Cobra Cyber Security

6.6K posts

Cobra Cyber Security banner
Cobra Cyber Security

Cobra Cyber Security

@CobraCyberSec

Cyber Security and Threat Intelligence Share.

127.0.0.1-127.255.255.255 Katılım Mart 2014
4K Takip Edilen803 Takipçiler
Cobra Cyber Security retweetledi
Kostas
Kostas@Kostastsale·
There are so many opportunities to detect and evict the threat actor in almost all stages of the intrusion from our latest report. Execution might happen and it might not be detected for a long time as we saw here with the custom PowerShell implant. Detection in depth is key…
Kostas tweet media
The DFIR Report@TheDFIRReport

Collect, Exfiltrate, Sleep, Repeat ➡️Initial Access: Job App VBA Maldoc ➡️Discovery: PS Cmdlets, net, tzutil, etc. ➡️Persistence: Scheduled Tasks ➡️Collection: AutoHotkey Keylogger, Compress-Archive, makecab.exe ➡️C2: Custom PowerShell Framework thedfirreport.com/2023/02/06/col… 1/X

English
3
25
127
38.8K