 Microsoft Patch Tuesday: Exchange, Sharepoint, Dynamics and DNS Spoofing |
2020-12-08 | ISC Stormcast For Tuesday, December 8th 2020 |
2020-12-07 | ISC Stormcast For Monday, December 7th 2020 |
2020-12-07 | Corrupt BASE64 Strings: Detection and Decoding |
2020-12-06 | oledump's Indicators (video) |
2020-12-05 | Is IP 91.199.118.137 testing Access to aahwwx.52host.xyz? |
2020-12-04 | ISC Stormcast For Friday, December 4th 2020 |
2020-12-04 | Detecting Actors Activity with Threat Intel |
2020-12-03 | ISC Stormcast For Thursday, December 3rd 2020 |
2020-12-03 | Traffic Analysis Quiz: Mr Natural |
2020-12-02 | ISC Stormcast For Wednesday, December 2nd 2020 |
2020-12-01 | ISC Stormcast For Tuesday, December 1st 2020 |
2020-11-30 | ISC Stormcast For Monday, November 30th 2020 |
2020-11-29 | Quick Tip: Using JARM With a SOCKS Proxy |
2020-11-27 | Threat Hunting with JARM |
2020-11-25 | ISC Stormcast For Wednesday, November 25th 2020 |
2020-11-25 | Live Patching Windows API Calls Using PowerShell |
2020-11-24 | The special case of TCP RST |
2020-11-24 | ISC Stormcast For Tuesday, November 24th 2020 |
2020-11-23 | ISC Stormcast For Monday, November 23rd 2020 |
2020-11-23 | Quick Tip: Cobalt Strike Beacon Analysis |
2020-11-22 | Quick Tip: Extracting all VBA Code from a Maldoc - JSON Format |
2020-11-21 | VMware privilege escalation vulnerabilities (CVE-2020-4004, CVE-2020-4005) - |
2020-11-20 | Malicious Python Code and LittleSnitch Detection |
2020-11-20 | ISC Stormcast For Friday, November 20th 2020 |
2020-11-19 | ISC Stormcast For Thursday, November 19th 2020 |
2020-11-19 | PowerShell Dropper Delivering Formbook |
2020-11-18 | When Security Controls Lead to Security Issues |
2020-11-18 | ISC Stormcast For Wednesday, November 18th 2020 |
2020-11-17 | ISC Stormcast For Tuesday, November 17th 2020 |
2020-11-16 | Heartbleed, BlueKeep and other vulnerabilities that didn't disappear just because we don't talk about them anymore |
2020-11-16 | ISC Stormcast For Monday, November 16th 2020 |
2020-11-15 | oledump's ! Indicator |
2020-11-13 | Old Worm But New Obfuscation Technique |
2020-11-13 | ISC Stormcast For Friday, November 13th 2020 |
2020-11-12 | ISC Stormcast For Thursday, November 12th 2020 |
2020-11-12 | Preventing Exposed Azure Blob Storage |
2020-11-12 | Exposed Blob Storage in Azure |
2020-11-11 | ISC Stormcast For Wednesday, November 11th 2020 |
2020-11-11 | Traffic Analysis Quiz: DESKTOP-FX23IK5 |
2020-11-10 | Microsoft November 2020 Patch Tuesday |
2020-11-10 | ISC Stormcast For Tuesday, November 10th 2020 |
2020-11-09 | ISC Stormcast For Monday, November 9th 2020 |
2020-11-09 | How Attackers Brush Up Their Malicious Scripts |
2020-11-08 | Quick Tip: Extracting all VBA Code from a Maldoc |
2020-11-07 | Cryptojacking Targeting WebLogic TCP/7001 |
2020-11-06 | Rediscovering Limitations of Stateful Firewalls: "NAT Slipstreaming" ? Implications, Detections and Mitigations |
2020-11-06 | ISC Stormcast For Friday, November 6th 2020 |
2020-11-05 | Did You Spot "Invoke-Expression"? |
2020-11-05 | ISC Stormcast For Thursday, November 5th 2020 |
2020-11-04 | ISC Stormcast For Wednesday, November 4th 2020 |
2020-11-03 | ISC Stormcast For Tuesday, November 3rd 2020 |
2020-11-03 | Attackers Exploiting WebLogic Servers via CVE-2020-14882 to install Cobalt Strike |
2020-11-03 | Emotet -> Qakbot -> more Emotet |
2020-11-02 | ISC Stormcast For Monday, November 2nd 2020 |
2020-11-02 | AV Cleaned Maldoc |
2020-11-01 | Wireshark 3.2.8 and 3.4.0 Released |
2020-10-31 | More File Selection Gaffes |
2020-10-30 | ISC Stormcast For Friday, October 30th 2020 |
2020-10-30 | Quick Status of the CAA DNS Record Adoption |
2020-10-29 | ISC Stormcast For Thursday, October 29th 2020 |
2020-10-29 | PATCH NOW: CVE-2020-14882 Weblogic Actively Exploited Against Honeypots |
2020-10-28 | SMBGhost - the critical vulnerability many seem to have forgotten to patch |
2020-10-28 | ISC Stormcast For Wednesday, October 28th 2020 |
2020-10-27 | ISC Stormcast For Tuesday, October 27th 2020 |
2020-10-26 | Excel 4 Macros: "Abnormal Sheet Visibility" |
2020-10-26 | ISC Stormcast For Monday, October 26th 2020 |
2020-10-25 | Video: Pascal Strings |
2020-10-24 | An Alternative to Shodan, Censys with User-Agent CensysInspect/1.1 |
2020-10-23 | Russian State-Sponsored APT Actor Compromises U.S. Gov Targets |
2020-10-23 | Sooty: SOC Analyst's All-in-One Tool |
2020-10-23 | ISC Stormcast For Friday, October 23rd 2020 |
2020-10-22 | BazarLoader phishing lures: plan a Halloween party, get a bonus and be fired in the same afternoon |
2020-10-22 | ISC Stormcast For Thursday, October 22nd 2020 |
2020-10-21 | 20 new Cisco security advisories for ASA and Firepower with CVSS>7: |
2020-10-21 | ISC Stormcast For Wednesday, October 21st 2020 |
2020-10-21 | Shipping dangerous goods |
2020-10-20 | ISC Stormcast For Tuesday, October 20th 2020 |
2020-10-20 | Mirai-alike Python Scanner |
2020-10-19 | ISC Stormcast For Monday, October 19th 2020 |
2020-10-18 | File Selection Gaffe |
2020-10-17 | CVE-2020-5135 - Buffer Overflow in SonicWall VPNs - Patch Now |
2020-10-16 | CVE-2020-3991 VMWare Security Advisory for VMWare Horizon Client - |
2020-10-16 | Traffic Analysis Quiz: Ugly-Wolf.net |
2020-10-16 | ISC Stormcast For Friday, October 16th 2020 |
2020-10-15 | CVE-2020-16898: Windows ICMPv6 Router Advertisement RRDNS Option Remote Code Execution Vulnerability |
2020-10-15 | ISC Stormcast For Thursday, October 15th 2020 |
2020-10-14 | Nicely Obfuscated Python RAT |
2020-10-14 | ISC Stormcast For Wednesday, October 14th 2020 |
2020-10-14 | More TA551 (Shathak) Word docs push IcedID (Bokbot) |
2020-10-13 | Microsoft October 2020 Patch Tuesday |
2020-10-13 | ISC Stormcast For Tuesday, October 13th 2020 |
2020-10-12 | Nested .MSGs: Turtles All The Way Down |
2020-10-12 | ISC Stormcast For Monday, October 12th 2020 |
2020-10-11 | Analyzing MSG Files With plugin_msg_summary |
2020-10-10 | Open Packaging Conventions |
2020-10-09 | Phishing kits as far as the eye can see |
2020-10-09 | ISC Stormcast For Friday, October 9th 2020 |
2020-10-08 | ISC Stormcast For Thursday, October 8th 2020 |
2020-10-07 | Today, Nobody is Going to Attack You. |
2020-10-07 | ISC Stormcast For Wednesday, October 7th 2020 |
2020-10-06 | ISC Stormcast For Tuesday, October 6th 2020 |
2020-10-05 | Obfuscation and Repetition |
2020-10-05 | ISC Stormcast For Monday, October 5th 2020 |
2020-10-04 | Nmap 7.90 Released |
2020-10-03 | Scanning for SOHO Routers |
2020-10-02 | ISC Stormcast For Friday, October 2nd 2020 |
2020-10-02 | Analysis of a Phishing Kit |
2020-10-01 | ISC Stormcast For Thursday, October 1st 2020 |
2020-10-01 | Making sense of Azure AD (AAD) activity logs |
2020-10-01 | IOC's turning into IOOI's |
2020-09-30 | Scans for FPURL.xml: Reconnaissance or Not? |
2020-09-30 | ISC Stormcast For Wednesday, September 30th 2020 |
2020-09-29 | Managing Remote Access for Partners & Contractors |
2020-09-29 | ISC Stormcast For Tuesday, September 29th 2020 |
2020-09-28 | Some Tyler Technologies Customers Targeted with The Installation of a Bomgar Client |
2020-09-28 | ISC Stormcast For Monday, September 28th 2020 |
2020-09-28 | PowerShell Backdoor Launched from a ShellCode |
2020-09-27 | Decoding Corrupt BASE64 Strings |
2020-09-27 | Wireshark 3.2.7 Released |
2020-09-25 | Securing Exchange Online [Guest Diary] |
2020-09-25 | ISC Stormcast For Friday, September 25th 2020 |
2020-09-24 | ISC Stormcast For Thursday, September 24th 2020 |
2020-09-24 | Party in Ibiza with PowerShell |
2020-09-23 | ISC Stormcast For Wednesday, September 23rd 2020 |
2020-09-23 | Malicious Word Document with Dynamic Content |
2020-09-22 | ISC Stormcast For Tuesday, September 22nd 2020 |
2020-09-21 | Slightly broken overlay phishing |
2020-09-21 | ISC Stormcast For Monday, September 21st 2020 |
2020-09-20 | Analysis of a Salesforce Phishing Emails |
2020-09-18 | ISC Stormcast For Friday, September 18th 2020 |
2020-09-18 | A Mix of Python & VBA in a Malicious Word Document |
2020-09-17 | Suspicious Endpoint Containment with OSSEC |
2020-09-17 | ISC Stormcast For Thursday, September 17th 2020 |
2020-09-16 | Do Vulnerabilities Ever Get Old? Recent "Mirai" Variant Scanning for 20 Year Old Amanda Version? |
2020-09-16 | ISC Stormcast For Wednesday, September 16th 2020 |
2020-09-15 | ISC Stormcast For Tuesday, September 15th 2020 |
2020-09-15 | Traffic Analysis Quiz: Oh No... Another Infection! |
2020-09-14 | Not Everything About ".well-known" is Well Known |
2020-09-14 | ISC Stormcast For Monday, September 14th 2020 |
2020-09-13 | Creating patched binaries for pentesting purposes |
2020-09-12 | Office Documents with Embedded Objects |
