Article: Rebuilding My Playbook .. Knowledge Base - published about 7 years ago. Content: I find myself in the situation where I lost my personal playbook by user error. I accidentally deleted the VM where I ran xWiki where it was kept and did not realized the mistake until days later. Even if painful to rebuild it is a good opportunity to think on how to better organize it and put it in a more flexible format. I Initially called my collection o... https://www.darkoperator.com/blog/2017/12/10/nmba1hrmndda8m3eo7ipoh7bxvphz4 Published: 2017 12 13 11:00:00 Received: 2022 10 01 03:48:55 Feed: Blog Source: Blog Category: Cyber Security Topic: Cyber Security |
Article: when windows 10 installer says its the most secure windows ever... - published about 7 years ago. Content: https://securityreactions.tumblr.com/post/168478724214 Published: 2017 12 12 22:00:27 Received: 2021 06 06 09:04:59 Feed: Infosec Reactions Source: Infosec Reactions Category: Cyber Security Topic: Cyber Security |
Article: The awkward truth about how Lateral Thinking actually works in an intrusion attempt - published about 7 years ago. Content: https://securityreactions.tumblr.com/post/168476893608 Published: 2017 12 12 21:00:41 Received: 2021 06 06 09:04:59 Feed: Infosec Reactions Source: Infosec Reactions Category: Cyber Security Topic: Cyber Security |
|
Article: Equifax breach response - published about 7 years ago. Content: https://securityreactions.tumblr.com/post/168475151630 Published: 2017 12 12 20:00:32 Received: 2021 06 06 09:04:59 Feed: Infosec Reactions Source: Infosec Reactions Category: Cyber Security Topic: Cyber Security |
|
Article: getting users to follow best practices - published about 7 years ago. Content: https://securityreactions.tumblr.com/post/168473430890 Published: 2017 12 12 19:00:27 Received: 2021 06 06 09:04:59 Feed: Infosec Reactions Source: Infosec Reactions Category: Cyber Security Topic: Cyber Security |
Article: "We're only concerned about vulnerabilities on production servers, they're the important ones." - published about 7 years ago. Content: https://securityreactions.tumblr.com/post/168471747014 Published: 2017 12 12 18:00:29 Received: 2021 06 06 09:04:59 Feed: Infosec Reactions Source: Infosec Reactions Category: Cyber Security Topic: Cyber Security |
|
Article: 4056318 - Guidance for securing AD DS account used by Azure AD Connect for directory synchronization - Version: 1.0 - published about 7 years ago. Content: Revision Note: V1.0 (December 12, 2017): Advisory published.Summary: Microsoft is releasing this security advisory to provide information regarding security settings for the AD DS (Active Directory Domain Services) account used by Azure AD Connect for directory synchronization. This advisory also provides guidance on what on-premises AD administrators can do... https://technet.microsoft.com/en-us/library/security/4056318 Published: 2017 12 12 18:00:00 Received: 2022 04 14 18:03:35 Feed: Latest Security Advisories Source: Latest Security Advisories Category: Alerts Topic: Vulnerabilities |
|
Article: Plan for security flaws - published about 7 years ago. Content: https://www.ncsc.gov.uk/guidance/plan-security-flaws Published: 2017 12 10 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
Article: New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit - published about 7 years ago. Content: Less than a week after Microsoft issued a patch for CVE-2017-11882 on Nov. 14, 2017, FireEye observed an attacker using an exploit for the Microsoft Office vulnerability to target a government organization in the Middle East. We assess this activity was carried out by a suspected Iranian cyber espionage threat group, whom we refer to as APT34, usin... http://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html Published: 2017 12 07 17:00:00 Received: 2021 11 02 23:00:12 Feed: FireEye Blog Source: FireEye Blog Category: Cyber Security Topic: Cyber Security |
|
Article: Weekly Threat Report 8th December 2017 - published about 7 years ago. Content: https://www.ncsc.gov.uk/report/weekly-threat-report-8th-december-2017 Published: 2017 12 07 05:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
Article: Cracking open the next batch - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/cracking-open-next-batch Published: 2017 12 04 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: CyBOK - the scope - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/cybok-scope Published: 2017 12 01 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Managing supply chain risk in cloud-enabled products - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/managing-supply-chain-risk-cloud-enabled-products Published: 2017 12 01 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: CyBOK - the scope - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/cybok-scope Published: 2017 12 01 00:00:00 Received: 2021 04 18 14:04:39 Feed: NCSC – Blog Feed Source: National Cyber Security Centre (NCSC) Category: Blogs Topic: Cyber Security |
Article: Managing supply chain risk in cloud-enabled products - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/managing-supply-chain-risk-cloud-enabled-products Published: 2017 12 01 00:00:00 Received: 2021 04 18 14:04:39 Feed: NCSC – Blog Feed Source: National Cyber Security Centre (NCSC) Category: Blogs Topic: Cyber Security |
|
