Saide

25 posts

Saide banner
Saide

Saide

@saidesheikh

Seeker | hunting threats @unit42_intel | ex @msftsecurity

Event Logs Katılım Ekim 2022
141 Takip Edilen13 Takipçiler
Black Hills Information Security
Black Hills Information Security@BHinfoSecurity·
The next free monthly one-hour training session with @ActiveCmeasures is on Threat Hunting C2: DNS TXT Record Abuse w/ Faan Rossouw! Join us for a free monthly one-hour training session on command & controls and malicious traffic with Faan Rossouw (Active Countermeasures) and learn a stealthy C2 technique that bypasses common DNS tunneling detections and how to catch it. Register: events.zoom.us/ev/Aqb16UU6sZM…
Black Hills Information Security tweet media
English
1
8
34
2.2K
Saide
Saide@saidesheikh·
Investigated #KongTuke #ClickFix abuse of DNS TXT records delivering a PowerShell botnet agent. The script contains XOR-obfuscated code, patches AMSI, disables PS ETW, polls C2, executes via IEX, and exposes an interactive cmd.exe shell. Persistence logic exists but was disabled.
Unit 42@Unit42_Intel

We discovered the #KongTuke campaign using #DNS TXT records in its #ClickFix script. These DNS TXT records staged a command to retrieve and run a PowerShell script. We continue to monitor ClickFix campaigns for any future occurrences. Details at bit.ly/3Ze2Qpg

English
0
0
1
117
Saide retweetledi
Microsoft BlueHat
Microsoft BlueHat@MSFTBlueHat·
The BlueHat India Villages are now open! Swing by between sessions and get hands-on, challenge your skills, and connect with security experts. AI in Security Village: Explore AI’s role in cybersecurity and test yourself with AI-themed CTF challenges Garage Village: Try soldering workshops and live 3D printing demos, perfect for prototyping newbies Forensics Village: Learn digital forensics techniques, take a quiz, and join the CTF MSRC Village: Hunt bugs, spot insecure code, dive into a phishing CTF, and get the scoop on bounty programs AppSec Village: Brush up on secure coding, take on quizzes, and test yourself in CTF + RTF challenges Arena: Don’t miss fireside chats on Diversity & Inclusion and the future of Quantum Computing Which village are you checking out first? #BlueHatIndia
Microsoft BlueHat tweet mediaMicrosoft BlueHat tweet mediaMicrosoft BlueHat tweet mediaMicrosoft BlueHat tweet media
English
0
3
9
603
Saide retweetledi
Traceix
Traceix@usetraceix·
Push straight to prod. Testing is for the weak.
English
9
14
84
6.5K
Saide retweetledi
chientrm
chientrm@realchientrm·
He nearly make it tbh. CVE-2024-3094 Until next time.
chientrm tweet media
English
0
7
29
2.8K
Saide
Saide@saidesheikh·
Was going through Malware Analysis Fundamentals on @LetsDefendIO Ironic enough? 🤔🤔
Saide tweet media
English
0
0
1
142
Saide
Saide@saidesheikh·
Just when I thought I dodged a bullet by not going crazy during the meta downtime, LinkedIn decides to go on a break. #LinkedInDown #LinkedIn
English
0
0
1
195
Saide retweetledi
inversecos
inversecos@inversecos·
threat intelligence is basically stalking people for a living
English
22
67
470
49.5K
Saide retweetledi
vx-underground
vx-underground@vxunderground·
Threat Actors when they trip the EDR
English
21
209
1.2K
133.7K
Saide retweetledi
Jake Williams
Jake Williams@MalwareJake·
Newton's First Law of Security Engineering: There's nothing more permanent than a temporary solution...
English
21
68
406
31.1K
Saide retweetledi
Samir
Samir@SBousseaden·
:)
Samir tweet media
ZXX
9
5
72
18.1K
Saide retweetledi
4n6lady
4n6lady@4n6lady·
⭐️GIVEAWAY!⭐️ I'm giving away 10 digital copies of Digital Forensics and Incident Response, 3rd Edition by @GERARDJOHANSEN @PacktPublishing Winners will be announced Friday, @ 12pm EST 🥳 Enter by liking, sharing, and commenting 😊
4n6lady tweet media
English
860
976
2.7K
225.3K