Angehefteter Tweet
PeterM🌻
1K posts

PeterM🌻
@AltShiftPrtScn
Work in DFIR, fighting the good fight. Don't go 5 minutes without saying ransomware. Created as a failsafe: https://t.co/zIAq2Hz99E
Earth, currently. Beigetreten Temmuz 2017
100 Folgt2.8K Follower

Nice post about exfil tools: Ransomware-driven data exfiltration: techniques and implications blog.sekoia.io/ransomware-dri…
English
PeterM🌻 retweetet

This is amazing! Sophos' transparency should be lauded; pretty much all big security vendors have swept things like this under the rug, but this shows the industry could be driving a lot more value if vendors were just willing to be accountable.
sophos.com/en-us/content/…
English
PeterM🌻 retweetet

Another great article full of technical info!👏 Great job by @MorganDemboski and @securitydumpstr as always for this blog!
Chinese State-sponsored TAs have become the punching bag for Sophos this year lol 😂
It inspired me to illustrate how they must be feeling right now😆🎬👇
Sophos X-Ops@SophosXOps
Today, we've published a report on Sophos MDR's investigation into renewed cyberespionage tied to Operation Crimson Palace, an intrusion into a SE Asian government agency that has expanded to other regional public service organizations. /1 news.sophos.com/en-us/2024/09/…
English

I get asked a lot "how do you prepare for a ransomware attack". I always give the same answer; have an Incident Response Plan and practice it in advance. But how do you do that easily? well I highly recommend the NCSC's Exercise in a box, it's free! exerciseinabox.service.ncsc.gov.uk
English
PeterM🌻 retweetet
PeterM🌻 retweetet

🚨 Ransomware still beats up-to-date protection - even decade-old strains! Want to know how? See @AltShiftPrtScn in "Know the Enemy". Wednesday, August 7, 11:25 am – 12:15 pm (Business Hall Theater A) More: #know-the-enemy-a-defenders-real-world-view-on-the-latest-ransomware-attack-techniques-41832" target="_blank" rel="nofollow noopener">blackhat.com/us-24/sponsore… #BlackHat
English

Working in DFIR and dealing with encrypted VMDKs? here is how we have been extracting forensic evidence from them. Well done to everyone involved in developing these methods. news.sophos.com/en-us/2024/05/…
English

Lots of IOCs and intel just published on the #ScreenConnect exploits. news.sophos.com/en-us/2024/02/…
English

@sneakymonk3y @zeropointsecltd If a coinminer can get in so can a ransomware TA. Treat them seriously before it's to late.
English

I thought this was one of the best modules from the @zeropointsecltd CRTO course today, lateral movement & code execution via MS SQL Server. Do not overlook your SQL instances, harden these as much as possible. I've seen plenty of PURPLEFOX and LEMONDUCK malware take advantage.

English
PeterM🌻 retweetet

#AlphV files an SEC complaint against #MeridianLink for not disclosing a breach to the SEC #Ransomware
databreaches.net/alphv-files-an…
GIF
English

#HuntersInternational IOCs - Cobalt: virustotal.com/gui/ip-address… & virustotal.com/gui/ip-address…, Other C2s: virustotal.com/gui/ip-address… & virustotal.com/gui/ip-address…. Rclone->SFTP: virustotal.com/gui/ip-address…. Filnames include vmware.exe, vmware.dll, vm.dll in ProgramData and Windows\Temp.
Română

@0gtweet I think you both might be right, depending on the Tylenol cases you are involved in and what is the success criteria
English

@rik_ferguson Imagine if it was true and the only people left in the world after today are the type of people who choose not to get vacinated for this reason. Theres a dystopian movie idea.
English

@NSA_CSDirector Thats not a hug, he has him in a headlock, strangling the last of the budget out of him :-)
English