2020-09-11 | What's in Your Clipboard? Pillaging and Protecting the Clipboard |
2020-09-11 | ISC Stormcast For Friday, September 11th 2020 |
2020-09-10 | ISC Stormcast For Thursday, September 10th 2020 |
2020-09-10 | Recent Dridex activity |
2020-09-09 | A First Look at macOS 11 Big Sur Network Traffic (New! Now with more GREASE!) |
2020-09-09 | ISC Stormcast For Wednesday, September 9th 2020 |
2020-09-08 | Microsoft September 2020 Patch Tuesday |
2020-09-08 | ISC Stormcast For Tuesday, September 8th 2020 |
2020-09-07 | Office: About OLE and ZIP Files |
2020-09-04 | A blast from the past - XXEncoded VB6.0 Trojan |
2020-09-04 | ISC Stormcast For Friday, September 4th 2020 |
2020-09-03 | Sandbox Evasion Using NTP |
2020-09-03 | ISC Stormcast For Thursday, September 3rd 2020 |
2020-09-02 | Python and Risky Windows API Calls |
2020-09-02 | ISC Stormcast For Wednesday, September 2nd 2020 |
2020-09-01 | Exposed Windows Domain Controllers Used in CLDAP DDoS Attacks |
2020-09-01 | ISC Stormcast For Tuesday, September 1st 2020 |
2020-08-31 | ISC Stormcast For Monday, August 31st 2020 |
2020-08-31 | Finding The Original Maldoc |
2020-08-30 | CenturyLink Outage Causing Internet Wide Problems |
2020-08-29 | Malicious Excel Sheet with a NULL VT Score: More Info |
2020-08-28 | ISC Stormcast For Friday, August 28th 2020 |
2020-08-28 | Example of Malicious DLL Injected in PowerShell |
2020-08-27 | Security.txt - one small file for an admin, one giant help to a security researcher |
2020-08-27 | ISC Stormcast For Thursday, August 27th 2020 |
2020-08-26 | Malicious Excel Sheet with a NULL VT Score |
2020-08-26 | ISC Stormcast For Wednesday, August 26th 2020 |
2020-08-25 | Keep An Eye on LOLBins |
2020-08-25 | ISC Stormcast For Tuesday, August 25th 2020 |
2020-08-24 | Tracking A Malware Campaign Through VT |
2020-08-24 | ISC Stormcast For Monday, August 24th 2020 |
2020-08-23 | Small Challenge: A Simple Word Maldoc - Part 4 |
2020-08-22 | Remote Desktop (TCP/3389) and Telnet (TCP/23), What might they have in Common? |
2020-08-22 | VMware App Volumes patches address Stored Cross-Site Scripting (XSS) vulnerability - |
2020-08-21 | ISC Stormcast For Friday, August 21st 2020 |
2020-08-20 | ISC Stormcast For Thursday, August 20th 2020 |
2020-08-20 | Office 365 Mail Forwarding Rules (and other Mail Rules too) |
2020-08-19 | Example of Word Document Delivering Qakbot |
2020-08-19 | ISC Stormcast For Wednesday, August 19th 2020 |
2020-08-18 | ISC Stormcast For Tuesday, August 18th 2020 |
2020-08-18 | ISC Blocked |
2020-08-18 | Using API's to Track Attackers |
2020-08-17 | Password Reuse Strikes Again! |
2020-08-17 | ISC Stormcast For Monday, August 17th 2020 |
2020-08-16 | Small Challenge: A Simple Word Maldoc - Part 3 |
2020-08-15 | Wireshark 3.2.6 Released |
2020-08-14 | Definition of 'overkill' - using 130 MB executable to hide 24 kB malware |
2020-08-14 | ISC Stormcast For Friday, August 14th 2020 |
2020-08-13 | ISC Stormcast For Thursday, August 13th 2020 |
2020-08-12 | Wireshark 3.2.6 released, Kafka dissector crash repaired: |
2020-08-12 | To the Brim at the Gates of Mordor Pt. 1 |
2020-08-12 | ISC Stormcast For Wednesday, August 12th 2020 |
2020-08-11 | Microsoft August 2020 Patch Tuesday |
2020-08-11 | ISC Stormcast For Tuesday, August 11th 2020 |
2020-08-10 | Scoping web application and web service penetration tests |
2020-08-10 | ISC Stormcast For Monday, August 10th 2020 |
2020-08-09 | Small Challenge: A Simple Word Maldoc - Part 2 |
2020-08-08 | Scanning Activity Include Netcat Listener |
2020-08-07 | ISC Stormcast For Friday, August 7th 2020 |
2020-08-07 | TA551 (Shathak) Word docs push IcedID (Bokbot) |
2020-08-06 | ISC Stormcast For Thursday, August 6th 2020 |
2020-08-06 | A Fork of the FTCode Powershell Ransomware |
2020-08-05 | ISC Stormcast For Wednesday, August 5th 2020 |
2020-08-05 | Traffic Analysis Quiz: What's the Malware From This Infection? |
2020-08-04 | Internet Choke Points: Concentration of Authoritative Name Servers |
2020-08-04 | Reminder: Patch Cisco ASA / FTD Devices (CVE-2020-3452). Exploitation Continues |
2020-08-04 | ISC Stormcast For Tuesday, August 4th 2020 |
2020-08-03 | A Word of Caution: Helping Out People Being Stalked Online |
2020-08-03 | Powershell Bot with Multiple C2 Protocols |
2020-08-03 | ISC Stormcast For Monday, August 3rd 2020 |
2020-08-02 | Small Challenge: A Simple Word Maldoc |
2020-08-01 | What pages do bad bots look for? |
2020-07-31 | Building a .freq file with Public Domain Data Sources |
2020-07-31 | ISC Stormcast For Friday, July 31st 2020 |
2020-07-30 | Python Developers: Prepare!!! |
2020-07-30 | ISC Stormcast For Thursday, July 30th 2020 |
2020-07-29 | Consumer VPNs: You May Be Fine Without |
2020-07-29 | ISC Stormcast For Wednesday, July 29th 2020 |
2020-07-28 | All I want this Tuesday: More Data |
2020-07-28 | ISC Stormcast For Tuesday, July 28th 2020 |
2020-07-27 | In Memory of Donald Smith |
2020-07-27 | ISC Stormcast For Monday, July 27th 2020 |
2020-07-27 | Analyzing Metasploit ASP .NET Payloads |
2020-07-26 | Cracking Maldoc VBA Project Passwords |
2020-07-25 | ndisasm Update 2.15 |
2020-07-24 | ISC Stormcast For Friday, July 24th 2020 |
2020-07-24 | Compromized Desktop Applications by Web Technologies |
2020-07-23 | ISC Stormcast For Thursday, July 23rd 2020 |
2020-07-23 | Simple Blocklisting with MISP & pfSense |
2020-07-22 | A few IoCs related to CVE-2020-5902 |
2020-07-22 | ISC Stormcast For Wednesday, July 22nd 2020 |
2020-07-21 | Couple of interesting Covid-19 related stats |
2020-07-21 | ISC Stormcast For Tuesday, July 21st 2020 |
2020-07-20 | ISC Stormcast For Monday, July 20th 2020 |
2020-07-20 | Sextortion Update: The Final Final Chapter |
2020-07-19 | Scanning Activity for ZeroShell Unauthenticated Access |
2020-07-18 | Zone.Identifier: A Couple Of Observations |
2020-07-17 | ISC Stormcast For Friday, July 17th 2020 |
2020-07-16 | Hunting for SigRed Exploitation |
2020-07-16 | Apple Releases Security Update 2020-04 for iOS, patches some arbitrary code execution flaws. More here: |
2020-07-16 | ISC Stormcast For Thursday, July 16th 2020 |
2020-07-15 | PATCH NOW - SIGRed - CVE-2020-1350 - Microsoft DNS Server Vulnerability |
2020-07-15 | ISC Stormcast For Wednesday, July 15th 2020 |
2020-07-15 | Word docs with macros for IcedID (Bokbot) |
2020-07-14 | Microsoft July 2020 Patch Tuesday - Patch Now! |
2020-07-14 | ISC Stormcast For Tuesday, July 14th 2020 |
2020-07-13 | VBA Project Passwords |
2020-07-13 | ISC Stormcast For Monday, July 13th 2020 |
2020-07-12 | Maldoc: VBA Purging Example |
2020-07-11 | Scanning Home Internet Facing Devices to Exploit |
2020-07-11 | VMware XPC Client validation privilege escalation vulnerability - |
2020-07-10 | ISC Stormcast For Friday, July 10th 2020 |
2020-07-10 | Excel spreasheet macro kicks off Formbook infection |
2020-07-09 | Active Exploit Attempts Targeting Recent Citrix ADC Vulnerabilities CTX276688 |
2020-07-09 | ISC Stormcast For Thursday, July 9th 2020 |
2020-07-08 | ISC Stormcast For Wednesday, July 8th 2020 |
2020-07-08 | If You Want Something Done Right, You Have To Do It Yourself... Malware Too! |
2020-07-07 | Happy Birthday DShield: DShield.org was registered 20 years ago. |
2020-07-07 | F5 BigIP vulnerability exploitation followed by a backdoor implant attempt |
2020-07-07 | ISC Stormcast For Tuesday, July 7th 2020 |
2020-07-06 | Summary of CVE-2020-5902 F5 BIG-IP RCE Vulnerability Exploits |
2020-07-06 | CVE-2020-5902: F5 BIG-IP RCE Vulnerability |
2020-07-06 | ISC Stormcast For Monday, July 6th 2020 |
2020-07-05 | CVE-2020-5902 F5 BIG-IP Exploitation Attempt |
2020-07-05 | Wireshark 3.2.5 Released |
2020-07-04 | Happy FouRth of July from the Internet Storm Center |
2020-07-02 | ISC Stormcast For Thursday, July 2nd 2020 |
2020-07-01 | Setting up the Dshield honeypot and tcp-honeypot.py |
2020-07-01 | Elastalert with Sigma |
2020-07-01 | ISC Stormcast For Wednesday, July 1st 2020 |
2020-06-30 | ISC Snapshot: SpectX IP Hitcount Query |
2020-06-30 | ISC Stormcast For Tuesday, June 30th 2020 |
2020-06-29 | Sysmon and Alternate Data Streams |
2020-06-29 | ISC Stormcast For Monday, June 29th 2020 |
2020-06-28 | tcp-honeypot.py Logstash Parser & Dashboard Update |
2020-06-27 | Video: YARA's BASE64 Strings |
2020-06-26 | Share the Mic in Cyber |
2020-06-26 | ISC Stormcast For Friday, June 26th 2020 |
2020-06-25 | Tech Tuesday Recap / Recordings: Part 2 (Installing the Honeypot) release. |
2020-06-25 | ISC Stormcast For Thursday, June 25th 2020 |
2020-06-24 | Using Shell Links as zero-touch downloaders and to initiate network connections |
2020-06-24 | VMware security advisory VMSA-2020-0015 |
