Quick IOC Scan With Docker, (Fri, Apr 28th)

When investigating an incident, you must perform initial tasks quickly. There is one tool in my arsenal that I&#;x26;#;39;m using to quickly scan for interesting IOCs (“Indicators of Compromise”). This tool is called Loki[1], the free version of the Thor scanner. I like this tool because you can scan for a computer (processes &#;x26; files) or a specific directory (only files) for suspicious content. The tool has many interesting YARA rules, but you can always add your own to increase the detection capabilities.

Continue reading Quick IOC Scan With Docker, (Fri, Apr 28th)→

Posted in Uncategorized

SANS.edu Research Journal: Volume 3 , (Thu, Apr 27th)

One of my privileges as dean of research for the SANS.edu college is the ability to work with some of our graduate students as they complete their research projects. More recently, I have also been lucky to advise many of our undergraduate students as they participate in our Internet Storm Center internship. You may have seen me highlight some of the work done by our students as part of diaries or as part of the daily podcast. At times, I could interview some of our students for some episodes.

Continue reading SANS.edu Research Journal: Volume 3 , (Thu, Apr 27th)→

Posted in Uncategorized

Strolling through Cyberspace and Hunting for Phishing Sites, (Wed, Apr 26th)

From time to time and as much as my limited time permits, I often explore the Internet and my DShield logs to see if I can uncover any interesting artifacts that suggest nefarious behaviour. Time-driven events such as tax filing are also considered when I perform such hunting activities. I recently discovered one such site masquerading as the Inland Revenue Authority of Singapore (IRAS) and observed some interesting points.

Continue reading Strolling through Cyberspace and Hunting for Phishing Sites, (Wed, Apr 26th)→

Posted in Uncategorized

VMware releases Security Advisory VMSA-2023-0008, multiple security vulnerabilities in VMware Workstation and Fusion with CVSS scores ranging from 7.3 – 9.3, please patch. https://www.vmware.com/security/advisories/VMSA-2023-0008.html, (Wed, Apr 26th)

———–
Yee Ching Tok, Ph.D., ISC Handler
Personal Site
Mastodon
Twitter

Continue reading VMware releases Security Advisory VMSA-2023-0008, multiple security vulnerabilities in VMware Workstation and Fusion with CVSS scores ranging from 7.3 – 9.3, please patch. https://www.vmware.com/security/advisories/VMSA-2023-0008.html, (Wed, Apr 26th)→

Posted in Uncategorized