Mike Cohen

474 posts

Mike Cohen

Mike Cohen

@scudette

Digital Paleontologist, digging deeper

Katılım Eylül 2009
167 Takip Edilen781 Takipçiler
Mike Cohen retweetledi
Velociraptor
Velociraptor@velocidex·
Great example of VQL automation!
Matthew Green 🌻@mgreen27

For any velociraptor users - I have been messing around with plyara over the last week and created a few bulk yara artifacts using Yara-Forge - yarahq.github.io. Velociraptor artifacts: File - github.com/mgreen27/Detec… Process github.com/mgreen27/Detec… github.com/mgreen27/Detec… github.com/mgreen27/Detec… Webshell - github.com/mgreen27/Detec… My automation takes Yara-Forge full ruleset, then seperates rules into buckets to optimise deployment. Updated each week to keep the rules up to date. #dfir @velocidex

English
0
5
19
1.5K
Mike Cohen retweetledi
Stephan Berger
Stephan Berger@malmoeb·
The incident started with a compromised server. When we extended the hunting to the entire network, we found traces of the "WayBack" campaign on a computer, which @yoroisecurity documented almost exactly three years ago [1]. We also found the exact same code as in the blog on the corresponding client in the customer's network. For three years, this and other code could have gone unnoticed in the network. Another reason for regular compromise assessments and hunting in the internal network. [1] yoroi.company/en/research/th…
Stephan Berger tweet media
English
0
17
41
5.3K
Mike Cohen retweetledi
Rapid7
Rapid7@rapid7·
Version 0.7.2 of @velocidex is now fully available for download! Learn what's new 👉 r-7.co/3WliUVJ
Rapid7 tweet mediaRapid7 tweet mediaRapid7 tweet media
English
0
4
16
4.9K
Mike Cohen
Mike Cohen@scudette·
Only a few days left to secure your early bird for our Velociraptor training in Singapore. This is a rare opportunity to learn about Velociraptor and how to deploy it effectively, develop VQL artifacts and actively hunt for adversaries. #digging-deeper-with-velociraptor-35856" target="_blank" rel="nofollow noopener">blackhat.com/asia-24/traini…
English
1
2
10
848
Mike Cohen
Mike Cohen@scudette·
@DebugPrivilege Excellent! Really looking forward to reading your full article. Thanks for the great content!
English
0
0
0
167
Mike Cohen
Mike Cohen@scudette·
@DebugPrivilege Indeed, the act of passing this environment variable is a very strong signal in itself. I wrote about this approach here #detecting-etw-subversion" target="_blank" rel="nofollow noopener">docs.velociraptor.app/blog/2021/2021…
English
0
0
2
188
Mike Cohen retweetledi
Matthew Green 🌻
Matthew Green 🌻@mgreen27·
Thought I would make some posts for #100daysofyara. Not sure how often i'll post but good chance to test some triage workflow and build some pratical Velociraptor rules for automation :) In the example below I grabbed a NanoCore sample from MalwareBazaar - bazaar.abuse.ch/sample/6ff9daa… if folks want to test. Good rules dont need to be complex rules with good targeting. This sample injects an unbacked pe file with rwx permissions. In this example I have targeted unbacked xrw permisssions. I have also included -rw permissions to cover .NET reflection as NanoCore is a .net binary. Due to targeting, this query should also be quite performant. github.com/mgreen27/Detec…
Matthew Green 🌻 tweet mediaMatthew Green 🌻 tweet media
English
0
4
16
2.6K
Mike Cohen retweetledi
Velociraptor
Velociraptor@velocidex·
We're incredibly thankful to our wonderful community of contributors, testers and enthusiasts! Without you, Velociraptor wouldn't be what it is. To all of you, your family and friends, HAPPY THANKSGIVING!
Velociraptor tweet media
English
0
1
4
825
Mike Cohen retweetledi
Velociraptor
Velociraptor@velocidex·
Want a sneak peek at the upcoming Velociraptor v0.7.1? With awesome new capabilities like built in Sigma integration and enhanced notebook functionality, you will want to download the release candidate today and test it out. Be sure to log any bugs or issues through GitHub. docs.velociraptor.app/blog/2023/2023…
English
0
13
38
4.3K