Saide
25 posts

Saide
@saidesheikh
Seeker | hunting threats @unit42_intel | ex @msftsecurity
Event Logs Katılım Ekim 2022
141 Takip Edilen13 Takipçiler

The next free monthly one-hour training session with @ActiveCmeasures is on Threat Hunting C2: DNS TXT Record Abuse w/ Faan Rossouw!
Join us for a free monthly one-hour training session on command & controls and malicious traffic with Faan Rossouw (Active Countermeasures) and learn a stealthy C2 technique that bypasses common DNS tunneling detections and how to catch it.
Register: events.zoom.us/ev/Aqb16UU6sZM…

English

Investigated #KongTuke #ClickFix abuse of DNS TXT records delivering a PowerShell botnet agent. The script contains XOR-obfuscated code, patches AMSI, disables PS ETW, polls C2, executes via IEX, and exposes an interactive cmd.exe shell. Persistence logic exists but was disabled.
Unit 42@Unit42_Intel
We discovered the #KongTuke campaign using #DNS TXT records in its #ClickFix script. These DNS TXT records staged a command to retrieve and run a PowerShell script. We continue to monitor ClickFix campaigns for any future occurrences. Details at bit.ly/3Ze2Qpg
English

Glad to have been a part of this #ThreatIntelligence
Unit 42@Unit42_Intel
Attackers are leveraging #SEOpoisoning and abusing online repositories to target users looking for legitimate tools. Associated ZIP archives contain BAT files that impersonate various applications. C2 server returns follow-up remote admin tool. Details: bit.ly/4qLhwII
English
Saide retweetledi

The BlueHat India Villages are now open! Swing by between sessions and get hands-on, challenge your skills, and connect with security experts.
AI in Security Village: Explore AI’s role in cybersecurity and test yourself with AI-themed CTF challenges
Garage Village: Try soldering workshops and live 3D printing demos, perfect for prototyping newbies
Forensics Village: Learn digital forensics techniques, take a quiz, and join the CTF
MSRC Village: Hunt bugs, spot insecure code, dive into a phishing CTF, and get the scoop on bounty programs
AppSec Village: Brush up on secure coding, take on quizzes, and test yourself in CTF + RTF challenges
Arena: Don’t miss fireside chats on Diversity & Inclusion and the future of Quantum Computing
Which village are you checking out first?
#BlueHatIndia




English
Saide retweetledi

@TecmundoDigita @PredictaLabOff @EquationCorp Is Luan USDoD?
Yep he confirmed it to a statement to HackRead 2 hours ago
hackread.com/usdod-hacker-s…

English
Saide retweetledi
Saide retweetledi


Just when I thought I dodged a bullet by not going crazy during the meta downtime, LinkedIn decides to go on a break.
#LinkedInDown #LinkedIn
English
Saide retweetledi

Check out my article: 3CX Supply Chain Compromise -
A Personal Perspective linkedin.com/pulse/3cx-supp… via @LinkedIn
English

@nullcon last weekend was a blast - got to meet some fantastic new folks and reconnect with familiar ones! 🤝
#NullconGoa2023 #Nullcon #Infosec #CyberSecurity

English
Saide retweetledi
Saide retweetledi
Saide retweetledi

@4n6lady @GERARDJOHANSEN @PacktPublishing Let’s hope I get one. More than that I hope I find time to read it.
English
Saide retweetledi

⭐️GIVEAWAY!⭐️
I'm giving away 10 digital copies of Digital Forensics and Incident Response, 3rd Edition by @GERARDJOHANSEN @PacktPublishing
Winners will be announced Friday, @ 12pm EST 🥳
Enter by liking, sharing, and commenting 😊

English











