Elektrine lite

← Feed

Saltmyhash

saltmyhash@infosec.exchange

<p>Blue team. <a href="https://infosec.exchange/tags/cti" class="mention hashtag" rel="tag">#<span>cti</span></a> <a href="https://infosec.exchange/tags/threat_hunting" class="mention hashtag" rel="tag">#<span>threat_hunting</span></a> <a href="https://infosec.exchange/tags/ioc" class="mention hashtag" rel="tag">#<span>ioc</span></a> <a href="https://infosec.exchange/tags/reverseengineering" class="mention hashtag" rel="tag">#<span>reverseengineering</span></a> <a href="https://infosec.exchange/tags/threatintelligence" class="mention hashtag" rel="tag">#<span>threatintelligence</span></a> <a href="https://infosec.exchange/tags/soc" class="mention hashtag" rel="tag">#<span>soc</span></a> <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="tag">#<span>malware</span><

Posts

  • Post #3901438

    Die Another Day #BetterLateThanNeverAMovie #HashtagGames

  • Post #3662013

    Rosemary Clooney’s Baby #HashTagGames #ClassicMovieStarABook

  • Post #3616629

    Argo Back To Bed #TooSleepyAMovieOrPlay #HashtagGames

  • Post #3522803

    I was trying to carve out an encrypted blob from a PNG file last night using dd and finally triggered the new macOS ClickFix warning in my terminal. It was interesting that it fired because I wasn’t attempting to execute a commonly abused binary like osascript or make an outbound web call. While I haven’t been able to identify what XProtect is flagging on, I’m personally leaning towards either simple pattern matching for risky terms (I did have a suspicious output filename) or literally any past...

  • Post #3522429

    Friendly reminder that the first round of DEATHCon tickets go on sale July 7th. I recommend setting a reminder and logging on earlier in the day (like, early morning) to purchase as they will sell out quick. DEATHCon is easily the best bang for your conference buck when it comes to the amount of presentations and available logs to cut your teeth on detection engineering and threat hunting. https://deathcon.io/tickets.html #deathcon #threathunting #detectionengineering #conference

  • Post #3429849

    Network defenders should take a look at and hunt for Overlord RAT, a publicly-available and open-source Go-based RAT. Proofpoint recently published a blog post highlighting its adoption by UNK_DeadDrop, a DPRK-nexus threat group which appears to have used a lightly modified version but can still be detected via Shodan, Censys, or FOFA queries. Proofpoint notes minor operational overlaps with Contagious Interview, but UNK_DeadDrop appears to prefer Overlord while Contagious Interview sticks with...

  • Post #2867699

    @da_667 relatively weak but something is better than nothing. Might benefit from a GitHub PR if you find something interesting in network/host artifacts. https://lolrmm.io/tools/nomachine

  • Post #2867698

    @darfplatypus @cR0w I took a look at a canonical threat intel job a few months ago, saw the ridiculous requirements involving pre-college transcripts/report cards, laughed, and closed the page.

  • Post #2867697

    CISA KEV is claiming Copy Fail is under active exploitation but provides zero evidence of how/where. Anyone seeing anything else in public reporting to corroborate these claims? https://www.cisa.gov/known-exploited-vulnerabilities-catalog #copyfail #cve_2026_31431

  • Post #2867696

  • Post #2867695

    @bagder You have a fan at Dairy Queen. #curl