PeterM🌻

1K posts

PeterM🌻 banner
PeterM🌻

PeterM🌻

@AltShiftPrtScn

Work in DFIR, fighting the good fight. Don't go 5 minutes without saying ransomware. Created as a failsafe: https://t.co/zIAq2Hz99E

Earth, currently. Katılım Temmuz 2017
100 Takip Edilen2.8K Takipçiler
Sabitlenmiş Tweet
PeterM🌻
PeterM🌻@AltShiftPrtScn·
My WFH office is finally done. This took months and multiple lockdowns to complete. I converted part of my garage for this. Enter through a hidden door (with a camera watching). The projector also connects to my CCTV system.
English
5
0
88
0
PeterM🌻 retweetledi
John Viega
John Viega@viega·
This is amazing! Sophos' transparency should be lauded; pretty much all big security vendors have swept things like this under the rug, but this shows the industry could be driving a lot more value if vendors were just willing to be accountable. sophos.com/en-us/content/…
English
1
1
16
909
PeterM🌻 retweetledi
Kostas
Kostas@Kostastsale·
Another great article full of technical info!👏 Great job by @MorganDemboski and @securitydumpstr as always for this blog! Chinese State-sponsored TAs have become the punching bag for Sophos this year lol 😂 It inspired me to illustrate how they must be feeling right now😆🎬👇
Sophos X-Ops@SophosXOps

Today, we've published a report on Sophos MDR's investigation into renewed cyberespionage tied to Operation Crimson Palace, an intrusion into a SE Asian government agency that has expanded to other regional public service organizations. /1 news.sophos.com/en-us/2024/09/…

English
5
13
65
13.9K
PeterM🌻
PeterM🌻@AltShiftPrtScn·
I get asked a lot "how do you prepare for a ransomware attack". I always give the same answer; have an Incident Response Plan and practice it in advance. But how do you do that easily? well I highly recommend the NCSC's Exercise in a box, it's free! exerciseinabox.service.ncsc.gov.uk
English
0
3
7
432
PeterM🌻 retweetledi
Curated Intelligence
Curated Intelligence@CuratedIntel·
⚠️PSA: Curated Intel DFIR has noticed a new trend among Akira Ransomware cases in Summer 2024. For a while, Akira has been exploiting Cisco ASA devices. ➡️ They are now targeting SonicWall SSL-VPNs for access with no MFA (!) and weak passwords (!). Other TTPs remain the same 🔍
English
0
26
51
9.8K
PeterM🌻 retweetledi
Mark Loman
Mark Loman@markloman·
🚨 Ransomware still beats up-to-date protection - even decade-old strains! Want to know how? See @AltShiftPrtScn in "Know the Enemy". Wednesday, August 7, 11:25 am – 12:15 pm (Business Hall Theater A) More: #know-the-enemy-a-defenders-real-world-view-on-the-latest-ransomware-attack-techniques-41832" target="_blank" rel="nofollow noopener">blackhat.com/us-24/sponsore… #BlackHat
English
0
4
5
669
PeterM🌻
PeterM🌻@AltShiftPrtScn·
Working in DFIR and dealing with encrypted VMDKs? here is how we have been extracting forensic evidence from them. Well done to everyone involved in developing these methods. news.sophos.com/en-us/2024/05/…
English
0
24
48
4.6K
Mark
Mark@sneakymonk3y·
I thought this was one of the best modules from the @zeropointsecltd CRTO course today, lateral movement & code execution via MS SQL Server. Do not overlook your SQL instances, harden these as much as possible. I've seen plenty of PURPLEFOX and LEMONDUCK malware take advantage.
Mark tweet media
English
3
5
86
8.7K
PeterM🌻
PeterM🌻@AltShiftPrtScn·
Most ransomware IR's
PeterM🌻 tweet media
English
4
37
328
114.1K
PeterM🌻
PeterM🌻@AltShiftPrtScn·
@cyb3rops Well, as your reputation preceeds you, I will accept JAB is the b64 to hunt for, but I specifically like finding JABz as I know it inalmost every case means Cobalt. We can be friends though :-)
PeterM🌻 tweet media
English
1
1
9
930
PeterM🌻
PeterM🌻@AltShiftPrtScn·
If you work in DFIR and recognize b64 starting with "JABz" we can be friends.
English
6
8
59
12.9K
PeterM🌻
PeterM🌻@AltShiftPrtScn·
@0xMatt Fun, rewarding, stressful, tiring, CSV
English
0
0
0
56
PeterM🌻
PeterM🌻@AltShiftPrtScn·
@tonyszko @0gtweet I agree that you are correct about them being correct :-) depends on the incident and what the client/lawyers/insurance want.
English
0
0
1
27
Tomasz Onyszko
Tomasz Onyszko@tonyszko·
@0gtweet I think you both might be right, depending on the Tylenol cases you are involved in and what is the success criteria
English
1
0
2
511
Grzegorz Tworek
Grzegorz Tworek@0gtweet·
Cannot agree. Dump analysis takes a lot of resources (time * skills) and provides only a minimal benefit for the victim. Typical IR scenarios focus on cost minimizing, and not on the scientific values.
English
3
1
23
10K
PeterM🌻
PeterM🌻@AltShiftPrtScn·
@rik_ferguson Imagine if it was true and the only people left in the world after today are the type of people who choose not to get vacinated for this reason. Theres a dystopian movie idea.
English
0
0
1
122
PeterM🌻
PeterM🌻@AltShiftPrtScn·
@NSA_CSDirector Thats not a hug, he has him in a headlock, strangling the last of the budget out of him :-)
English
0
0
5
555