2020-06-24 | ISC Stormcast For Wednesday, June 24th 2020 |
2020-06-23 | ISC Stormcast For Tuesday, June 23rd 2020 |
2020-06-22 | Comparing Office Documents with WinMerge |
2020-06-22 | Cyberbunker 2.0: Analysis of the Remnants of a Bullet Proof Hosting Provider |
2020-06-22 | ISC Stormcast For Monday, June 22nd 2020 |
2020-06-21 | ISC Handler Series: SANS@MIC - Maldocs: a bit of blue, a bit of red |
2020-06-20 | Pi Zero HoneyPot |
2020-06-19 | Sigma rules! The generic signature format for SIEM systems. |
2020-06-19 | ISC Stormcast For Friday, June 19th 2020 |
2020-06-18 | Broken phishing accidentally exploiting Outlook zero-day |
2020-06-18 | ISC Stormcast For Thursday, June 18th 2020 |
2020-06-17 | ISC Stormcast For Wednesday, June 17th 2020 |
2020-06-16 | Odd "Protest" Spam (Scam?) Targeting Atlanta Police Foundation |
2020-06-16 | ISC Stormcast For Tuesday, June 16th 2020 |
2020-06-16 | Sextortion to The Next Level |
2020-06-15 | HTML based Phishing Run |
2020-06-15 | VMWare Security Advisory - VMSA-2020-0013 - |
2020-06-15 | ISC Stormcast For Monday, June 15th 2020 |
2020-06-14 | YARA's BASE64 Strings |
2020-06-13 | Mirai Botnet Activity |
2020-06-12 | Malicious Excel Delivering Fileless Payload |
2020-06-12 | ISC Stormcast For Friday, June 12th 2020 |
2020-06-11 | Anti-Debugging JavaScript Techniques |
2020-06-11 | ISC Stormcast For Thursday, June 11th 2020 |
2020-06-10 | ISC Stormcast For Wednesday, June 10th 2020 |
2020-06-10 | Job application-themed malspam pushes ZLoader |
2020-06-09 | Microsoft June 2020 Patch Tuesday |
2020-06-09 | ISC Stormcast For Tuesday, June 9th 2020 |
2020-06-08 | Translating BASE64 Obfuscated Scripts |
2020-06-08 | ISC Stormcast For Monday, June 8th 2020 |
2020-06-05 | Cyber Security for Protests |
2020-06-05 | Not so FastCGI! |
2020-06-05 | ISC Stormcast For Friday, June 5th 2020 |
2020-06-04 | Suspending Suspicious Domain Feed / Update to Researcher IP Feed |
2020-06-04 | ISC Stormcast For Thursday, June 4th 2020 |
2020-06-04 | Anti-Debugging Technique based on Memory Protection |
2020-06-04 | Polish malspam pushes ZLoader malware |
2020-06-03 | ISC Stormcast For Wednesday, June 3rd 2020 |
2020-06-02 | ISC Stormcast For Tuesday, June 2nd 2020 |
2020-06-01 | Stackstrings, type 2 |
2020-06-01 | XLMMacroDeobfuscator: An Update |
2020-06-01 | ISC Stormcast For Monday, June 1st 2020 |
2020-05-31 | Windows 10 Built-in Packet Sniffer - PktMon |
2020-05-30 | YARA v4.0.1 |
2020-05-29 | The Impact of Researchers on Our Data |
2020-05-29 | ISC Stormcast For Friday, May 29th 2020 |
2020-05-28 | Flashback on CVE-2019-19781 |
2020-05-28 | ISC Stormcast For Thursday, May 28th 2020 |
2020-05-27 | Frankenstein's phishing using Google Cloud Storage |
2020-05-27 | ISC Stormcast For Wednesday, May 27th 2020 |
2020-05-26 | Seriously, SHA3 where art thou? |
2020-05-26 | ISC Stormcast For Tuesday, May 26th 2020 |
2020-05-24 | Zloader Maldoc Analysis With xlm-deobfuscator |
2020-05-24 | Wireshark 3.2.4 Released |
2020-05-23 | AgentTesla Delivered via a Malicious PowerPoint Add-In |
2020-05-22 | Some Strings to Remember |
2020-05-22 | ISC Stormcast For Friday, May 22nd 2020 |
2020-05-21 | Malware Triage with FLOSS: API Calls Based Behavior |
2020-05-21 | ISC Stormcast For Thursday, May 21st 2020 |
2020-05-20 | ISC Stormcast For Wednesday, May 20th 2020 |
2020-05-20 | Microsoft Word document with malicious macro pushes IcedID (Bokbot) |
2020-05-19 | VMWare Security Advisory - VMSA-2020-0010 - |
2020-05-19 | Wireshark Release - 2.6.17, 3.0.11 and 3.2.4 - |
2020-05-19 | What is up on Port 62234? |
2020-05-19 | Cisco Advisories for FTD, ASA, Firepower 1000 |
2020-05-19 | ISC Stormcast For Tuesday, May 19th 2020 |
2020-05-18 | Automating nmap scans |
2020-05-18 | ISC Stormcast For Monday, May 18th 2020 |
2020-05-17 | Antivirus & Multiple Detections |
2020-05-16 | Scanning for Outlook Web Access (OWA) & Microsoft Exchange Control Panel (ECP) |
2020-05-15 | SHA3 Hashes (on Windows) - Where Art Thou? |
2020-05-15 | Hashes in PowerShell |
2020-05-15 | ISC Stormcast For Friday, May 15th 2020 |
2020-05-14 | Patch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe |
2020-05-14 | Base Conversions and Creating GUI Apps in PowerShell |
2020-05-14 | ISC Stormcast For Thursday, May 14th 2020 |
2020-05-13 | ISC Stormcast For Wednesday, May 13th 2020 |
2020-05-13 | Malspam with links to zip archives pushes Dridex malware |
2020-05-12 | Microsoft May 2020 Patch Tuesday |
2020-05-12 | ISC Stormcast For Tuesday, May 12th 2020 |
2020-05-11 | Excel 4 Macro Analysis: XLMMacroDeobfuscator |
2020-05-11 | ISC Stormcast For Monday, May 11th 2020 |
2020-05-10 | YARA v4.0.0: BASE64 Strings |
2020-05-09 | Nmap Basics - The Security Practitioner's Swiss Army Knife |
2020-05-09 | VMWare vRealize Critical vulnerabilities due to SaltStack - VMSA-2020-0009 |
2020-05-08 | ISC Stormcast For Friday, May 8th 2020 |
2020-05-08 | Using Nmap As a Lightweight Vulnerability Scanner |
2020-05-07 | Scanning with nmap?s NSE scripts |
2020-05-07 | ISC Stormcast For Thursday, May 7th 2020 |
2020-05-06 | Keeping an Eye on Malicious Files Life Time |
2020-05-06 | ISC Stormcast For Wednesday, May 6th 2020 |
2020-05-05 | Cloud Security Features Don't Replace the Need for Personnel Security Capabilities |
2020-05-05 | ISC Stormcast For Tuesday, May 5th 2020 |
2020-05-04 | Sysmon and File Deletion |
2020-05-04 | ISC Stormcast For Monday, May 4th 2020 |
2020-05-03 | ZIP & AES |
2020-05-02 | Phishing PDF with Unusual Hostname |
2020-05-01 | ISC Stormcast For Friday, May 1st 2020 |
2020-05-01 | Attack traffic on TCP port 9673 |
2020-04-30 | ISC Stormcast For Thursday, April 30th 2020 |
2020-04-30 | Collecting IOCs from IMAP Folder |
2020-04-29 | Privacy Preserving Protocols to Trace Covid19 Exposure |
2020-04-29 | ISC Stormcast For Wednesday, April 29th 2020 |
2020-04-28 | Agent Tesla delivered by the same phishing campaign for over a year |
2020-04-28 | ISC Stormcast For Tuesday, April 28th 2020 |
2020-04-27 | Powershell Payload Stored in a PSCredential Object |
2020-04-27 | ISC Stormcast For Monday, April 27th 2020 |
2020-04-26 | Video: Malformed .docm File |
2020-04-25 | MALWARE Bazaar |
2020-04-24 | ISC Stormcast For Friday, April 24th 2020 |
2020-04-24 | Malicious Excel With a Strong Obfuscation and Sandbox Evasion |
2020-04-23 | ISC Stormcast For Thursday, April 23rd 2020 |
2020-04-22 | ISC Stormcast For Wednesday, April 22nd 2020 |
2020-04-21 | ISC Stormcast For Tuesday, April 21st 2020 |
2020-04-21 | SpectX: Log Parser for DFIR |
2020-04-20 | ISC Stormcast For Monday, April 20th 2020 |
2020-04-20 | KPOT AutoIt Script: Analysis |
2020-04-19 | KPOT Analysis: Obtaining the Decrypted KPOT EXE |
2020-04-18 | Maldoc Falsely Represented as DOCX Invoice Redirecting to Fake Apple Store |
2020-04-17 | ISC Stormcast For Friday, April 17th 2020 |
2020-04-17 | Weaponized RTF Document Generator & Mailer in PowerShell |
2020-04-16 | Using AppLocker to Prevent Living off the Land Attacks |
2020-04-16 | ISC Stormcast For Thursday, April 16th 2020 |
2020-04-15 | No IOCs? No Problem! Getting a Start Hunting for Malicious Office Files (10 Comments) |
2020-04-15 | ISC Stormcast For Wednesday, April 15th 2020 |
2020-04-14 | Microsoft April 2020 Patch Tuesday |
2020-04-14 | ISC Stormcast For Tuesday, April 14th 2020 |
2020-04-13 | Look at the same phishing campaign 3 months apart |
2020-04-13 | ISC Stormcast For Monday, April 13th 2020 |
2020-04-12 | Reader Analysis: "Dynamic analysis technique to get decrypted KPOT Malware." |
2020-04-11 | Wireshark 3.2.3 Released: Mac Users Pay Attention Please |
2020-04-10 | Critical Vuln in vCenter vmdir (CVE-2020-3952) |
2020-04-10 | PowerShell Sample Extracting Payload From SSL |
2020-04-10 | ISC Stormcast For Friday, April 10th 2020 |
2020-04-09 | ISC Stormcast For Thursday, April 9th 2020 |
2020-04-08 | ISC Stormcast For Wednesday, April 8th 2020 |
2020-04-08 | German malspam pushes ZLoader malware |
2020-04-07 | Increase in RDP Scanning |
2020-04-07 | ISC Stormcast For Tuesday, April 7th 2020 |
2020-04-06 | Password Protected Malicious Excel Files |
2020-04-06 | ISC Stormcast For Monday, April 6th 2020 |
2020-04-05 | Maldoc XLS Invoice with Excel 4 Macros |
2020-04-04 | New Bypass Technique or Corrupt Word Document? |
2020-04-03 | Obfuscated with a Simple 0x0A |
2020-04-03 | ISC Stormcast For Friday, April 3rd 2020 |
2020-04-02 | ISC Stormcast For Thursday, April 2nd 2020 |
2020-04-02 | TPOT's Cowrie to ISC Logs |
2020-04-01 | ISC Stormcast For Wednesday, April 1st 2020 |
2020-04-01 | Qakbot malspam sent from an infected Windows host |
2020-03-31 | ISC Stormcast For Tuesday, March 31st 2020 |
2020-03-31 | Kwampirs Targeted Attacks Involving Healthcare Sector |
