PinnedCobalt Strike PowerShell Payload AnalysisI have spotted this interesting tweet from Malwar3Ninja and decided to take a look and analyse the Cobalt Strike PowerShell payload.Sep 1, 2021401Sep 1, 2021401
PinnedCobalt Strike Hunting — DLL Hijacking/Attack AnalysisDLL Hijacking via Cobalt StrikeAug 17, 20218Aug 17, 20218
PinnedCobalt Strike Hunting — Malleable C2 jQuery profile & rundll32 AnalysisMalleable C2 — jQuery profiles.Aug 5, 202113Aug 5, 202113
PinnedCobalt Strike Hunting — simple PCAP and Beacon AnalysisLegit healthcare company.Jul 21, 202190Jul 21, 202190
Published inDetect FYIHunting Malicious Infrastructure-Headers and Hardcoded/Static StringsIn my last blog Hunting Malicious Infrastructure using JARM and HTTP ResponseDec 5, 2023113Dec 5, 2023113
Threat Intel-Pivoting using CensysHunting malicious infrastructure: Muddy Water Cyberespionage Threat Actor from Iran 🇮🇷Nov 5, 202355Nov 5, 202355
APT 29 Initial Access Killchain -MITRE ATT@CK MappingAPT29/Nobelium Initial Access & ATT@CK MappingMay 23, 2023751May 23, 2023751
Published inDetect FYIHunting Malicious Infrastructure using JARM and HTTP ResponseHunting QBot C2 and Brute Ratel C4 InfrastructureMay 16, 20231082May 16, 20231082
Adversaries Infrastructure-Ransomware Groups, APTs, and Red TeamsWhat you can learn from scanning adversaries' infra?Dec 30, 2022127Dec 30, 2022127
Follina (CVE-2022–30190) & Cobalt Strike C2 -Simple AnalysisFollina CVE-2022–30190 & Cobalt Strike C2Jun 29, 20221Jun 29, 20221
Diamond Model of Intrusion Analysis in PracticeLetsDefend: SOC171-Spring4ShellMay 30, 2022221May 30, 2022221
Server-Side Request Forgery (SSRF)- PortSwigger LabsLab: Blind SSRF with out-of-band detectionApr 21, 20222Apr 21, 20222
Server-Side Request Forgery (SSRF)- PortSwigger LabsLab: SSRF with filter bypass via open redirection vulnerabilityApr 20, 20221Apr 20, 20221
Server-Side Request Forgery (SSRF)- PortSwigger LabsLab: SSRF with blacklist-based input filterApr 18, 2022Apr 18, 2022
Server-Side Request Forgery (SSRF)- PortSwigger LabsLab: Basic SSRF against another back-end systemApr 17, 20223Apr 17, 20223