Get an RSS feed of RansomLook (ransomware posts,leaks) and DDoSia (DDoS toolkit) via the @circl@social.circl.lu Mastodon server by adding '.rss' to the handle. Example: @Ransomlook.rss@social.circl.lu. Also check out @adulau@infosec.exchange 'Bring back RSS for operational security'! #OpSec https://archives.pass-the-salt.org/Pass%20the%20SALT/2024/slides/PTS2024-TALK-03-RSS.pdf
Koen Van Impe
Freelancer. CSIRT. Incident Response. Threat Intelligence. MISP. Security, IDS, Linux, OpenBSD, Honeypots, Jazz, Literature, Modern Art.
You can now browse the @misp@misp-community.org playbooks on GitHub Pages: https://misp.github.io/misp-playbooks/ . The playbooks are automatically converted into easy-to-navigate HTML pages. Dive in and explore!
New @misp@misp-community.org playbook! Tackle the week with JARM fingerprint investigations to track threat actor infrastructure using @censys@infosec.exchange , @shodan@mastodon.shodan.io and MISP. Boost your #cti game with #automation and #infrastructure insights. https://github.com/MISP/misp-playbooks/blob/main/misp-playbooks/pb_jarm_verification-with_output.ipynb
Further enhance phishing investigations with @MISPProject@mastodon.opencloud.lu playbooks! 'URL Remediation' streamlines finding abuse contacts via AbuseFinder, LookyLoo , @firstdotorg@infosec.exchange , and RDAP, while reporting malicious sites to MSRC, Google Safe Browsing and Netcraft. https://github.com/MISP/misp-playbooks/blob/main/misp-playbooks/pb_url_remediation-with_output.ipynb
There's a new @misp@misp-community.org playbook waiting for you! Search in @TimesketchProj@infosec.exchange for MISP indicators. Plot the results in a graph, create a saved search in Timesketch, report sightings in MISP, and send a summary to Mattermost. #cti #automation #playbooks https://github.com/MISP/misp-playbooks/blob/main/misp-playbooks/pb_timesketch_search_query_sightings-with_output.ipynb
I created a small script to extract unique hostnames and domains from the DDoSia configuration objects shared via @misp@misp-community.org . Post at https://www.vanimpe.eu/2024/10/08/extract-hostnames-and-domains-from-ddosia-misp-object/ ; Script: https://github.com/cudeso/tools/blob/master/ddosia-extract/parse_ddosia.py #DDOS #DDOSIA
Interesting approach on manipulating argv[0] to mislead security tools and analysts. A clever tactic for obfuscation! https://www.wietzebeukema.nl/blog/why-bother-with-argv0
Simplify phishing investigations with the @misp@misp-community.org "Query URL Reputation" playbook. Enrich URLs using Lookyloo @urlscanio@twtr.plus @virustotal@bird.makeup , and more. #automation https://github.com/MISP/misp-playbooks/blob/main/misp-playbooks/pb_query_url_reputation-with_output.ipynb
New conversion scripts bridge @misp@misp-community.org playbooks and CACAO ( @oasisopen@bird.makeup
) security playbooks. Still an initial version but significantly simplifies integration between both formats. https://github.com/MISP/misp-playbooks/blob/main/documentation/MISP_CACAO.md #CTI #automation #soar
Honeypot technology may seem old, but it’s still very much in play. @ncsc is exploring honeypots & honeytokens as part of cyber defence strategy "Building a nation-scale evidence base for cyber deception". Opportunities @circl@social.circl.lu #D4 and @shadowserver@infosec.exchange https://www.ncsc.gov.uk/blog-post/building-a-nation-scale-evidence-base-for-cyber-deception
A new @misp@misp-community.org playbook to help with curation of decayed indicators. Use the custom model of the playbook or one of the MISP build-in models. Decayed indicators are disabled and tagged. #cti https://github.com/MISP/misp-playbooks/blob/main/misp-playbooks/pb_curate_disable_decayed_indicators-with_output.ipynb
Happy to have contributed to the @enisa_eu@respublicae.eu Threat Landscape 2024. Explore the threats and trends observed during the latest reporting period on threat actors activity, ransomware, malware, social engineering and more. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024 #ETL #CTI #ThreatLandscape
Earth Baku, tied to APT41, is expanding operations into Europe. Targeting public-facing IIS servers, using Google & Cloudflare for C2, and possibly exfiltrating via MEGA. @TrendMicro@infosec.exchange https://www.trendmicro.com/en_us/research/24/h/earth-baku-latest-campaign.html Indicators in botvrij.eu https://www.botvrij.eu/data/feed-osint/739fc559-c1ea-427b-9dd6-4999276f537c.json
After MISP2Sentinel already allowed you to share indicators from MISP with Microsoft Sentinel, you can now use a @misp@misp-community.org playbook to create MISP events from Sentinel incidents, complete with entity-based indicators. @msftsecintel@twtr.plus #cti #automation https://github.com/MISP/misp-playbooks/blob/main/misp-playbooks/pb_event_from_sentinel_incidents-with_output.ipynb
A @misp@misp-community.org tip of the week: You can report security vulnerabilities for MISP or related MISP project repositories to CIRCL. You can encrypt your report with the public GPG key 'CA57 2205 C002 4E06 BA70 BE89 EAAD CFFC 22BD 4CD5'. https://github.com/cudeso/misp-tip-of-the-week
I'm working on "Proving the Value of Cyber Threat Intelligence," to support demonstrate the impact of #CTI in organisations. Early work, and open to feedback and suggestions for improvement! https://github.com/cudeso/proof-value-cti
The ECB warns that despite record-high profitability, banks fail to adequately address structural weaknesses, lack sound recovery capabilities and need to further improve their cyber #resilience. #CyberSecurity #Banking https://www.bankingsupervision.europa.eu/press/blog/2024/html/ssm.blog240726~7bfb4e2267.en.html https://www.bankingsupervision.europa.eu/banking/priorities/html/ssm.supervisory_priorities202312~a15d5d36ab.en.html#toc5
Kick off the week with a new @misp@misp-community.org playbook! Query Elasticsearch @elastic@twtr.plus for threat intelligence from custom MISP searches, plot the results in a graph, report sightings in MISP, and send a summary to Mattermost. #cti #automation #playbooks https://github.com/MISP/misp-playbooks/blob/main/misp-playbooks/pb_elasticsearch_matches_sightings-with_output.ipynb