Click here to download all references as Bib-File.•
| 2021-10-27
⋅
Twitter (@darienhuss)
⋅
Tweet on FinickyFrogfish/Wslink malware used by TA444 Wslink |
| 2021-10-26
⋅
Cisco Talos
⋅
SQUIRRELWAFFLE Leverages malspam to deliver Qakbot, Cobalt Strike Cobalt Strike QakBot Squirrelwaffle |
| 2021-10-22
⋅
Amazon
⋅
Building an open source IDS/IPS service on AWS with Suricata |
| 2021-07-27
⋅
Youtube (SANS Institute)
⋅
SANS Threat Analysis Rundown - Kaseya VSA attack REvil |
| 2021-06-22
⋅
Cisco
⋅
Attackers in Executive Clothing - BEC continues to separate orgs from their money |
| 2021-06-16
⋅
Mandiant
⋅
Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise DarkSide Cobalt Strike DarkSide SMOKEDHAM UNC2465 |
| 2021-06-16
⋅
Mandiant
⋅
Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise Cobalt Strike SMOKEDHAM |
| 2021-06-16
⋅
FireEye
⋅
Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise Cobalt Strike SMOKEDHAM |
| 2021-05-19
⋅
Team Cymru
⋅
Tracking BokBot Infrastructure Mapping a Vast and Currently Active BokBot Network IcedID |
| 2021-05-14
⋅
MOBISEC
⋅
Slides & Recordings for Mobile security trainings FlexiSpy ZitMo |
| 2021-05-04
⋅
FireEye
⋅
The UNC2529 Triple Double: A Trifecta Phishing Campaign DOUBLEBACK |
| 2021-04-07
⋅
Talos
⋅
Sowing Discord: Reaping the benefits of collaboration app abuse |
| 2021-03-09
⋅
Red Canary
⋅
Microsoft Exchange server exploitation: how to detect, mitigate, and stay calm CHINACHOPPER |
| 2021-03-08
⋅
Youtube (SANS Digital Forensics and Incident Response)
⋅
STAR Webcast: Making sense of SolarWinds through the lens of MITRE ATT&CK(R) Cobalt Strike SUNBURST TEARDROP |
| 2021-02-23
⋅
Medium (Katie’s Five Cents)
⋅
A Cyber Threat Intelligence Self-Study Plan: Part 1 |
| 2021-01-19
⋅
Mandiant
⋅
Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452 (WHITE PAPER) |
| 2021-01-19
⋅
FireEye
⋅
Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452 |
| 2021-01-13
⋅
Gitlab RCE Stealth Shellbot PerlBot |
| 2020-12-18
⋅
Cloudflare
⋅
A quirk in the SUNBURST DGA algorithm SUNBURST |
| 2020-12-16
⋅
Lookout
⋅
Lookout Discovers New Spyware Used by Sextortionists to Blackmail iOS and Android Users goontact |