As cyber adversaries become more sophisticated, detecting and neutralizing potential threats before they can cause any harm has become a top priority for cybersecurity professionals. It is also why threat hunting is a crucial skill. By mastering the art of cyber threat hunting, security professional…
Tag: THREAT HUNTING
ABSTRACT This document will help and guide you to start your first threat hunting based on MITRE ATT&CK Tactics. Reconnaissance Objective: Identify potential reconnaissance activity on the network Description: Reconnaissance is an important phase of an attack, where the attacker gathers informat…
Windows Event Logs mindmap provides a simplified view of Windows Event logs and their capacities that enables defenders to enhance visibility for different purposes: Log collection (eg: into a SIEM) Threat hunting Forensic / DFIR Troubleshooting Scheduled tasks: Event ID 4697 , This event generates…
EclecticIQ uncovered “Operation FlightNight,” an espionage campaign that used ISO attachments and LNK shortcuts to deliver a modified HackBrowserData stealer targeting Indian government agencies and energy companies. The malware harvested browser caches, docum…
Insikt Group uncovers ties between I-SOON and multiple Chinese state-sponsored cyber groups like RedAlpha and RedHotel.
ShinyHunters (aka ShinyCorp) is a global cybercrime group known for major data breaches and owning BreachForums. The article details their methods, notable victims like Tokopedia, Wattpad, and AT&T, and their evolution on dark web platforms, including a member…
PRESS RELEASEDENVER, March 5, 2024 – Red Canary today announced full coverage of its detection and response capabilities to include all major cloud infrastructure and platform services providers, such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). Red Canary can dete…
PRESS RELEASEHERNDON, Va., March 13, 2024 — (BUSINESS WIRE) — Expel, the leading managed detection and response (MDR) provider, today unveiled the updated version of its National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) Getting Started toolkit. The kit, which includ…
Microsoft announces that its Copilot for Security generative AI security solution will become generally available on April 1.
The post Microsoft’s AI-Powered Copilot for Security Set for Worldwide Release appeared first on SecurityWeek….
GAO study finds that CISA does not have enough staff to respond to significant OT attacks in multiple locations at the same time.
The post CISA’s OT Attack Response Team Understaffed: GAO appeared first on SecurityWeek….
Just one day after disclosure, adversaries began targeting the vulnerabilities to take complete control of affected instances of the popular developer platform.
The Cloud Security Alliance’s "Pandemic 11" cloud security challenges can be addressed by putting the right processes in place.
The Top 10 Malware in Q4 2023 changed slightly from the previous quarter. Here’s what the CIS Cyber Threat Intelligence team observed….
The Sandman APT group has drawn major attention for targeting telecommunications providers in Europe, the Middle East, and South Asia, employing LuaDream, a LuaJIT-based modular backdoor, to achieve stealthy espionage with minimal footprints. Research ties San…
Detect and mitigate CVE-2023-46805, CVE-2024-21887, CVE-2024-21888 and CVE-2024-21893, critical vulnerabilities in Ivanti VPN products. Organizations should patch urgently, and government agencies are instructed to isolate Ivanti VPN instances.