#dfir

155 posts · Last used 9d

2026-09-26 RDP #Honeypot IOCs - 366 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 66.163.119.35 - 240 104.64.217.122 - 30 165.22.190.202 - 18 Top ASNs: AS63023 - 240 AS63949 - 45 AS396982 - 36 Top Accounts: hello - 300 rg5hhbrn - 12 Administr - 9 Top ISPs: GTHost - 240 Google LLC - 36 Akamai Technologies, Inc. - 33 Top Clients: Unknown - 366 Top Software: Unknown - 366 Top Keyboards: Unknown - 366 Top IP Classification: Unknown - 243 hosting - 114 hosting & proxy - 9 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
1
0
0
0
State-aligned threat actors continue to evolve their operations and infrastructure tactics. Feike Hacquebord will be speaking at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) about APT campaigns by Russia-, China-, and DPRK-aligned actors targeting Europe in 2026. Feike will examine China-aligned residential proxy networks built on compromised IoT devices, DPRK-aligned operations run from static Russian IP addresses and hundreds of VPS servers, and a decade of Pawn Storm (APT28/Fancy Bear) activity. He will also explain how domestic Chinese AI capabilities have reduced China-aligned actors' dependence on frontier Western models. Seating is limited. Register now to secure your spot: https://luma.com/0qtkw49c #dfir #threatintel #apt
0
0
0
0
2026-09-23 RDP #Honeypot IOCs - 216 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 20.51.184.62 - 39 104.64.217.122 - 27 80.66.83.43 - 18 Top ASNs: AS8075 - 39 AS396982 - 36 AS63949 - 36 Top Accounts: hello - 84 Administr - 24 (empty) - 21 Top ISPs: Microsoft Corporation - 39 Google LLC - 36 Akamai Technologies, Inc. - 36 Top Clients: Unknown - 216 Top Software: Unknown - 216 Top Keyboards: Unknown - 216 Top IP Classification: hosting - 195 Unknown - 9 hosting & proxy - 6 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
RE: https://infosec.exchange/@tazwake/117321231170069103 #Dfir #Incidentresponse
Quoting
Reading the Linux Process Tree During Triage A flat process list tells you what is running. The tree tells you what started it. This guide covers reading Linux process lineage, exposing renamed processes and recovering a deleted binary through /proc. https://www.halkynconsulting.co.uk/a/2026/09/linux-process-tree/
Open quoted post
0
0
0
0
---------------- 🛠️ Tool =================== IRDoc is a self-hostable, open-core incident response documentation platform designed for SOC analysts, IR engineers, and MSSPs. It provides a structured workspace to document an incident from initial detection through the final report, replacing the fragmented workflow of switching between a ticket system, a Word document, and a SharePoint folder. 🔹 Key Features • Timeline-first workspace: Chronological event logging across detection, analysis, containment, evidence, and communications phases. This approach ensures that the report is built progressively as the investigation unfolds. • IOC management: Automated tracking and detection of IPs, domains, hashes, emails, and URLs within the platform. This eliminates the need to maintain separate IOC lists. • Evidence attachments: Drag-and-drop or paste screenshots directly into the incident timeline. This keeps visual evidence contextually aligned with the investigation steps. • Task management: Phase-grouped tasks generated from incident templates. Analysts can track containment and remediation actions without leaving the workspace. • Inbound webhook API: Create cases from ServiceDesk Plus, Jira, or any system capable of POSTing JSON. This allows seamless integration with existing alerting pipelines. • Investigation graph: Visual relationship map linking IOCs, timeline entries, and attached evidence. This provides a quick overview of how different components of the incident interact. • Self-hosted architecture: Incident data remains on the deploying organization's infrastructure, addressing data residency and privacy concerns. 🔹 Technical Implementation The core repository is licensed under AGPL-3.0. The project integrates automated security scanning, including CodeQL, secret scanning, dependency audits, and an OpenSSF Scorecard. The maintainers state they aim to release patches for critical vulnerabilities within 24 hours of confirmation. Inbound webhooks allow integration with existing ticketing systems, ensuring IRDoc can act as a dedicated documentation layer rather than a replacement for alerting or case creation. 🔹 Use Cases Primary use cases include structured IR case management for SOCs that require strict data residency via self-hosting. It is also suited for MSSPs needing a structured documentation framework that can map relationships between indicators and evidence across multiple client incidents. The visual investigation graph is particularly useful for complex incidents involving multiple overlapping IOCs. 🔹 Limitations The core is free under AGPL-3.0, but the open-core model implies there may be paid features or enterprise extensions not detailed in the repository. The repository does not specify the underlying database or deployment framework in the provided summary, though documentation is available at their docs site. Performance under high concurrency is not documented. 🔹 tool #IncidentResponse #SOC #OpenSource #DFIR 🔗 Source: https://github.com/soc-irdoc/irdoc-app
