Search timeline

People

New to threat hunting and not sure where start? Need some inspiration for your next hunt? We've got you covered!
Cyber Threat Detection For You đŸ‘£
Digital Forensics and Incident Response. Talk to me about engineering detection and managing response. Views on this channel are those of my own.
In #ThreatHunting or #DFIR, we usually search for the presence of something. Sometimes, absence is also a good indicator of malicious activity. Ex: If you have a scheduled task that runs every hour and does NOTHING (file creation, network conn., etc.), it might be malicious.đŸ’¡
Quote Tweet
Question for Red teamers: When using scheduled task for persistence, do you have to check if the malicious process is already running so that you can exit without spawning a duplicate process? #redteam
7
15
Building out a #ThreatHunting program can be scary! shares his ‘Crawl, Walk, Run’ approach, which tactically breaks down the individual Threat Hunt building process & provides organizations a strategic option to meet their program objectives
1
9
36
This is a great notebook - making IoC extraction from #ThreatHunting reports quick and simple with the help of #MSTICPy
Quote Tweet
I coded a simple IOCs extractor from an url in Python to show how to extract IOCs from threat report using MSTICpy library! You can play with it in binder and adapt the code if you like! đŸ¤“@msticpy #ioc #python #Jupyter #ThreatHunting đŸ”¬Notebook: github.com/fr0gger/jupyte
Show this thread
Embedded video
GIF
9
44
Let's talk network recon and discovery! This week's #techtalktuesday dives into indicators associated with #apt34, #apt39, and generic approaches. We also talk about how attackers evade signatures and how to deal with this during #threathunting efforts.
3
50
#ThreatHunting Tip of the day: Hunt command line arguments for software management automation tools such as Choclatey & Hombrew on your endpoints. Threat actors can utilise both to install whatever packages they choose and will likely not get flagged by your AV/EDR.
Image
2
Show this thread