2020-03-30 | Crashing explorer.exe with(out) a click |
2020-03-30 | ISC Stormcast For Monday, March 30th 2020 |
2020-03-29 | Obfuscated Excel 4 Macros |
2020-03-28 | Covid19 Domain Classifier |
2020-03-27 | Help us classify Covid19 related domains (login required) |
2020-03-27 | Malicious JavaScript Dropping Payload in the Registry |
2020-03-27 | ISC Stormcast For Friday, March 27th 2020 |
2020-03-26 | ISC Stormcast For Thursday, March 26th 2020 |
2020-03-26 | Very Large Sample as Evasion Technique? |
2020-03-25 | ISC Stormcast For Wednesday, March 25th 2020 |
2020-03-25 | Recent Dridex activity |
2020-03-24 | SANS CyberCast Hallway Talk: Microsoft Windows Type 1 Font Parsing 0-Day |
2020-03-24 | Another Critical COVID-19 Shortage: Digital Security |
2020-03-24 | ISC Stormcast For Tuesday, March 24th 2020 |
2020-03-23 | Windows Zeroday Actively Exploited: Type 1 Font Parsing Remote Code Execution Vulnerability |
2020-03-23 | KPOT Deployed via AutoIt Script |
2020-03-23 | ISC Stormcast For Monday, March 23rd 2020 |
2020-03-22 | More COVID-19 Themed Malware |
2020-03-21 | Honeypot - Scanning and Targeting Devices & Services |
2020-03-20 | ISC Stormcast For Friday, March 20th 2020 |
2020-03-19 | ISC Stormcast For Thursday, March 19th 2020 |
2020-03-19 | COVID-19 Themed Multistage Malware |
2020-03-18 | ISC Stormcast For Wednesday, March 18th 2020 |
2020-03-18 | Trickbot gtag red5 distributed as a DLL file |
2020-03-17 | A Quick Summary of Current Reflective DNS DDoS Attacks |
2020-03-17 | ISC Stormcast For Tuesday, March 17th 2020 |
2020-03-16 | Desktop.ini as a post-exploitation tool |
2020-03-16 | ISC Stormcast For Monday, March 16th 2020 |
2020-03-16 | SANS Work From Home Deployment Kit. Free Material to Help You Stay Secure While Working From Home |
2020-03-15 | VPN Access and Activity Monitoring |
2020-03-14 | Phishing PDF With Incremental Updates. |
2020-03-13 | Microsoft Patches SMBv3 Compression RCE bug - |
2020-03-13 | VMware Patches for Bugs in DHCP Service (Workstation, Fusion, Horizon, VMRC) |
2020-03-13 | ISC Stormcast For Friday, March 13th 2020 |
2020-03-13 | Not all Ethernet NICs are Created Equal - Trying to Capture Invalid Ethernet Frames |
2020-03-12 | ISC Stormcast For Thursday, March 12th 2020 |
2020-03-12 | Hancitor distributed through coronavirus-themed malspam |
2020-03-12 | Critical SMBv3 Vulnerability: Remote Code Execution |
2020-03-11 | ISC Stormcast For Wednesday, March 11th 2020 |
2020-03-11 | Agent Tesla Delivered via Fake Canon EOS Notification on Free OwnCloud Account |
2020-03-10 | Microsoft Patch Tuesday March 2020 |
2020-03-10 | ISC Stormcast For Tuesday, March 10th 2020 |
2020-03-09 | Malicious Spreadsheet With Data Connection and Excel 4 Macros |
2020-03-09 | ISC Stormcast For Monday, March 9th 2020 |
2020-03-08 | Excel Maldocs: Hidden Sheets |
2020-03-07 | Wireshark 3.2.2 Released: Windows' Users Pay Attention Please |
2020-03-07 | Chain Reactor: Simulate Adversary Behaviors on Linux |
2020-03-06 | ISC Stormcast For Friday, March 6th 2020 |
2020-03-06 | A Safe Excel Sheet Not So Safe |
2020-03-05 | Will You Put Your Password in a Survey? |
2020-03-05 | ISC Stormcast For Thursday, March 5th 2020 |
2020-03-04 | Let's Encrypt Revoking 3 Million Certificates |
2020-03-04 | ISC Stormcast For Wednesday, March 4th 2020 |
2020-03-03 | Introduction to EvtxEcmd (Evtx Explorer) |
2020-03-03 | ISC Stormcast For Tuesday, March 3rd 2020 |
2020-03-02 | Secure vs. cleartext protocols - couple of interesting stats |
2020-03-02 | ISC Stormcast For Monday, March 2nd 2020 |
2020-02-29 | Hazelcast IMDG Discover Scan |
2020-02-28 | ISC Stormcast For Friday, February 28th 2020 |
2020-02-28 | Show me Your Clipboard Data! |
2020-02-27 | ISC Stormcast For Thursday, February 27th 2020 |
2020-02-27 | Offensive Tools Are For Blue Teams Too |
2020-02-26 | ISC Stormcast For Wednesday, February 26th 2020 |
2020-02-25 | Quick look at a couple of current online scam campaigns |
2020-02-25 | ISC Stormcast For Tuesday, February 25th 2020 |
2020-02-24 | Maldoc: Excel 4 Macros and VBA, Devil and Angel? |
2020-02-24 | ISC Stormcast For Monday, February 24th 2020 |
2020-02-23 | Maldoc: Excel 4 Macros in OOXML Format |
2020-02-22 | Simple but Efficient VBScript Obfuscation |
2020-02-21 | Quick Analysis of an Encrypted Compound Document Format |
2020-02-21 | ISC Stormcast For Friday, February 21st 2020 |
2020-02-20 | Whodat? Enumerating Who "owns" a Workstation for IR |
2020-02-20 | ISC Stormcast For Thursday, February 20th 2020 |
2020-02-19 | ISC Stormcast For Wednesday, February 19th 2020 |
2020-02-18 | Discovering contents of folders in Windows without permissions |
2020-02-18 | ISC Stormcast For Tuesday, February 18th 2020 |
2020-02-17 | curl and SSPI |
2020-02-17 | ISC Stormcast For Monday, February 17th 2020 |
2020-02-16 | SOAR or not to SOAR? |
2020-02-15 | bsdtar on Windows 10 |
2020-02-14 | Keep an Eye on Command-Line Browsers |
2020-02-14 | ISC Stormcast For Friday, February 14th 2020 |
2020-02-13 | Auth-mageddon deferred (but not averted), Microsoft LDAP Changes now slated for Q3Q4 2020 |
2020-02-13 | ISC Stormcast For Thursday, February 13th 2020 |
2020-02-12 | March Patch Tuesday is Coming - the LDAP Changes will Change Your Life! |
2020-02-12 | ISC Stormcast For Wednesday, February 12th 2020 |
2020-02-12 | Malpsam pushes Ursnif through Italian language Word docs |
2020-02-11 | Microsoft Patch Tuesday for February 2020 |
2020-02-11 | ISC Stormcast For Tuesday, February 11th 2020 |
2020-02-10 | Current PayPal phishing campaign or "give me all your personal information" |
2020-02-10 | ISC Stormcast For Monday, February 10th 2020 |
2020-02-08 | After Action Review |
2020-02-07 | Sandbox Detection Tricks & Nice Obfuscation in a Single VBScript |
2020-02-07 | ISC Stormcast For Friday, February 7th 2020 |
2020-02-06 | ISC Stormcast For Thursday, February 6th 2020 |
2020-02-05 | Fake browser update pages are "still a thing" |
2020-02-05 | ISC Stormcast For Wednesday, February 5th 2020 |
2020-02-04 | ISC Stormcast For Tuesday, February 4th 2020 |
2020-02-03 | Analysis of a triple-encrypted AZORult downloader |
2020-02-03 | ISC Stormcast For Monday, February 3rd 2020 |
2020-02-02 | Video: Stego & Cryptominers |
2020-02-01 | Wireshark 3.2.1 Released |
2020-01-31 | ISC Stormcast For Friday, January 31st 2020 |
2020-01-30 | ISC Stormcast For Thursday, January 30th 2020 |
2020-01-29 | ISC Stormcast For Wednesday, January 29th 2020 |
2020-01-28 | ISC Stormcast For Tuesday, January 28th 2020 |
2020-01-28 | Emotet epoch 1 infection with Trickbot gtag mor84 |
2020-01-27 | Network Security Perspective on Coronavirus Preparedness |
2020-01-27 | ISC Stormcast For Monday, January 27th 2020 |
2020-01-25 | Is Threat Hunting the new Fad? |
2020-01-25 | Visibility Gap of Your Security Tools |
2020-01-24 | Why Phishing Remains So Popular? |
2020-01-24 | ISC Stormcast For Friday, January 24th 2020 |
2020-01-23 | Complex Obfuscation VS Simple Trick |
2020-01-23 | ISC Stormcast For Thursday, January 23rd 2020 |
2020-01-22 | ISC Stormcast For Wednesday, January 22nd 2020 |
2020-01-22 | German language malspam pushes Ursnif |
2020-01-21 | DeepBlueCLI: Powershell Threat Hunting |
2020-01-21 | ISC Stormcast For Tuesday, January 21st 2020 |
2020-01-20 | ISC Stormcast For Monday, January 20th 2020 |
2020-01-20 | Citrix ADC Exploits Update |
2020-01-17 | ISC Stormcast For Friday, January 17th 2020 |
2020-01-16 | Summing up CVE-2020-0601, or the Let?s Decrypt vulnerability |
2020-01-16 | Picks of 2019 malware - the large, the small and the one full of null bytes |
2020-01-16 | ISC Stormcast For Thursday, January 16th 2020 |
2020-01-15 | CVE-2020-0601 Followup |
2020-01-15 | ISC Stormcast For Wednesday, January 15th 2020 |
2020-01-14 | Microsoft Patch Tuesday for January 2020 |
2020-01-14 | ISC Stormcast For Tuesday, January 14th 2020 |
2020-01-13 | ISC Stormcast For Monday, January 13th 2020 |
2020-01-13 | Citrix ADC Exploits: Overview of Observed Payloads |
2020-01-12 | ELK Dashboard and Logstash parser for tcp-honeypot Logs |
2020-01-11 | Citrix ADC Exploits are Public and Heavily Used. Attempts to Install Backdoor |
2020-01-10 | More Data Exfiltration |
2020-01-10 | ISC Stormcast For Friday, January 10th 2020 |
2020-01-09 | Quick Analyzis of a(nother) Maldoc |
2020-01-09 | ISC Stormcast For Thursday, January 9th 2020 |
2020-01-09 | Windows 7 - End of Life |
2020-01-08 | ISC Stormcast For Wednesday, January 8th 2020 |
2020-01-07 | A Quick Update on Scanning for CVE-2019-19781 (Citrix ADC / Gateway Vulnerability) |
2020-01-07 | ISC Stormcast For Tuesday, January 7th 2020 |
2020-01-06 | SNMP service: still opened to the public and still queried by attackers |
