Security Datasets

66 posts

Security Datasets banner
Security Datasets

Security Datasets

@SecDatasets

Contributing datasets, from different platforms, to the InfoSec community to expedite data analysis and threat research! https://t.co/j62Xx21lEc

Datastore Katılım Eylül 2019
5 Takip Edilen2.1K Takipçiler
Security Datasets retweetledi
Microsoft Threat Intelligence
Microsoft Threat Intelligence@MsftSecIntel·
Today, Microsoft is open sourcing Cloud Katana, a cloud-native serverless application built on the top of Azure Functions to assess security controls in the cloud and hybrid cloud environments. Read about the design principles and learn how to deploy: msft.it/6011n46MT
Microsoft Threat Intelligence tweet media
English
6
144
319
0
Security Datasets
Security Datasets@SecDatasets·
We shared a dataset that contains the core behavior 🍻 You can add more context around it! (i.e. Service creation & execution) @OTR_Community 😈 Data: mordordatasets.com/notebooks/smal… 🛡️@sigma_hq rules: 1⃣ github.com/SigmaHQ/sigma/… 2⃣ github.com/SigmaHQ/sigma/… How Do I use the data? ⏬
Security Datasets tweet mediaSecurity Datasets tweet media
John Lambert@JohnLaTwC

#HuntingTipOfTheDay Search for command lines 🔎with 'comsvcs.dll' and 'MiniDump' to find credential dumping. 👀 ✏️Test your detections: gist.github.com/JohnLaTwC/3e7d… 📎References: ▪️risksense.com/blog/hidden-ge… by Jenna Magius and Nate Caroe (@RiskSense) ▪️modexp.wordpress.com/2019/08/30/min…

English
1
13
39
0
Security Datasets retweetledi
Open Threat Research
Open Threat Research@OTR_Community·
🚨 In less than 24h 😉, we are sharing telemetry ( #Sysmon, Security & System) through the @Mordor_Project to help everyone 🌎 expedite the validation process of detection rules! @Cyb3rPandaH #CobaltStrike 🗒️Metadata: mordordatasets.com/notebooks/smal… 😈Dataset: raw.githubusercontent.com/OTRF/mordor/ma…
Open Threat Research tweet mediaOpen Threat Research tweet media
Florian Roth ⚡️@cyb3rops

APTSimulator 0.9.0 featuring #CobaltStrike beacon activity simulation with - NamedPipe Creation - Service installation & exec pattern - HTTP beaconing github.com/NextronSystems… If you want to help, add some steps in here: github.com/NextronSystems…

English
0
80
188
0
Security Datasets retweetledi
Microsoft Security
Microsoft Security@msftsecurity·
It's time to go to SimuLand! 🎠🎡🎢 But it isn't a new vacation theme park hot spot, it's a new open-source initiative that will help you deploy a lab environment to reproduce real attack scenarios to test your security defenses. Get the details: msft.it/6017VxcHv
English
7
168
335
0
Security Datasets retweetledi
Open Threat Research
Open Threat Research@OTR_Community·
Sharing @Mordor_Project datasets for "Getting AD FS Database Config Remotely" (Security, Sysmon & PCAP) @Cyb3rWard0g 🍻🙏 mordordatasets.com/notebooks/smal… 1⃣ A few tool-based comments at the host level 2⃣ Group hosts & processes connecting to AD FS server over port 80 (Usually 443)
Open Threat Research tweet mediaOpen Threat Research tweet mediaOpen Threat Research tweet media
Dr. Nestori Syynimaa@DrAzureAD

New version of #AADInternals out now, including remote dumping of #ADFS configuration database🔥 Read the blog at: o365blog.com/post/adfs/ Credits to @vesat, @doughsec, @BakedSec, @_dirkjan, @gentilkiwi, @MGrafnetter, and @Cyb3rWard0g for your help and previous work!

English
3
38
71
0
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Terms we used in my years in IR Mordor: completely compromised network segments (FUBAR) Jurassic Park: networks with many EOL/EOS servers& outdated software Spreadsheet of Doom: ever growing list of compromised hosts/accounts Figurative speech helps you cope with all the misery
English
7
18
171
0
Security Datasets
Security Datasets@SecDatasets·
If you are wondering what this might look like in Sysmon, we got you covered with a new small dataset. You can simply download it from the link below and explore it with PSH as shown in the second image below 😊 Thank you @jxy__s ! 😈 mordordatasets.com/notebooks/smal…
Security Datasets tweet mediaSecurity Datasets tweet media
Johnny Shaw@jxy__s

I’m pleased to present this Windows exploit. Process Herpaderping is a method for evading detection - similar to process migration, hollowing, or doppelganging. herpaderping.com

English
1
44
120
0