Email

- 3 mins read

300 Emails? It was 24 hours!

I would have never thought as a front line manager of a small team that I could receive as much email as I do. It’s so overwhelming, I’ve taken to putting my Out of Office as “Due to the volume of email, I will be deleting all email received in my absence. Please hold important correspondence til my return on 3 January 2024”!

Velociraptor Offline Collector

- 3 mins read

This is a living document and may be incomplete.

  • Updated 1DEC2023

Locating Evidences of Execution using Prefetch, Velociraptor, and Zimmerman’s PECmd

Prefetch is a common Windows artifact used for determining the first and last incidences of a program being executed. This file is a binary blob stored at $:\Windows\Prefetch and consists of a series of files named APPLICATION-GUID.pf. These files contain the name of the executable, the last n run date time groups a hash of the executable and path, and a list of files accessed by the .exe in the first few seconds of loading.

Show And Tell

- 10 mins read

Once a week, our security team gathers everyone into a meeting and shares the last week’s worth of security related news and any new security initiatives.

This one hour may be the most valuable meeting we attend and has the greatest impact on successful security outcomes.

A woman’s hand holds a cellphone showing a BBC news article discussing Russian hacking.

2023.10.17.News You Should Know

- 4 mins read

CDW investigating ransomware gang claims of data theft (therecord.media) - #Ransomware #ThreatActor - CDW acknowledges breach of a subsidiary of a division of a business area. Threat actors miffed over $1m offer after $80m demand.

HTTP/2 ‘Rapid Reset’ zero-day exploited in biggest DDoS yet • The Register - #Research #ThreatActor - Largest ever DDoS…from smallest ever botnet? 20k bots (multitudes smaller than previous botnets) were able to abuse HTTP/2 streaming to request hundreds of assets from a server over a single TCP stream (a feature of HTTP/2) then cancel those request midstream and request a hundred assets again. Which doesn’t count toward the max request limit. The only theoretical limit to this attack is target bandwidth.

LibWebP (CVE-2023-4863)

- 6 mins read

Here is a non-exhaustive list of possible mitigations to prevent the exploitation of CVE 2023-4863 in the LibWebP library. This library has a heap buffer overflow available across all operating systems, most browsers, an exceptional number of Electron framework applications.

This CVE is rated a 10 after previously being rated 8.8. This was due to an original disclosure from Google stating that Chrome was the only effected application. After investigation, it was discovered that all instances of the LibWebP library were vulnerable across all platforms.

2023.03.21.News You Should Know

- 4 mins read

Silicon Valley Bank collapsed this month causing credit ratings of major banks to drop and another to fail. While a multitude of information about this is available we find it most interesting because threat actors are using the collapse as pretext for scam emails. These emails are sent to trusted third-party businesses asking for updates to the accounts payable or EFT details to threat actor controlled accounts.

Malicious OneNote

- 4 mins read

Anatomy of a Malicious Email Attachment

With Microsoft’s recent changes to macros within the Office and M365 suite, Threat Actors have changed their TTPs to utilize the OneNote (.one) file type for Malicious Code Delivery

TL;DR (.one) files are a binary blob capable of embedding any file type. Threat actors are utilizing the prolific nature of OneNote to execute malicious code on endpoints. Block (.one) files from incoming email and dissociate commonly abused file extensions.

The Problem

Microsoft recently modified the way legacy Office applications and M365 applications handle macros within documents. With the restrictions on macros tightening, threat actors have been forced to find new techniques to deliver malicious code to the endpoint.

2023.01.17.News You Should Know

- 2 mins read

Microsoft is set to introduce significant changes to the Windows enterprise over the next year. With multiple security settings going from recommended to enforced.

Highlights include the EOL for AD Connector 2.0.x, changes to MFA, and the end of standalone Office Apps for 2016/19.

Caniphish’s Sebastian Salla published a review of thousands of misconfigured SPF records today allowing emails to be sent on behalf of foreign governments, the Massachusetts Institute of Technology, the University of Miami, among others.

2023.01.10.News You Should Know

- 3 mins read

House omnibus spending bill brings three interesting cybersecurity measures.

  • Section 7030 will require cybersecurity to be a key consideration in the adoption of technology and specifically 5g technologies for members of the Digital Connectivity and Cybersecurity Partnership.
  • The “No TikTok on Government Devices Act” bans the use of the Chinese-owned ByteDance company’s TikTok social media platform on goverment owned devices with power being given to the Director of the Cybersecurity and Infrastructure Security Agency (CISA) to dictate how application management is performed.
  • Section 3305 will require the FDA to ensure cybersecurity requirements are placed on medical devices. This is a change in posture from the FDA’s previous encouragement to follow cybersecurity best practices. Lawfare gives a breakdown of Section 3305.

Chair of the Senate Select Committee on Intelligence, and former techie, Sen. Mark Warner (D-VA) gave an interview via TechCrunch at the 2023 Consumer Electronics Show. In the interview, Warner discusses his legislation preventing the use of Huawei technologies, TikTok on federal devices, and the FTC’s handling of acquisitions and monopolies.