ImPureMotion

110 posts

ImPureMotion banner
ImPureMotion

ImPureMotion

@ImPureMotion

The Cyberz

Katılım Şubat 2015
618 Takip Edilen195 Takipçiler
ImPureMotion
ImPureMotion@ImPureMotion·
@Kostastsale Awesome stuff - good recent use case from (thedfirreport.com/2023/08/28/htm…) where xcopy was used to rename rundll32 to entails.exe tweaking the regex a bit if you have cmdline parsed out: (xcopy|copy|copy-item|cp)\s+c:\\windows\\(system32|syswow64)\\[a-zA-Z0-9_\-]{1,}\.exe\s\w:\\.*\\?
ImPureMotion tweet media
English
1
1
3
217
Kostas
Kostas@Kostastsale·
Malware sometimes copies Windows binaries out of System32(See recent #DarkGate copying curl.exe & renaming) 🎯You can hunt or detect this by using the below regex ➡️(copy|copy-item|cp)\s+c:\\windows\\system32\\[a-zA-Z0-9_\-]{1,50}\.exe\s+(c:\\.*\\)?[a-zA-Z0-9_\-]{1,50}\.exe
English
10
52
226
29.3K
ImPureMotion retweetledi
The DFIR Report
The DFIR Report@TheDFIRReport·
HTML Smuggling Leads to Domain Wide Ransomware ➡️Initial Access: Thread-Hijacked Email > HTML Attachment ➡️Credentials: LSASS Access, SessionGopher ➡️Lateral Movement: RDP, PsExec ➡️C2: IcedID, Cobalt Strike ➡️Impact: Nokoyawa Ransomware thedfirreport.com/2023/08/28/htm… 1/X
English
5
165
373
97K
Alex Teixeira
Alex Teixeira@ateixei·
Seems like Detection Engineering has many similarities with Data Engineering starting with the acronym 'DE'. Should we pick #DetEng instead? Suggestions?
GIF
English
2
0
6
662
Elon Musk
Elon Musk@elonmusk·
Major Twitter improvement we just released is that you can now bookmark tweets from tweet details page. Importantly, bookmarks are *private*, unlike likes. No one other than you can see your bookmarks.
English
6.6K
9.3K
116.9K
18.2M
Security Doggo
Security Doggo@securitydoggo·
Don't know if it's because I haven't been on #infosec Twitter as much, or because I clicked on a few of the posts, but seems like everyone and their mothers has open positions 👀
English
2
1
5
0
Security Doggo
Security Doggo@securitydoggo·
Been running some #YARA, #Snort, and #Regex training for the team - anyone got any tips or things I should make sure to cover to make sure the team are 100% #cyber ninjas?
English
4
0
5
0
ImPureMotion retweetledi
ClearSky Cyber Security
ClearSky Cyber Security@ClearskySec·
Iranian #Oilrig campaign decoy: "User list must change password.xls", target in Saudi Arabia. C2: coldflys[.]com Further analysis: #heading=h.o3c0cv46s20s" target="_blank" rel="nofollow noopener">docs.google.com/document/d/1oY… Leads and analysis with @ImPureMotion and @blu3_team
ClearSky Cyber Security tweet mediaClearSky Cyber Security tweet mediaClearSky Cyber Security tweet mediaClearSky Cyber Security tweet media
English
0
9
13
0