@bagder@mastodon.social You have a fan at Dairy Queen.
Remote
Saltmyhash
@saltmyhash@infosec.exchange
0 Followers
0 Following
20 Posts
Joined November 08, 2022
Open post
Open post
Replying to @cR0w@infosec.exchange
9
0
3
0
Open post
Open post
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange good reminder for all of us to consider donating to our instance admin who could be spending their weekend relaxing instead of patching. Just sent mine. Thanks Jerry.
4
1
1
0
Open post
Replying to @HailsandAles@metalhead.club
@HailsandAles@metalhead.club
Submission:
Power Trip - Nightmare Logic
Honorable Mentions:
Wolves in the Throne Room - Thrice Woven
Migos - Culture
Future Islands - The Far Field
War on Drugs - A Deeper Understanding
8
0
0
0
Open post
@darfplatypus@infosec.exchange @cR0w@infosec.exchange I took a look at a canonical threat intel job a few months ago, saw the ridiculous requirements involving pre-college transcripts/report cards, laughed, and closed the page.
1
1
0
0
Open post
Open post
CISA KEV is claiming Copy Fail is under active exploitation but provides zero evidence of how/where. Anyone seeing anything else in public reporting to corroborate these claims?
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
0
1
0
0
Open post
@da_667@infosec.exchange relatively weak but something is better than nothing. Might benefit from a GitHub PR if you find something interesting in network/host artifacts.
0
0
0
0
Open post
Network defenders should take a look at and hunt for Overlord RAT, a publicly-available and open-source Go-based RAT. Proofpoint recently published a blog post highlighting its adoption by UNK_DeadDrop, a DPRK-nexus threat group which appears to have used a lightly modified version but can still be detected via Shodan, Censys, or FOFA queries. Proofpoint notes minor operational overlaps with Contagious Interview, but UNK_DeadDrop appears to prefer Overlord while Contagious Interview sticks with OtterCookie/InvisibleFerret. Regardless, extraction of TTPs is super easy when the source code is available and great for folks who want an introduction into detection engineering and/or threat hunting.
For example, Overlord RAT ships with default self-signed certificates/port configurations. While advanced adversaries will obviously alter these settings, many groups won’t, including UNK_DeadDrop. This makes developing a baseline detection within Censys/Shodan/FOFA trivial for monitoring. The Censys query in the screenshot is rudimentary, but you get the idea. Start with low-hanging fruit and tune your queries to hunt for advanced adversaries who might be using more bespoke Overlord configurations. Once found, ingest and retro-hunt the IOCs in your environment. Overlord clients will establish C2 communications with these servers.
https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal
https://github.com/vxaboveground/Overlord
#overlord #unk_deaddrop #RAT #detectionengineering #threathunting #cti #threatintel
0
0
0
0
Open post
Friendly reminder that the first round of DEATHCon tickets go on sale July 7th. I recommend setting a reminder and logging on earlier in the day (like, early morning) to purchase as they will sell out quick.
DEATHCon is easily the best bang for your conference buck when it comes to the amount of presentations and available logs to cut your teeth on detection engineering and threat hunting.
https://deathcon.io/tickets.html
#deathcon #threathunting #detectionengineering #conference
0
0
0
0
Open post
I was trying to carve out an encrypted blob from a PNG file last night using dd and finally triggered the new macOS ClickFix warning in my terminal. It was interesting that it fired because I wasn’t attempting to execute a commonly abused binary like osascript or make an outbound web call. While I haven’t been able to identify what XProtect is flagging on, I’m personally leaning towards either simple pattern matching for risky terms (I did have a suspicious output filename) or literally any pastes from a browser. The latter I have tried numerous times to no avail when this was first released in Tahoe 26.4, so I have no idea.
FWIW, this was the offending command: dd if=clik.txt of=encrypted_payload.bin bs=1 skip=27856 status=progress
https://9to5mac.com/2026/03/25/macos-26-4-has-new-terminal-popup-warning-when-pasting-commands/
#macos #malware #clickfix
0
0
0
0
Open post
Open post
Replying to @cR0w@infosec.exchange
@cR0w@infosec.exchange @trojanfoxtrot@infosec.exchange I’ve started submitting applications from behind Astrill VPN infrastructure, at least I know their SOC/CTI shops will see my app when they are investigating DPRK remote IT workers.
0
0
0
0
Open post
Replying to @catsalad@infosec.exchange
@catsalad@infosec.exchange can’t inhale particulates if you can’t breathe
0
0
0
0
Open post
Replying to @kajer@infosec.exchange
@kajer@infosec.exchange impossible travel is hot garbage.
0
0
0
0
Open post
Replying to @trojanfoxtrot@infosec.exchange
@trojanfoxtrot@infosec.exchange Same. Have you rewritten your resume/CV to make it past the applicant tracking system (ATS)/AI bots? I was getting application rejections for job postings that were literally my current job role and decided to rewrite my resume to ensure the formatting wasn’t tripping up their stupid AI software. While I haven’t found a job yet, I HAVE been getting more call-backs post-rewrite. Stay strong, it’s rough out here.
0
1
0
0