2020-01-06 | Increase in Number of Sources January 3rd and 4th: spoofed |
2020-01-06 | ISC Stormcast For Monday, January 6th 2020 |
2020-01-05 | etl2pcapng: Convert .etl Capture Files To .pcapng Format |
2020-01-04 | KringleCon 2019 |
2020-01-03 | CCPA - Quick Overview |
2020-01-03 | ISC Stormcast For Friday, January 3rd 2020 |
2020-01-02 | Ransomware in Node.js |
2020-01-01 | "Nim httpclient/1.0.4" |
2019-12-31 | Some Thoughts About the Critical Citrix ADC/Gateway Vulnerability (CVE-2019-19781) |
2019-12-31 | ISC Stormcast For Tuesday, December 31st 2019 |
2019-12-30 | ISC Stormcast For Monday, December 30th 2019 |
2019-12-30 | Miscellaneous Updates to our "Threatfeed" API |
2019-12-29 | ELK Dashboard for Pihole Logs |
2019-12-28 | Corrupt Office Documents |
2019-12-27 | Enumerating office365 users |
2019-12-27 | ISC Stormcast For Friday, December 27th 2019 |
2019-12-26 | Bypassing UAC to Install a Cryptominer |
2019-12-25 | Merry christmas! |
2019-12-25 | Timely acquisition of network traffic evidence in the middle of an incident response procedure |
2019-12-24 | Malspam with links to Word docs pushes IcedID (Bokbot) |
2019-12-23 | ISC Stormcast For Monday, December 23rd 2019 |
2019-12-23 | New oledump.py plugin: plugin_version_vba |
2019-12-22 | Extracting VBA Macros From .DWG Files |
2019-12-21 | Wireshark 3.2.0 Released |
2019-12-20 | ISC Stormcast For Friday, December 20th 2019 |
2019-12-19 | More DNS over HTTPS: Become One With the Packet. Be the Query. See the Query |
2019-12-19 | ISC Stormcast For Thursday, December 19th 2019 |
2019-12-18 | ISC Stormcast For Wednesday, December 18th 2019 |
2019-12-18 | Emotet infection with spambot activity |
2019-12-17 | ISC Stormcast For Tuesday, December 17th 2019 |
2019-12-17 | Is it Possible to Identify DNS over HTTPs Without Decrypting TLS? |
2019-12-16 | ISC Stormcast For Monday, December 16th 2019 |
2019-12-16 | Malicious .DWG Files? |
2019-12-15 | VirusTotal Email Submissions |
2019-12-14 | (Lazy) Sunday Maldoc Analysis: A Bit More ... |
2019-12-13 | Internet banking sites and their use of TLS... and SSLv3... and SSLv2?! |
2019-12-13 | ISC Stormcast For Friday, December 13th 2019 |
2019-12-12 | Critical VMware Vulnerability (OpenSLP): |
2019-12-12 | ISC Stormcast For Thursday, December 12th 2019 |
2019-12-12 | Code & Data Reuse in the Malware Ecosystem |
2019-12-11 | ISC Stormcast For Wednesday, December 11th 2019 |
2019-12-11 | German language malspam pushes yet another wave of Trickbot |
2019-12-10 | Microsoft December 2019 Patch Tuesday |
2019-12-10 | ISC Stormcast For Tuesday, December 10th 2019 |
2019-12-09 | ISC Stormcast For Monday, December 9th 2019 |
2019-12-09 | (Lazy) Sunday Maldoc Analysis |
2019-12-08 | Wireshark 3.0.7 Released |
2019-12-07 | Integrating Pi-hole Logs in ELK with Logstash |
2019-12-06 | Phishing with a self-contained credentials-stealing webpage |
2019-12-06 | ISC Stormcast For Friday, December 6th 2019 |
2019-12-05 | E-mail from Agent Tesla |
2019-12-05 | ISC Stormcast For Thursday, December 5th 2019 |
2019-12-04 | Analysis of a strangely poetic malware |
2019-12-04 | ISC Stormcast For Wednesday, December 4th 2019 |
2019-12-03 | ISC Stormcast For Tuesday, December 3rd 2019 |
2019-12-03 | Ursnif infection with Dridex |
2019-12-02 | Next up, what's up with TCP port 26? |
2019-12-02 | ISC Stormcast For Monday, December 2nd 2019 |
2019-11-29 | ISC Snapshot: Search with SauronEye |
2019-11-27 | ISC Stormcast For Wednesday, November 27th 2019 |
2019-11-27 | Finding an Agent Tesla malware sample |
2019-11-26 | Lessons learned from playing a willing phish |
2019-11-26 | ISC Stormcast For Tuesday, November 26th 2019 |
2019-11-25 | My Little DoH Setup |
2019-11-25 | ISC Stormcast For Monday, November 25th 2019 |
2019-11-23 | Local Malware Analysis with Malice |
2019-11-22 | ISC Stormcast For Friday, November 22nd 2019 |
2019-11-22 | Abusing Web Filters Misconfiguration for Reconnaissance |
2019-11-21 | Gathering information to determine unusual network traffic |
2019-11-21 | ISC Stormcast For Thursday, November 21st 2019 |
2019-11-20 | ISC Stormcast For Wednesday, November 20th 2019 |
2019-11-20 | Hancitor infection with Pony, Evil Pony, Ursnif, and Cobalt Strike |
2019-11-19 | Cheap Chinese JAWS of DVR Exploitability on Port 60001 |
2019-11-19 | ISC Stormcast For Tuesday, November 19th 2019 |
2019-11-18 | SMS and 2FA: Another Reason to Move away from It. |
2019-11-18 | ISC Stormcast For Monday, November 18th 2019 |
2019-11-15 | ISC Stormcast For Friday, November 15th 2019 |
2019-11-13 | ISC Stormcast For Wednesday, November 13th 2019 |
2019-11-13 | An example of malspam pushing Lokibot malware, November 2019 |
2019-11-12 | November 2019 Microsoft Patch Tuesday |
2019-11-12 | ISC Stormcast For Tuesday, November 12th 2019 |
2019-11-11 | Are We Going Back to TheMoon (and How is Liquor Involved)? |
2019-11-11 | Some packet-fu with Zeek (previously known as bro) |
2019-11-11 | ISC Stormcast For Monday, November 11th 2019 |
2019-11-10 | Did the recent malicious BlueKeep campaign have any positive impact when it comes to patching? |
2019-11-09 | Fake Netflix Update Request by Text |
2019-11-08 | Microsoft Apps Diverted from Their Main Use |
2019-11-08 | ISC Stormcast For Friday, November 8th 2019 |
2019-11-07 | Getting the best value out of security assessments |
2019-11-07 | ISC Stormcast For Thursday, November 7th 2019 |
2019-11-06 | ISC Stormcast For Wednesday, November 6th 2019 |
2019-11-06 | More malspam pushing Formbook |
2019-11-05 | ISC Stormcast For Tuesday, November 5th 2019 |
2019-11-05 | Bluekeep exploitation causing Bluekeep vulnerability scan to fail |
2019-11-04 | ISC Stormcast For Monday, November 4th 2019 |
2019-11-04 | rConfig Install Directory Remote Code Execution Vulnerability Exploited |
2019-11-03 | You Too? "Unusual Activity with Double Base64 Encoding" |
2019-11-02 | Remark on EML Attachments |
2019-11-01 | Tip: Password Managers and 2FA |
2019-11-01 | ISC Stormcast For Friday, November 1st 2019 |
2019-10-31 | EML attachments in O365 - a recipe for phishing |
2019-10-31 | ISC Stormcast For Thursday, October 31st 2019 |
2019-10-30 | Keep an Eye on Remote Access to Mailboxes |
2019-10-30 | ISC Stormcast For Wednesday, October 30th 2019 |
2019-10-29 | ISC Stormcast For Tuesday, October 29th 2019 |
2019-10-29 | Generating PCAP Files from YAML |
2019-10-28 | ISC Stormcast For Monday, October 28th 2019 |
2019-10-27 | Using scdbg to Find Shellcode |
2019-10-27 | Unusual Activity with Double Base64 Encoding |
2019-10-27 | Wireshark 3.0.6 Released |
2019-10-25 | VMware Patch Alert! |
2019-10-25 | More on DNS Archeology (with PowerShell) |
2019-10-25 | ISC Stormcast For Friday, October 25th 2019 |
2019-10-24 | Your Supply Chain Doesn't End At Receiving: How Do You Decommission Network Equipment? |
2019-10-24 | ISC Stormcast For Thursday, October 24th 2019 |
2019-10-23 | ISC Stormcast For Wednesday, October 23rd 2019 |
2019-10-22 | Testing TLSv1.3 and supported ciphers |
2019-10-22 | ISC Stormcast For Tuesday, October 22nd 2019 |
2019-10-21 | What's up with TCP 853 (DNS over TLS)? |
2019-10-21 | ISC Stormcast For Monday, October 21st 2019 |
2019-10-20 | Scanning Activity for NVMS-9000 Digital Video Recorder |
2019-10-19 | What Assumptions Are You Making? |
2019-10-18 | Quick Malicious VBS Analysis |
2019-10-18 | ISC Stormcast For Friday, October 18th 2019 |
2019-10-17 | Phishing e-mail spoofing SPF-enabled domain |
2019-10-17 | ISC Stormcast For Thursday, October 17th 2019 |
2019-10-16 | New VMware security advisory: | Oracle quarterly patches bundle: https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html |
2019-10-16 | Security Monitoring: At Network or Host Level? |
2019-10-16 | ISC Stormcast For Wednesday, October 16th 2019 |
2019-10-15 | ISC Stormcast For Tuesday, October 15th 2019 |
2019-10-14 | When MacOS Catalina Comes to Life: The First Few Minutes of Network Traffic From MacOS 10.15. |
2019-10-14 | YARA's XOR Modifier |
2019-10-14 | ISC Stormcast For Monday, October 14th 2019 |
2019-10-12 | YARA v3.11.0 released |
2019-10-11 | ISC Stormcast For Friday, October 11th 2019 |
2019-10-10 | Mining Live Networks for OUI Data Oddness |
2019-10-10 | ISC Stormcast For Thursday, October 10th 2019 |
2019-10-09 | ISC Stormcast For Wednesday, October 9th 2019 |
2019-10-09 | What data does Vidar malware steal from an infected host? |
2019-10-08 | Microsoft October 2019 Patch Tuesday |
2019-10-08 | ISC Stormcast For Tuesday, October 8th 2019 |
2019-10-07 | ISC Stormcast For Monday, October 7th 2019 |
2019-10-06 | visNetwork for Network Data |
2019-10-04 | ISC Stormcast For Friday, October 4th 2019 |
