Show me All Your Windows!, (Fri, Aug 11th)

It&#;x26;#;39;s a key point for attackers to implement anti-debugging and anti-analysis techniques. Anti-debugging means the malware will try to detect if it&#;x26;#;39;s being debugged (executed in a debugger or its execution is slower than expected). Anti-analysis refers to techniques to detect if the malware is detonated in a sandbox or by a malware analyst. In such cases, tools run in parallel with the malware to collect live data (packets, API calls, files, or registry activity).

Continue reading Show me All Your Windows!, (Fri, Aug 11th)→

Posted in Uncategorized

Some things never change ? such as SQL Authentication ?encryption?, (Thu, Aug 10th)

Fat client applications running on (usually) Windows are still extremely common in enterprises. When I look at internal penetration tests or red team engagements for any larger enterprise, it is almost 100% guaranteed that one will stumble upon such an application.

Continue reading Some things never change ? such as SQL Authentication ?encryption?, (Thu, Aug 10th)→

Posted in Uncategorized

Update: Researchers scanning the Internet, (Mon, Aug 7th)

We have been tracking researchers scanning the Internet for open ports or vulnerabilities for a few years. These groups often show up in our “top 10” lists. We do not make any general recommendations to block these IPs but we want to give you the information you need to make this decision for your network.

Continue reading Update: Researchers scanning the Internet, (Mon, Aug 7th)→

Posted in Uncategorized