Global elections in 2024 face a wide range of cyber threats from state-sponsored actors, cybercriminals, hacktivists, insiders, and information‑operations-as-a-service, with state actors posing the most serious risk. Defenders should prioritize hardening acros…
Tag: THREAT HUNTING
At its core, threat hunting is the practice of proactively searching for signs of malicious activities or…
Threat activity surrounding CVE-2024-3400 targets PAN-OS devices (GlobalProtect) with post-exploitation attempts. The operation, dubbed MidnightEclipse, includes a Python backdoor (UPSTYLE) and a cronbackdoor, with mitigations, indicators, and hunting guidance…
Phishing is one of the most common and effective cyberattack vectors that threat actors use to compromise email accounts, steal sensitive data, and deliver malware. Recently, we have observed a new trend in phishing campaigns that leverage QR codes embedded in emails to evade detection and trick use…
Summary: The role of CISOs and other cybersecurity executives is gaining more influence and importance as companies recognize the need for strong cyber governance and oversight. Threat Actor: N/A Victim: N/A Key Point : About 90% of cybersecurity managers now report to a top-level company executive,…
Threat hunting uncovered an attack that used malicious MSI delivery to trick a user into installing a browser hijacker, while legitimate tools like PowerShell were used in the process. The post emphasizes integrating threat hunting with SecOps to detect abuse …
Threat detection and response are critical components of a robust cybersecurity strategy. However, simply relying…
ReliaQuest investigated a targeted April 2024 campaign against health care organizations where attackers used social engineering with help desk staff to bypass MFA and gain access to Revenue Cycle Management (RCM) accounts, likely to alter banking routing info…
Threat actors gained initial access via malicious Microsoft OneNote attachments that executed a batch file to download an IcedID DLL (disguised as an image) which ran via rundll32 and established long-lived C2 beaconing before deploying Cobalt Strike, AnyDesk,…
What is Threat Management? Threat management is a process that is used by cybersecurity analysts, incident responders and threat hunters to prevent cyberattacks, detect cyberthreats and respond to security incidents. Why is threat management important? Most IT and security teams face informat…
The world of cyber security faces new and more complex threats every day. Among these threats, which we encounter anew each day, one of the most significant is malicious software designed to steal personal and corporate information, known as “stealers”. Stealers can be considered one of today’s unse…
What’s happening? Given the intricate landscape of cybersecurity, the misuse of Windows Management Instrumentation (WMI) stands out as a pervasive threat. WMI facilitates centralized management of Windows devices by providing a consistent and well-documented interface that can be utilized by various…
You can’t talk about hunting for persistence techniques without mentioning scheduled tasks. As in the case of persistence via Windows services, described in a previous blog post, techniques related to scheduled tasks also allow for the use of a dual approach to persistence hunting: Both the creation…
When discussing Windows services and how to hunt for their abuse, it is worth mentioning that several threat hunting hypotheses can be leveraged. This is common in threat hunting in general and for persistence-related techniques in particular. As a reminder, all our service-related hypotheses can be…
When discussing Windows services and how to hunt for their abuse, it is worth mentioning that there are several threat hunting hypotheses that we can leverage. This is very common in threat hunting tradecraft in general and for persistence-related techniques in particular. When you are dealing with…