0
0
0
0
Following @volexity@infosec.exchange’s September 9 blog post on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity discovered another threat actor, UTA0565, had been using the same exploits on Sept 3-4, 2026, while they were still unpatched.   UTA0565 used multiple fake websites, posing as media organizations and an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening.   Full details and IOCs can be found here: https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/   #DFIR #threatintel
0
0
0
0
2026-09-19 RDP #Honeypot IOCs - 183 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 104.64.217.122 - 30 118.69.191.219 - 24 165.22.190.202 - 18 Top ASNs: AS396982 - 48 AS63949 - 36 AS18403 - 24 Top Accounts: hello - 78 Administr - 21 ident - 18 Top ISPs: Google LLC - 48 Akamai Technologies, Inc. - 36 Vietnam Internet Network Information Center - 24 Top Clients: Unknown - 183 Top Software: Unknown - 183 Top Keyboards: Unknown - 183 Top IP Classification: hosting - 120 Unknown - 39 proxy - 18 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
2026-09-18 RDP #Honeypot IOCs - 756 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 134.209.180.117 - 510 104.64.217.122 - 87 118.69.191.219 - 42 Top ASNs: AS14061 - 510 AS63949 - 90 AS18403 - 42 Top Accounts: hello - 642 Administr - 18 ident - 18 Top ISPs: DigitalOcean, LLC - 510 Akamai Technologies, Inc. - 90 Vietnam Internet Network Information Center - 42 Top Clients: Unknown - 756 Top Software: Unknown - 756 Top Keyboards: Unknown - 756 Top IP Classification: hosting - 684 Unknown - 48 proxy - 18 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs). I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection. #DFIR #IDS #Honeypots
13
2
8
1
2026-09-15 RDP #Honeypot IOCs - 2343 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 147.182.250.28 - 2263 104.64.217.122 - 10 80.66.83.43 - 6 Top ASNs: AS14061 - 2270 AS63949 - 15 AS4766 - 13 Top Accounts: hello - 2298 142.93.8.59 - 11 anonymous - 7 Top ISPs: DigitalOcean, LLC - 2270 Akamai Technologies, Inc. - 15 Korea Telecom - 13 Top Clients: Unknown - 2343 Top Software: Unknown - 2343 Top Keyboards: Unknown - 2343 Top IP Classification: hosting - 2317 Unknown - 18 hosting & proxy - 4 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
iLEAPP, ALEAPP, RLEAPP, VLEAPP and DLEAPP v2026.4.0 are out! 💽 Raw disk images and E01s read directly 🖥️ GUI stays responsive while processing 📱 iLEAPP: Garmin Connect, Tutanota, MEGA 🤖 ALEAPP: Blink, Avast Cleanup, Kwai, YouCam Perfect 📑 RLEAPP: Synchronoss DV access log workbooks, quarantined CyberTip media 🚗 VLEAPP: E01, HFS+ and APFS volumes 🍎 DLEAPP: macOS iMessage, Safari, Keychain, Slack Desktop https://leapps.org/releases #DFIR #DigitalForensics #FOSS #MobileForensics
0
1
0
0
2026-09-09 RDP #Honeypot IOCs - 3946 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 152.42.198.23 - 2200 168.144.34.49 - 1666 80.66.83.43 - 12 Top ASNs: AS14061 - 3878 AS396982 - 28 AS216473 - 12 Top Accounts: hello - 3900 Administr - 12 Test - 4 Top ISPs: DigitalOcean, LLC - 3878 Google LLC - 28 Bashinskii Vadim Ruslanovich - 12 Top Clients: Unknown - 3946 Top Software: Unknown - 3946 Top Keyboards: Unknown - 3946 Top IP Classification: hosting - 3940 Unknown - 4 hosting & proxy - 2 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
2026-08-08 RDP #Honeypot IOCs - 2091 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 155.117.13.211 - 726 170.64.227.228 - 642 206.189.58.63 - 564 Top ASNs: AS14061 - 1236 AS16276 - 726 AS396982 - 30 Top Accounts: hello - 2007 Domain - 18 zgrab - 6 Top ISPs: DigitalOcean, LLC - 1236 OVH SAS - 726 Google LLC - 30 Top Clients: Unknown - 2091 Top Software: Unknown - 2091 Top Keyboards: Unknown - 2091 Top IP Classification: hosting - 1320 Unknown - 765 proxy - 6 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
2026-08-08 RDP #Honeypot IOCs - 1394 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 155.117.13.211 - 484 170.64.227.228 - 428 206.189.58.63 - 376 Top ASNs: AS14061 - 824 AS16276 - 484 AS396982 - 20 Top Accounts: hello - 1338 Domain - 12 zgrab - 4 Top ISPs: DigitalOcean, LLC - 824 OVH SAS - 484 Google LLC - 20 Top Clients: Unknown - 1394 Top Software: Unknown - 1394 Top Keyboards: Unknown - 1394 Top IP Classification: hosting - 880 Unknown - 510 proxy - 4 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
2026-08-08 RDP #Honeypot IOCs - 697 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 155.117.13.211 - 242 170.64.227.228 - 214 206.189.58.63 - 188 Top ASNs: AS14061 - 412 AS16276 - 242 AS396982 - 10 Top Accounts: hello - 669 Domain - 6 zgrab - 2 Top ISPs: DigitalOcean, LLC - 412 OVH SAS - 242 Google LLC - 10 Top Clients: Unknown - 697 Top Software: Unknown - 697 Top Keyboards: Unknown - 697 Top IP Classification: hosting - 440 Unknown - 255 proxy - 2 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0