2019-10-03 | Buffer overflows found in libpcap and tcpdump |
2019-10-03 | ISC Stormcast For Thursday, October 3rd 2019 |
2019-10-03 | "Lost_Files" Ransomware |
2019-10-02 | ISC Stormcast For Wednesday, October 2nd 2019 |
2019-10-02 | A recent example of Emotet malspam |
2019-10-01 | A Quick Look at Some Current Comment Spam |
2019-10-01 | ISC Stormcast For Tuesday, October 1st 2019 |
2019-09-30 | Maldoc, PowerShell & BITS |
2019-09-30 | ISC Stormcast For Monday, September 30th 2019 |
2019-09-29 | Encrypted Maldoc, Wrong Password |
2019-09-27 | New Scans for Polycom Autoconfiguration Files |
2019-09-27 | ISC Stormcast For Friday, September 27th 2019 |
2019-09-26 | Vulnerability on specific Cisco Industrial / Grid router models |
2019-09-26 | Mining MAC Address and OUI Information |
2019-09-26 | ISC Stormcast For Thursday, September 26th 2019 |
2019-09-25 | ISC Stormcast For Wednesday, September 25th 2019 |
2019-09-25 | Malspam pushing Quasar RAT |
2019-09-24 | Huge Amount of remotewebaccess.com Sites Found in Certificate Transparency Logs |
2019-09-24 | ISC Stormcast For Tuesday, September 24th 2019 |
2019-09-23 | ISC Stormcast For Monday, September 23rd 2019 |
2019-09-22 | YARA XOR Strings: an Update |
2019-09-22 | Video: Encrypted Sextortion PDFs |
2019-09-21 | Wireshark 3.0.5 Release: Potential Windows Crash when Updating |
2019-09-20 | ISC Stormcast For Friday, September 20th 2019 |
2019-09-19 | Blacklisting or Whitelisting in the Right Way |
2019-09-19 | Agent Tesla Trojan Abusing Corporate Email Accounts |
2019-09-19 | ISC Stormcast For Thursday, September 19th 2019 |
2019-09-18 | ISC Stormcast For Wednesday, September 18th 2019 |
2019-09-18 | Emotet malspam is back |
2019-09-17 | Investigating Gaps in your Windows Event Logs |
2019-09-17 | ISC Stormcast For Tuesday, September 17th 2019 |
2019-09-16 | Encrypted Sextortion PDFs |
2019-09-16 | ISC Stormcast For Monday, September 16th 2019 |
2019-09-13 | ISC Stormcast For Friday, September 13th 2019 |
2019-09-12 | Rig Exploit Kit Delivering VBScript |
2019-09-12 | Blocking Firefox DoH with Bind |
2019-09-12 | ISC Stormcast For Thursday, September 12th 2019 |
2019-09-11 | ISC Stormcast For Wednesday, September 11th 2019 |
2019-09-10 | Microsoft September 2019 Patch Tuesday |
2019-09-10 | ISC Stormcast For Tuesday, September 10th 2019 |
2019-09-09 | ISC Stormcast For Monday, September 9th 2019 |
2019-09-07 | Unidentified Scanning Activity |
2019-09-06 | PowerShell Script with a builtin DLL |
2019-09-06 | ISC Stormcast For Friday, September 6th 2019 |
2019-09-05 | Private IP Addresses in Malware Samples? |
2019-09-05 | ISC Stormcast For Thursday, September 5th 2019 |
2019-09-04 | ISC Stormcast For Wednesday, September 4th 2019 |
2019-09-04 | Malspam using password-protected Word docs to push Remcos RAT |
2019-09-03 | [Guest Diary] Tricky LNK points to TrickBot |
2019-09-03 | ISC Stormcast For Tuesday, September 3rd 2019 |
2019-09-02 | ISC Stormcast For Monday, September 2nd 2019 |
2019-08-30 | Malware Dropping a Local Node.js Instance |
2019-08-30 | ISC Stormcast For Friday, August 30th 2019 |
2019-08-29 | ISC Stormcast For Thursday, August 29th 2019 |
2019-08-28 | Malware Samples Compiling Their Next Stage on Premise |
2019-08-28 | [Guest Diary] Open Redirect: A Small But Very Common Vulnerability |
2019-08-28 | ISC Stormcast For Wednesday, August 28th 2019 |
2019-08-27 | ISC Stormcast For Tuesday, August 27th 2019 |
2019-08-26 | Is it Safe to Require TLS 1.2 for E-Mail |
2019-08-26 | ISC Stormcast For Monday, August 26th 2019 |
2019-08-25 | Are there any Advantages of Buying Cyber Security Insurance? |
2019-08-23 | ISC Stormcast For Friday, August 23rd 2019 |
2019-08-22 | Simple Mimikatz & RDPWrapper Dropper |
2019-08-22 | ISC Stormcast For Thursday, August 22nd 2019 |
2019-08-21 | KAPE: Kroll Artifact Parser and Extractor |
2019-08-21 | ISC Stormcast For Wednesday, August 21st 2019 |
2019-08-20 | ISC Stormcast For Tuesday, August 20th 2019 |
2019-08-20 | Guildma malware is now accessing Facebook and YouTube to keep up-to-date |
2019-08-19 | Compressed ISO Files (ISZ) |
2019-08-19 | ISC Stormcast For Monday, August 19th 2019 |
2019-08-18 | Video: Analyzing DAA Files |
2019-08-16 | The DAA File Format |
2019-08-16 | ISC Stormcast For Friday, August 16th 2019 |
2019-08-15 | Analysis of a Spearphishing Maldoc |
2019-08-15 | ISC Stormcast For Thursday, August 15th 2019 |
2019-08-14 | ISC Stormcast For Wednesday, August 14th 2019 |
2019-08-14 | Recent example of MedusaHTTP malware |
2019-08-13 | August 2019 Microsoft Patch Tuesday |
2019-08-13 | ISC Stormcast For Tuesday, August 13th 2019 |
2019-08-12 | Malicious .DAA Attachments |
2019-08-12 | ISC Stormcast For Monday, August 12th 2019 |
2019-08-11 | Nmap Defcon Release: 7.80 |
2019-08-09 | ISC Stormcast For Friday, August 9th 2019 |
2019-08-09 | 100% JavaScript Phishing Page |
2019-08-08 | [Guest Diary] The good, the bad and the non-functional, or "how not to do an attack campaign" |
2019-08-08 | ISC Stormcast For Thursday, August 8th 2019 |
2019-08-07 | Verifying SSL/TLS configuration (part 2) |
2019-08-07 | ISC Stormcast For Wednesday, August 7th 2019 |
2019-08-06 | ISC Stormcast For Tuesday, August 6th 2019 |
2019-08-05 | ISC Stormcast For Monday, August 5th 2019 |
2019-08-05 | Scanning for Bluekeep vulnerable RDP instances |
2019-08-05 | Sextortion: Follow the Money - The Final Chapter |
2019-08-04 | Detecting ZLIB Compression |
2019-08-02 | Combining Low Tech Scams: SMS + SET + Credit Card Harvesting |
2019-08-02 | ISC Stormcast For Friday, August 2nd 2019 |
2019-08-01 | What is Listening On Port 9527/TCP? |
2019-08-01 | ISC Stormcast For Thursday, August 1st 2019 |
2019-07-31 | ISC Stormcast For Wednesday, July 31st 2019 |
2019-07-31 | Targeted Phishing Attacks in the Financial Industry: Fire-3 Phishing Kit |
2019-07-30 | Can You Spell 2FA? A Luno Phish Example |
2019-07-30 | ISC Stormcast For Tuesday, July 30th 2019 |
2019-07-29 | Recognizing ZLIB Compression |
2019-07-29 | ISC Stormcast For Monday, July 29th 2019 |
2019-07-28 | Video: Analyzing Compressed PowerShell Scripts |
2019-07-27 | A Python TCP proxy |
2019-07-26 | DVRIP Port 34567 - Uptick |
2019-07-26 | ISC Stormcast For Friday, July 26th 2019 |
2019-07-25 | When Users Attack! Users (and Admins) Thwarting Security Controls |
2019-07-25 | ISC Stormcast For Thursday, July 25th 2019 |
2019-07-24 | May People Be Considered as IOC? |
2019-07-24 | ISC Stormcast For Wednesday, July 24th 2019 |
2019-07-23 | Verifying SSL/TLS configuration (part 1) |
2019-07-23 | ISC Stormcast For Tuesday, July 23rd 2019 |
2019-07-22 | Analyzing Compressed PowerShell Scripts |
2019-07-22 | ISC Stormcast For Monday, July 22nd 2019 |
2019-07-21 | Malicious RTF Analysis CVE-2017-11882 by a Reader |
2019-07-20 | Re-evaluating Network Security - It is Increasingly More Complex |
2019-07-19 | ISC Stormcast For Friday, July 19th 2019 |
2019-07-18 | Malicious PHP Script Back on Stage? |
2019-07-18 | The Other Side of Critical Control 1: 802.1x Wired Network Access Controls |
2019-07-18 | ISC Stormcast For Thursday, July 18th 2019 |
2019-07-17 | Analyzis of DNS TXT Records |
2019-07-17 | ISC Stormcast For Wednesday, July 17th 2019 |
2019-07-16 | ISC Stormcast For Tuesday, July 16th 2019 |
2019-07-16 | Commando VM: The Complete Mandiant Offensive VM |
2019-07-15 | isodump.py and Malicious ISO Files |
2019-07-15 | ISC Stormcast For Monday, July 15th 2019 |
2019-07-13 | Guidance to Protect DNS Against Hijacking & Scanning for Version.BIND Still a Thing |
2019-07-12 | ISC Stormcast For Friday, July 12th 2019 |
2019-07-11 | Russian Dolls Malicious Script Delivering Ursnif |
2019-07-11 | Remembering Mike Assante |
2019-07-11 | ISC Stormcast For Thursday, July 11th 2019 |
2019-07-11 | Recent AZORult activity |
2019-07-10 | Dumping File Contents in Hex (in PowerShell) |
2019-07-10 | Samba Project tells us "What's New" - SMBv1 Disabled by Default (finally) |
2019-07-10 | ISC Stormcast For Wednesday, July 10th 2019 |
2019-07-09 | VMWare Security Advisory on DoS Vulnerability in ESXi |
2019-07-09 | MSFT July 2019 Patch Tuesday |
2019-07-09 | Solving the WHOIS and Privacy Problem: A Draft of Implementing WHOIS in DNS |
2019-07-09 | ISC Stormcast For Tuesday, July 9th 2019 |
2019-07-08 | Machine Code? No! |
2019-07-08 | ISC Stormcast For Monday, July 8th 2019 |
2019-07-07 | OpSec and OSInt |
2019-07-06 | Malicious XSL Files |
2019-07-05 | A "Stream O" Maldoc |
2019-07-04 | Machine Code? |
2019-07-03 | ISC Stormcast For Wednesday, July 3rd 2019 |
2019-07-02 | Malicious Script With Multiple Payloads |
2019-07-02 | Using Powershell in Basic Incident Response - A Domain Wide "Kill-Switch" |
