Video: Analyzing Malicious OneNote Documents, (Sun, Feb 5th)
I recorded a video for my diary entry “Detecting (Malicious) OneNote Files“.
Continue reading Video: Analyzing Malicious OneNote Documents, (Sun, Feb 5th)
Collaborate Disseminate
I recorded a video for my diary entry “Detecting (Malicious) OneNote Files“.
Continue reading Video: Analyzing Malicious OneNote Documents, (Sun, Feb 5th)
If you are looking for a malware sandbox that is easy to install and maintain, Assenblyline (AL) &#;x26;#;x5b;1&#;x26;#;x5d; is likely the system you want to be part of your toolbox. “Once a file is submitted to Assemblyline, the system will automatically perform multiple checks to determine how to best process the file. One of Assemblyline&#;x26;#;39;s most powerful functionalities is its recursive analysis model.”&#;x26;#;x5b;2&#;x26;#;x5d;
Continue reading Assemblyline as a Malware Analysis Sandbox, (Sat, Feb 4th)
—————
Jim Clausing, GIAC GSE #26
jclausing –at– isc [dot] sans (dot) edu
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Friday, February 3rd, 2023 https://isc.sans.edu/podcastdetail.html?id=8354, (Fri, Feb 3rd)
I don&#;x26;#;39;t get nearly as much opportunity to play with packets these days as I did in the first 5-10 years I was a handler and I miss it. I was looking back through some of my old diaries and realized that in the years since I wrote some of them, we have at least a generation of folks who have entered the field. So I thought that on (the day after) Groundhog Day, it might be time to point folks back to some stuff I wrote earlier. Note, some of the tools have changed/evolved, so ethereal is now wireshark and instead of hping3 I would probably use scapy, but here are 2 of my favorite diaries from the past. Check them out, [1] is from 2006 and [2] is from 2009.
Continue reading Check out a couple of my older posts, (Thu, Feb 2nd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Thursday, February 2nd, 2023 https://isc.sans.edu/podcastdetail.html?id=8352, (Thu, Feb 2nd)
Having a new pfSense firewall in place gives some opportunities to do a bit more with the device. Maintaining some full packet captures was an item on my “to do” list. The last 24 hours is usually sufficient for me since I&#;x26;#;39;m usually looking at alerts within the same day. I decided to do rotating packet captures based on file size. This allows me to capture packets, saving files of a specific size and keeping a specified number of files.
Continue reading Rotating Packet Captures with pfSense, (Wed, Feb 1st)
We are starting to see malicious OneNote documents (cfr. Xavier&#;x26;#;39;s diary entry “A First Malicious OneNote Document“).
Continue reading Detecting (Malicious) OneNote Files, (Wed, Feb 1st)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Continue reading ISC Stormcast For Wednesday, February 1st, 2023 https://isc.sans.edu/podcastdetail.html?id=8350, (Wed, Feb 1st)