Article: Weekly Threat Report 1st December 2017 - published about 7 years ago. Content: https://www.ncsc.gov.uk/report/weekly-threat-report-1st-december-2017 Published: 2017 11 30 05:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Applying the Cloud Security Principles in practice: a case study - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/applying-the-cloud-security-principles Published: 2017 11 30 00:00:00 Received: 2022 03 31 11:41:21 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Managing the risk of cloud-enabled products - published about 7 years ago. Content: https://www.ncsc.gov.uk/guidance/managing-risk-cloud-enabled-products Published: 2017 11 30 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Operational Look at Sysinternals Sysmon 6.20 Update - published about 7 years ago. Content: Sysmon has been a game changer for many organizations allowing their teams to fine tune their detection of malicious activity when combined with tools that aggregate and correlate events. A new version of Symon was recently released. Version 6.20 fixes bugs and adds new features. Some the of the note worthy changes for me are:Enhancements in WMI Logging. Ab... https://www.darkoperator.com/blog/2017/11/24/operational-look-at-sysinternals-sysmon-620-update Published: 2017 11 27 11:00:00 Received: 2023 12 19 11:23:26 Feed: Blog Source: Blog Category: Cyber Security Topic: Cyber Security |
|
Article: NCSC advice for Uber customers and drivers - published about 7 years ago. Content: https://www.ncsc.gov.uk/guidance/ncsc-advice-uber-customers-and-drivers Published: 2017 11 26 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Reflecting on your development processes: fast-track your learning - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/reflecting-your-development-processes-fast-track-your-learning Published: 2017 11 24 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Weekly Threat Report 24th November 2017 - published about 7 years ago. Content: https://www.ncsc.gov.uk/report/weekly-threat-report-24th-november-2017 Published: 2017 11 23 05:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
Article: Firmware bugs are like buses - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/firmware-bugs-are-buses Published: 2017 11 23 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Some Comments and Thoughts on Tradecraft - published about 7 years ago. Content: I have been writing a series on the new Windows Defender Exploit Guard features on Attack Surface Reduction where I cover my research on it. I'm researching the controls to add the information in to my personal playbook. Surprisingly in conversations with some Red Teamers I know they dismissed the information as it is a Blue/Defense technology. These comment... https://www.darkoperator.com/blog/2017/11/20/some-comments-and-thoughts-on-tradecraft Published: 2017 11 20 11:00:00 Received: 2021 06 06 09:05:08 Feed: Blog Source: Blog Category: Cyber Security Topic: Cyber Security |
|
Article: This Black Friday, we're giving away... advice! - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/black-friday Published: 2017 11 20 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: A day in the life of an NCSC vulnerability researcher - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/day-life-ncsc-vulnerability-researcher Published: 2017 11 17 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
|
Article: Weekly Threat Report 17th November 2017 - published about 7 years ago. Content: https://www.ncsc.gov.uk/report/weekly-threat-report-17th-november-2017 Published: 2017 11 16 05:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
Article: Windows Defender Exploit Guard ASR Rules for Office - published about 7 years ago. Content: On this blog post I continue looking at the ASR rules, this time I'm looking at the ASR rules for Office. The ASR rules for office are:Block Office applications from creating child processesBlock Office applications from creating executable contentBlock Office applications from injecting code into other processesBlock Win32 API calls from Office macroThese ... https://www.darkoperator.com/blog/2017/11/11/windows-defender-exploit-guard-asr-rules-for-office Published: 2017 11 14 11:00:00 Received: 2023 12 19 11:23:26 Feed: Blog Source: Blog Category: Cyber Security Topic: Cyber Security |
|
Article: Wholesome guidance from the Sociotechnical Security Group - published about 7 years ago. Content: https://www.ncsc.gov.uk/blog-post/wholesome-guidance-sociotechnical-security-group Published: 2017 11 14 00:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
Article: Oracle Security Alert for CVE-2017-10269 - 13 November 2017
- published about 7 years ago. Content: http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html Published: 2017 11 13 19:30:54 Received: 2021 06 06 09:03:27 Feed: Oracle Security Alerts Source: Oracle Security Alerts Category: Alerts Topic: Vulnerabilities |
|
Article: Weekly Threat Report 10th November 2017 - published about 7 years ago. Content: https://www.ncsc.gov.uk/report/weekly-threat-report-10th-november-2017 Published: 2017 11 09 05:00:00 Received: 2021 04 18 14:04:48 Feed: NCSC – All Feeds Source: National Cyber Security Centre (NCSC) Category: All Topic: Cyber Security |
Article: Windows Defender Exploit Guard ASR Obfuscated Script Rule - published about 7 years ago. Content: On this blog post I will cover my testing of the Attack Surface Reduction rule for Potentially Obfuscated Scripts. This is one of the features that intrigued me the most. One obfuscates the scripts for several reasons:Bypass detection controls like AV, automatic log analysis and other controls. Hinder analysis of the script to determine its purpose and actio... https://www.darkoperator.com/blog/2017/11/8/windows-defender-exploit-guard-asr-obfuscated-script-rule Published: 2017 11 08 12:00:00 Received: 2023 12 19 11:23:26 Feed: Blog Source: Blog Category: Cyber Security Topic: Cyber Security |
|
Click to Open Code Editor