2019-07-02 | ISC Stormcast For Tuesday, July 2nd 2019 |
2019-07-01 | Maldoc: Payloads in User Forms |
2019-06-30 | ISC Stormcast For Sunday, June 30th 2019 |
2019-06-28 | Verifying Running Processes against VirusTotal - Domain-Wide |
2019-06-27 | ISC Stormcast For Friday, June 28th 2019 |
2019-06-27 | Finding the Gold in a Pile of Pennies - Long Tail Analysis in PowerShell |
2019-06-26 | The Other Side of CIS Critical Control 2 - Inventorying *Unwanted* Software |
2019-06-25 | ISC Stormcast For Wednesday, June 26th 2019 |
2019-06-25 | Rig Exploit Kit sends Pitou.B Trojan |
2019-06-24 | ISC Stormcast For Tuesday, June 25th 2019 |
2019-06-24 | Extensive BGP Issues Affecting Cloudflare and possibly others |
2019-06-23 | ISC Stormcast For Monday, June 24th 2019 |
2019-06-21 | ISC Stormcast For Friday, June 21st 2019 |
2019-06-21 | Netstat Local and Remote -new and improved, now with more PowerShell! |
2019-06-20 | Using a Travel Packing App for Infosec Purpose |
2019-06-20 | ISC Stormcast For Thursday, June 20th 2019 |
2019-06-19 | Quick Detect: Exim "Return of the Wizard" Attack |
2019-06-19 | Critical Actively Exploited WebLogic Flaw Patched CVE-2019-2729 |
2019-06-19 | ISC Stormcast For Wednesday, June 19th 2019 |
2019-06-18 | What You Need To Know About TCP "SACK Panic" |
2019-06-18 | ISC Stormcast For Tuesday, June 18th 2019 |
2019-06-18 | Malspam with password-protected Word docs pushing Dridex |
2019-06-17 | An infection from Rig exploit kit |
2019-06-17 | ISC Stormcast For Monday, June 17th 2019 |
2019-06-16 | Sysmon Version 10: DNS Logging |
2019-06-14 | ISC Stormcast For Friday, June 14th 2019 |
2019-06-14 | A few Ghidra tips for IDA users, part 4 - function call graphs |
2019-06-13 | ISC Stormcast For Thursday, June 13th 2019 |
2019-06-13 | What is "THAT" Address Doing on my Network |
2019-06-12 | ISC Stormcast For Wednesday, June 12th 2019 |
2019-06-11 | MSFT June 2019 Patch Tuesday |
2019-06-11 | ISC Stormcast For Tuesday, June 11th 2019 |
2019-06-10 | Interesting JavaScript Obfuscation Example |
2019-06-10 | ISC Stormcast For Monday, June 10th 2019 |
2019-06-09 | Tip: Sysmon Will Log DNS Queries |
2019-06-06 | ISC Stormcast For Friday, June 7th 2019 |
2019-06-06 | Keep an Eye on Your WMI Logs |
2019-06-06 | New VMWare security advisory that affects VMware tools and Workstation - more information at |
2019-06-06 | Time is (partially) on our side: the new Exim vulnerability |
2019-06-06 | ISC Stormcast For Thursday, June 6th 2019 |
2019-06-05 | Getting (proper) value out of security assessments |
2019-06-05 | GoldBrute Botnet Brute Forcing 1.5 Million RDP Servers |
2019-06-05 | Cisco Security Advisories (2x HIGH) per PSIRT 05 JUN 2019: |
2019-06-05 | ISC Stormcast For Wednesday, June 5th 2019 |
2019-06-04 | ISC snapshot: r-cyber with rud.is |
2019-06-04 | ISC Stormcast For Tuesday, June 4th 2019 |
2019-06-03 | Tip: BASE64 Encoded PowerShell Scripts are Recognizable by the Amount of Letter As |
2019-06-03 | ISC Stormcast For Monday, June 3rd 2019 |
2019-05-31 | Retrieving Second Stage Payload with Ncat |
2019-05-31 | ISC Stormcast For Friday, May 31st 2019 |
2019-05-30 | Analyzing First Stage Shellcode |
2019-05-30 | ISC Stormcast For Thursday, May 30th 2019 |
2019-05-29 | Behavioural Malware Analysis with Microsoft ASA |
2019-05-29 | ISC Stormcast For Wednesday, May 29th 2019 |
2019-05-28 | Office Document & BASE64? PowerShell! |
2019-05-28 | ISC Stormcast For Tuesday, May 28th 2019 |
2019-05-27 | nmap Service Fingerprint |
2019-05-26 | Video: nmap Service Detection Customization |
2019-05-25 | Do You Remember the SUBST Command? |
2019-05-24 | ISC Stormcast For Friday, May 24th 2019 |
2019-05-23 | Investigating an Odd DNS Query |
2019-05-22 | ISC Stormcast For Thursday, May 23rd 2019 |
2019-05-22 | An Update on the Microsoft Windows RDP "Bluekeep" Vulnerability (CVE-2019-0708) [now with pcaps] |
2019-05-21 | ISC Stormcast For Wednesday, May 22nd 2019 |
2019-05-21 | Using Shodan Monitoring |
2019-05-20 | ISC Stormcast For Tuesday, May 21st 2019 |
2019-05-20 | CVE-2019-0604 Attack |
2019-05-19 | ISC Stormcast For Monday, May 20th 2019 |
2019-05-19 | Is Metadata Only Approach, Good Enough for Network Traffic Analysis? |
2019-05-17 | ISC Stormcast For Friday, May 17th 2019 |
2019-05-16 | The Risk of Authenticated Vulnerability Scans |
2019-05-16 | ISC Stormcast For Thursday, May 16th 2019 |
2019-05-15 | ISC Stormcast For Wednesday, May 15th 2019 |
2019-05-14 | VMWare just released a security update to address a DLL-hijacking issue affecting VMware Workstation Pro / Player. Details: |
2019-05-14 | Microsoft May 2019 Patch Tuesday |
2019-05-14 | ISC Stormcast For Tuesday, May 14th 2019 |
2019-05-13 | From Phishing To Ransomware? |
2019-05-13 | ISC Stormcast For Monday, May 13th 2019 |
2019-05-10 | DSSuite - A Docker Container with Didier's Tools |
2019-05-10 | ISC Stormcast For Friday, May 10th 2019 |
2019-05-09 | ISC Stormcast For Thursday, May 9th 2019 |
2019-05-08 | ISC Stormcast For Wednesday, May 8th 2019 |
2019-05-08 | Email roulette, May 2019 |
2019-05-07 | Vulnerable Apache Jenkins exploited in the wild |
2019-05-07 | ISC Stormcast For Tuesday, May 7th 2019 |
2019-05-06 | Text and Text |
2019-05-05 | ISC Stormcast For Monday, May 6th 2019 |
2019-05-03 | A few Ghidra tips for IDA users, part 3 - conversion, labels, and comments |
2019-05-03 | ISC Stormcast For Friday, May 3rd 2019 |
2019-05-02 | ISC Stormcast For Thursday, May 2nd 2019 |
2019-05-01 | VBA Office Document: Which Version? |
2019-05-01 | Another Day, Another Suspicious UDF File |
2019-05-01 | ISC Stormcast For Wednesday, May 1st 2019 |
2019-04-30 | Introduction to KAPE |
2019-04-30 | ISC Stormcast For Tuesday, April 30th 2019 |
2019-04-29 | ISC Stormcast For Monday, April 29th 2019 |
2019-04-28 | Update about Weblogic CVE-2019-2725 (Exploits Used in the Wild, Patch Status) |
2019-04-27 | Quick Tip for Dissecting CVE-2017-11882 Exploits |
2019-04-26 | Pillaging Passwords from Service Accounts |
2019-04-26 | ISC Stormcast For Friday, April 26th 2019 |
2019-04-25 | Service Accounts Redux - Collecting Service Accounts with PowerShell |
2019-04-25 | Unpatched Vulnerability Alert - WebLogic Zero Day |
2019-04-25 | ISC Stormcast For Thursday, April 25th 2019 |
2019-04-24 | Finding Local Administrators on a Domain Member Stations |
2019-04-24 | Where have all the Domain Admins gone? Rooting out Unwanted Domain Administrators |
2019-04-24 | ISC Stormcast For Wednesday, April 24th 2019 |
2019-04-23 | Malicious VBA Office Document Without Source Code |
2019-04-22 | ISC Stormcast For Tuesday, April 23rd 2019 |
2019-04-22 | .rar Files and ACE Exploit CVE-2018-20250 |
2019-04-22 | ISC Stormcast For Monday, April 22nd 2019 |
2019-04-19 | Analyzing UDF Files with Python |
2019-04-19 | ISC Stormcast For Friday, April 19th 2019 |
2019-04-18 | ISC Stormcast For Thursday, April 18th 2019 |
2019-04-17 | Malware Sample Delivered Through UDF Image |
2019-04-17 | ISC Stormcast For Wednesday, April 17th 2019 |
2019-04-17 | A few Ghidra tips for IDA users, part 2 - strings and parameters |
2019-04-16 | ISC Stormcast For Tuesday, April 16th 2019 |
2019-04-16 | Odd DNS Requests that are Normal |
2019-04-15 | ISC Stormcast For Monday, April 15th 2019 |
2019-04-13 | Configuring MTA-STS and TLS Reporting For Your Domain |
2019-04-12 | When Windows 10 Comes to Live: The First Few Minutes in the Live of a Windows 10 System |
2019-04-12 | ISC Stormcast For Friday, April 12th 2019 |
2019-04-11 | How to Find Hidden Cameras in your AirBNB |
2019-04-11 | ISC Stormcast For Thursday, April 11th 2019 |
2019-04-10 | Blue + Red: An Infosec Purple Pyramid |
2019-04-09 | ISC Stormcast For Wednesday, April 10th 2019 |
2019-04-09 | Microsoft April 2019 Patch Tuesday |
2019-04-09 | ISC Stormcast For Tuesday, April 9th 2019 |
2019-04-08 | A few Ghidra tips for IDA users, part 1 - the decompiler/unreachable code |
2019-04-07 | ISC Stormcast For Monday, April 8th 2019 |
2019-04-07 | Fake Office 365 Payment Information Update |
2019-04-05 | Beagle: Graph transforms for DFIR data & logs |
2019-04-04 | ISC Stormcast For Friday, April 5th 2019 |
2019-04-04 | New Waves of Scans Detected by an Old Rule |
2019-04-04 | ISC Stormcast For Thursday, April 4th 2019 |
2019-04-03 | ISC Stormcast For Wednesday, April 3rd 2019 |
2019-04-03 | A few Ghidra tips for IDA users, part 0 - automatic comments for API call parameters |
2019-04-02 | ISC Stormcast For Tuesday, April 2nd 2019 |
2019-04-02 | Fake AV is Back: LaCie Network Drives Used to Spread Malware |
2019-04-01 | Analysis of PDFs Created with OpenOffice/LibreOffice |
2019-03-31 | ISC Stormcast For Monday, April 1st 2019 |
