chiefgyk3d, to python
@chiefgyk3d@social.chiefgyk3d.com avatar

I was up late trying to figure out a stupid issue I was having with the Crowdstrike API so I didn't stream on twitch last night, hoping to do a stream tonight. I think they took a feature out my team was actually using which would allow me to contain a device and make a note that could be viewed in the dashboard.

jpmellojr, to Cybersecurity
@jpmellojr@noc.social avatar

Threat actors, frequently frustrated by improved enterprise security systems, increased their efforts to compromise credentials in 2023, according to CrowdStrike.
https://jpmellojr.blogspot.com/2024/02/identity-hacking-saw-sharp-rise-2023.html

seanthegeek, to infosec
0xamit, to random

Finally some job related news. I'm excited to share that I'm joining #crowdstrike as lead security researcher

chiefgyk3d, to Cybersecurity
@chiefgyk3d@social.chiefgyk3d.com avatar

Thanks to @cybersheepdog for the initial inspiration, I have my GitHub up with my own twist on catching typosquat domains locally as well as an AWS lambda for Jira tickets. Next version will have automation https://github.com/ChiefGyk3D/Domain-Assassin

everythingopen, to infosec
@everythingopen@fosstodon.org avatar

We're delighted to announce our second Speaker for - Jana Dekanovska!

Jana is a well-known analyst, with a particular interest in the intersection of and threat , and is a Strategic Threat Advisor at .

👉 https://2024.everythingopen.au/news/keynote-jana-dekanovska/

chiefgyk3d, to Cybersecurity
@chiefgyk3d@social.chiefgyk3d.com avatar

README has been crafted for the upcoming Domain Assassin release for both the local and lambda versions with terraforms included for it, and tfenv files plus shell scripts to package the lambda to a zip as well as switch between AWS prod and dev for you easily.

I have some more tweaks to do before I am comfortable putting it up on Github but I don't see much deviating from here other than the addition of piping IOC over API

pixelnull, to random

in for conference... this is the worst trip i've ever been on

chiefgyk3d, to random
@chiefgyk3d@social.chiefgyk3d.com avatar

I may be getting for my homelab in a few months. I want to see about tying it into eventually and covering all my desktops and servers.

chiefgyk3d, to Cybersecurity
@chiefgyk3d@social.chiefgyk3d.com avatar

Somehow I became the freaking in my group of engineers at work. I have never done and my work paid for for the company to learn, and I’ve been rolling through and now at work and making custom for and and now looking at rolling a @grafana at work for a POC probably on AWS too. I only started doing Python a few months ago. helped a lot. The times really do change don’t they?

chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

Does anyone know how to do a @crowdstrike containment with a note in the WebUI via the on ? It’s bugging the hell out of me at work and Ops really wants that in the CS dashboard

chiefgyk3d, to python
@chiefgyk3d@social.chiefgyk3d.com avatar

Working on a autocontainment script for work, because Fusion Workflows apparently do not have a “not” statement which messes up logic. So on an lambda it is! But holy crap is the API convoluted. You have to pull by agent ID then pipe the agent ID to another call to figure out the host name. Gonna be a headache for automated tickets 🙃

I may see about sanitizing it when I’m done and putting it on GitHub it uses AWS secrets manager anyway 🤷‍♂️

0x58, to infosec

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes, but not only:

➝ 🇺🇸 🪖 Air Force denies running simulation where AI drone “killed” its operator
➝ 🇺🇸 🏂 Snowboards discloses after February attack
➝ 🇺🇸 🧪 Enzo Biochem Attack Exposes Information of 2.5M Individuals
➝ 🧠 🤖 Introducing Charlotte AI, ’s Generative AI Security Analyst
➝ 🐍 🦠 Malicious Packages Using Compiled Code to Bypass Detection
➝ 🇰🇵 🎠 N. Korean ScarCruft Hackers Exploit LNK Files to Spread
➝ 🦠 📱 New Zero-Click Hack Targets Users with Stealthy Root-Privilege
➝ 🇷🇺 🇺🇸 says U.S. accessed thousands of phones in spy plot
➝ 🇯🇵 🚗 Discloses New Data Breach Involving Vehicle, Customer Information
➝ ☁️ 👻 Organizations Warned of ‘Ghost Sites’ Exposing Sensitive Information
➝ 🔐 👀 faces $30 million fine over Ring, Alexa violations
➝ 🔐 🧱 Active Mirai Botnet Variant Exploiting Devices for Attacks
➝ 🇷🇺 🇺🇦 Russia’s ‘Silicon Valley’ hit by cyberattack; Ukrainian group claims deep access
➝ 🦠 🤖 Found in Apps With Over 420 Million Downloads
➝ 🦠 🚪 malware spread via Google Ads for , GIMP, more
➝ 👛 Southeast Asian hacking crew racks up victims, rapidly expands criminal campaign
➝ 🍏 finds bug that lets hackers bypass SIP root restrictions
➝ 🦠 🚪 zero-day abused since 2022 to drop new malware, steal data
➝ 🇬🇷 Worst cyberattack in disrupts high school exams, causes political spat
➝ 🇮🇳 🎠 Sneaky DogeRAT Trojan Poses as Popular Apps, Targets Indian Users
➝ 🇺🇸 U.S. Department of Defense releases 2023 Cyber Strategy
➝ 📱☝🏻 New BrutePrint Attack Lets Attackers Unlock Smartphones with Fingerprint Brute-Force
➝ 🇯🇵 🎠 New GobRAT Remote Access Targeting Routers in
➝ 🦠 📂 Clever ‘File Archiver In The Browser’ phishing trick uses domains

📚 This week's recommended reading is: "Fancy Bear Goes Phishing: The Dark History of the Information Age, in Five Extraordinary Hacks" by Scott J. Shapiro

Subscribe to the to have it piping hot in your inbox every Sunday ⬇️

https://0x58.substack.com/p/infosec-mashup-week-222023

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • ngwrru68w68
  • JUstTest
  • cubers
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • lostlight
  • All magazines