2019-03-31 | Maldoc Analysis of the Weekend by a Reader |
2019-03-30 | "404" is not Malware |
2019-03-29 | Annotating Golang binaries with Cutter and Jupyter |
2019-03-28 | ISC Stormcast For Friday, March 29th 2019 |
2019-03-27 | ISC Stormcast For Thursday, March 28th 2019 |
2019-03-27 | Running your Own Passive DNS Service |
2019-03-26 | ISC Stormcast For Wednesday, March 27th 2019 |
2019-03-25 | ISC Stormcast For Tuesday, March 26th 2019 |
2019-03-25 | "VelvetSweatshop" Maldocs: Shellcode Analysis |
2019-03-24 | ISC Stormcast For Monday, March 25th 2019 |
2019-03-24 | Decoding QR Codes with Python |
2019-03-23 | "VelvetSweatshop" Maldocs |
2019-03-22 | Introduction to analysing Go binaries |
2019-03-21 | ISC Stormcast For Thursday, March 21st 2019 |
2019-03-21 | New Wave of Extortion Emails: Central Intelligence Agency Case |
2019-03-20 | ISC Stormcast For Wednesday, March 20th 2019 |
2019-03-20 | Using AD to find hosts that aren't in AD - fun with the [IPAddress] construct! |
2019-03-19 | ISC Stormcast For Wednesday, March 20th 2019 |
2019-03-18 | Wireshark 3.0.0 and Npcap: Some Remarks |
2019-03-18 | ISC Stormcast For Monday, March 18th 2019 |
2019-03-17 | ISC Stormcast For Sunday, March 17th 2019 |
2019-03-17 | Video: Maldoc Analysis: Excel 4.0 Macro |
2019-03-16 | Maldoc: Excel 4.0 Macros |
2019-03-15 | Binary Analysis with Jupyter and Radare2 |
2019-03-15 | ISC Stormcast For Friday, March 15th 2019 |
2019-03-14 | Tip: Ghidra & ZIP Files |
2019-03-13 | ISC Stormcast For Wednesday, March 13th 2019 |
2019-03-13 | Malspam pushes Emotet with Qakbot as the follow-up malware |
2019-03-12 | Microsoft March 2019 Patch Tuesday |
2019-03-12 | Test Diary |
2019-03-12 | ISC Stormcast For Tuesday, March 12th 2019 |
2019-03-11 | Wireshark 3.0.0 and Npcap |
2019-03-10 | ISC Stormcast For Monday, March 11th 2019 |
2019-03-10 | Quick and Dirty Malicious HTA Analysis |
2019-03-10 | Malicious HTA Analysis by a Reader |
2019-03-09 | A Comparison Study of SSH Port Activity - TCP 22 & 2222 |
2019-03-08 | Analysing meterpreter payload with Ghidra |
2019-03-08 | ISC Stormcast For Friday, March 8th 2019 |
2019-03-07 | ISC Stormcast For Thursday, March 7th 2019 |
2019-03-06 | Keep an Eye on Disposable Email Addresses |
2019-03-06 | March Edition of Ouch! Newsletter: Securely Disposing Mobile Devices |
2019-03-06 | ISC Stormcast For Wednesday, March 6th 2019 |
2019-03-06 | Malspam with password-protected word docs still pushing IcedID (Bokbot) with Trickbot |
2019-03-05 | ISC Stormcast For Tuesday, March 5th 2019 |
2019-03-05 | Powershell, Active Directory and the Windows Host Firewall |
2019-03-04 | ISC Stormcast For Monday, March 4th 2019 |
2019-03-01 | Critical Cisco Wireless Patch for RV Series, CVE-2019-1663. |
2019-03-01 | ISC Stormcast For Friday, March 1st 2019 |
2019-02-28 | ISC Stormcast For Thursday, February 28th 2019 |
2019-02-28 | Phishing impersonations |
2019-02-27 | Maldoc Analysis by a Reader |
2019-02-27 | ISC Stormcast For Wednesday, February 27th 2019 |
2019-02-26 | Ad Blocking With Pi Hole |
2019-02-26 | ISC Stormcast For Tuesday, February 26th 2019 |
2019-02-25 | Sextortion Email Variant: With QR Code |
2019-02-25 | ISC Stormcast For Monday, February 25th 2019 |
2019-02-24 | Packet Editor and Builder by Colasoft |
2019-02-22 | ISC Stormcast For Friday, February 22nd 2019 |
2019-02-21 | Simple Powershell Keyloggers are Back |
2019-02-21 | ISC Stormcast For Thursday, February 21st 2019 |
2019-02-20 | ISC Stormcast For Wednesday, February 20th 2019 |
2019-02-20 | More Russian language malspam pushing Shade (Troldesh) ransomware |
2019-02-19 | Identifying Files: Failure Happens |
2019-02-19 | ISC Stormcast For Tuesday, February 19th 2019 |
2019-02-18 | VMware Security Advisory Released: VMSA-2019-0001 |
2019-02-18 | ISC Stormcast For Monday, February 18th 2019 |
2019-02-18 | Know What You Are Logging |
2019-02-17 | Video: Finding Property Values in Office Documents |
2019-02-16 | Finding Property Values in Office Documents |
2019-02-15 | ISC Stormcast For Friday, February 15th 2019 |
2019-02-14 | Old H-Worm Delivered Through GitHub |
2019-02-14 | Suspicious PDF Connecting to a Remote SMB Share |
2019-02-14 | ISC Stormcast For Thursday, February 14th 2019 |
2019-02-13 | ISC Stormcast For Wednesday, February 13th 2019 |
2019-02-13 | Fake Updates campaign still active in 2019 |
2019-02-12 | Microsoft February 2019 Patch Tuesday |
2019-02-12 | ISC Stormcast For Tuesday, February 12th 2019 |
2019-02-11 | Have You Seen an Email Virus Recently? |
2019-02-11 | ISC Stormcast For Monday, February 11th 2019 |
2019-02-10 | Video: Maldoc Analysis of the Weekend |
2019-02-09 | Maldoc Analysis of the Weekend |
2019-02-08 | ISC Stormcast For Friday, February 8th 2019 |
2019-02-07 | Phishing Kit with JavaScript Keylogger |
2019-02-07 | UAC is not all that bad really |
2019-02-06 | ISC Stormcast For Thursday, February 7th 2019 |
2019-02-06 | Hancitor malspam and infection traffic from Tuesday 2019-02-05 |
2019-02-06 | ISC Stormcast For Wednesday, February 6th 2019 |
2019-02-05 | Mitigations against Mimikatz Style Attacks |
2019-02-05 | ISC Stormcast For Tuesday, February 5th 2019 |
2019-02-04 | Wikipedia Articles as part of Tech Support Scamming Campaigns? |
2019-02-04 | Struts Vulnerability CVE-2017-5638 on VMware vCenter - the Gift that Keeps on Giving |
2019-02-04 | ISC Stormcast For Monday, February 4th 2019 |
2019-02-03 | Video: Analyzing a Simple HTML Phishing Attachment |
2019-02-02 | Scanning for WebDAV PROPFIND Exploiting CVE-2017-7269 |
2019-02-01 | ISC Stormcast For Friday, February 1st 2019 |
2019-02-01 | Sextortion: Follow the Money Part 3 - The cashout begins! |
2019-01-31 | Tracking Unexpected DNS Changes |
2019-01-31 | ISC Stormcast For Thursday, January 31st 2019 |
2019-01-30 | CR19-010: The United States vs. Huawei |
2019-01-30 | ISC Stormcast For Wednesday, January 30th 2019 |
2019-01-29 | A Not So Well Done Phish (Why Attackers need to Implement IPv6 Now! ;-) ) |
2019-01-29 | ISC Stormcast For Tuesday, January 29th 2019 |
2019-01-28 | Relaying Exchange?s NTLM authentication to domain admin (and more) |
2019-01-28 | ISC Stormcast For Monday, January 28th 2019 |
2019-01-27 | Resolve to Be More Involved In Your Local Community - REVISITED |
2019-01-26 | Video: Analyzing Encrypted Malicious Office Documents |
2019-01-25 | Are you Ready for DNS Flag Day? |
2019-01-25 | ISC Stormcast For Friday, January 25th 2019 |
2019-01-24 | Malspam with Word docs uses macro to run Powershell script and steal system data |
2019-01-24 | ISC Stormcast For Thursday, January 24th 2019 |
2019-01-23 | ISC Stormcast For Wednesday, January 23rd 2019 |
2019-01-22 | DNS Firewalling with MISP |
2019-01-22 | ISC Stormcast For Tuesday, January 22nd 2019 |
2019-01-21 | Suspicious GET Request: Do You Know What This Is? |
2019-01-21 | ISC Stormcast For Monday, January 21st 2019 |
2019-01-18 | Sextortion Bitcoin on the Move |
2019-01-18 | ISC Stormcast For Friday, January 18th 2019 |
2019-01-16 | ISC Stormcast For Wednesday, January 16th 2019 |
2019-01-15 | Oracle Has Published 284 Security Updates in their January Patch Advisory, More here: |
2019-01-15 | Microsoft Publishes Patches for Skype for Business and Team Foundation Server |
2019-01-14 | ISC Stormcast For Tuesday, January 15th 2019 |
2019-01-14 | Microsoft LAPS - Blue Team / Red Team |
2019-01-14 | Still Running Windows 7? Time to think about that upgrade project! |
2019-01-14 | ISC Stormcast For Monday, January 14th 2019 |
2019-01-12 | Snorpy a Web Base Tool to Build Snort/Suricata Rules |
2019-01-11 | Quick Maldoc Analysis |
2019-01-11 | ISC Stormcast For Friday, January 11th 2019 |
2019-01-10 | ISC Stormcast For Thursday, January 10th 2019 |
2019-01-10 | Heartbreaking Emails: "Love You" Malspam |
2019-01-09 | Wireshark 2.4.12 & 2.6.6 released, vulns & bugs fixed - |
2019-01-09 | gganimate: Animate YouR Security Analysis |
2019-01-09 | ISC Stormcast For Wednesday, January 9th 2019 |
2019-01-08 | Microsoft January 2019 Patch Tuesday |
2019-01-08 | ISC Stormcast For Tuesday, January 8th 2019 |
2019-01-07 | ISC Stormcast For Monday, January 7th 2019 |
2019-01-07 | Analyzing Encrypted Malicious Office Documents |
2019-01-06 | Malicious .tar Attachments |
2019-01-05 | A Malicious JPEG? Second Example |
2019-01-04 | A Malicious JPEG? |
2019-01-04 | ISC Stormcast For Friday, January 4th 2019 |
2019-01-03 | ISC Stormcast For Thursday, January 3rd 2019 |
2019-01-02 | Malicious Script Leaking Data via FTP |
2019-01-02 | Gift Card Scams on the rise |
2019-01-02 | ISC Stormcast For Wednesday, January 2nd 2019 |
2019-01-02 | Maldoc with Nonfunctional Shellcode |
2019-01-01 | Make a Wheel in 2019! |