NETSUPPORT RAT |
2020-02-05 | Brad Duncan | Fake browser update pages are "still a thing" |
NETSUPPORT |
2024-06-17/a> | Xavier Mertens | New NetSupport Campaign Delivered Through MSIX Packages |
2023-08-18/a> | Xavier Mertens | From a Zalando Phishing to a RAT |
2022-10-21/a> | Brad Duncan | sczriptzzbn inject pushes malware for NetSupport RAT |
2020-02-05/a> | Brad Duncan | Fake browser update pages are "still a thing" |
RAT |
2025-02-27/a> | Xavier Mertens | Njrat Campaign Using Microsoft Dev Tunnels |
2025-01-03/a> | Xavier Mertens | SwaetRAT Delivery Through Python |
2024-12-17/a> | Xavier Mertens | Python Delivering AnyDesk Client as RAT |
2024-11-05/a> | Xavier Mertens | Python RAT with a Nice Screensharing Feature |
2024-08-14/a> | Xavier Mertens | Multiple Malware Dropped Through MSI Package |
2024-06-17/a> | Xavier Mertens | New NetSupport Campaign Delivered Through MSIX Packages |
2024-05-31/a> | Xavier Mertens | "K1w1" InfoStealer Uses gofile.io for Exfiltration |
2024-03-28/a> | Xavier Mertens | From JavaScript to AsyncRAT |
2023-12-23/a> | Xavier Mertens | Python Keylogger Using Mailtrap.io |
2023-12-20/a> | Guy Bruneau | How to Protect your Webserver from Directory Enumeration Attack ? Apache2 [Guest Diary] |
2023-11-18/a> | Xavier Mertens | Quasar RAT Delivered Through Updated SharpLoader |
2023-08-20/a> | Guy Bruneau | SystemBC Malware Activity |
2023-08-18/a> | Xavier Mertens | From a Zalando Phishing to a RAT |
2023-08-11/a> | Xavier Mertens | Show me All Your Windows! |
2023-06-29/a> | Brad Duncan | GuLoader- or DBatLoader/ModiLoader-style infection for Remcos RAT |
2023-06-16/a> | Xavier Mertens | Another RAT Delivered Through VBS |
2023-05-30/a> | Brad Duncan | Malspam pushes ModiLoader (DBatLoader) infection for Remcos RAT |
2023-05-20/a> | Xavier Mertens | Phishing Kit Collecting Victim's IP Address |
2023-05-19/a> | Xavier Mertens | When the Phisher Messes Up With Encoding |
2023-05-14/a> | Guy Bruneau | VMware Aria Operations addresses multiple Local Privilege Escalations and a Deserialization issue |
2023-05-07/a> | Didier Stevens | Quickly Finding Encoded Payloads in Office Documents |
2023-05-03/a> | Xavier Mertens | Increased Number of Configuration File Scans |
2023-03-12/a> | Guy Bruneau | AsynRAT Trojan - Bill Payment (Pago de la factura) |
2023-03-11/a> | Xavier Mertens | Overview of a Mirai Payload Generator |
2022-10-21/a> | Brad Duncan | sczriptzzbn inject pushes malware for NetSupport RAT |
2022-09-22/a> | Xavier Mertens | RAT Delivered Through FODHelper |
2022-07-28/a> | Johannes Ullrich | Exfiltrating Data With Bookmarks |
2022-06-16/a> | Xavier Mertens | Houdini is Back Delivered Through a JavaScript Dropper |
2022-06-04/a> | Guy Bruneau | Spam Email Contains a Very Large ISO file |
2022-05-20/a> | Xavier Mertens | A 'Zip Bomb' to Bypass Security Controls & Sandboxes |
2022-05-05/a> | Brad Duncan | Password-protected Excel spreadsheet pushes Remcos RAT |
2022-05-03/a> | Rob VandenBrink | Finding the Real "Last Patched" Day (Interim Version) |
2022-03-11/a> | Xavier Mertens | Keep an Eye on WebSockets |
2022-03-09/a> | Xavier Mertens | Infostealer in a Batch File |
2022-02-18/a> | Xavier Mertens | Remcos RAT Delivered Through Double Compressed Archive |
2022-02-11/a> | Xavier Mertens | CinaRAT Delivered Through HTML ID Attributes |
2022-01-07/a> | Xavier Mertens | Custom Python RAT Builder |
2021-12-01/a> | Xavier Mertens | Info-Stealer Using webhook.site to Exfiltrate Data |
2021-11-04/a> | Brad Duncan | October 2021 Forensic Contest: Answers and Analysis |
2021-09-01/a> | Brad Duncan | STRRAT: a Java-based RAT that doesn't care if you have Java |
2021-06-21/a> | Rick Wanner | Mitre CWE - Common Weakness Enumeration |
2021-04-09/a> | Xavier Mertens | No Python Interpreter? This Simple RAT Installs Its Own Copy |
2021-03-31/a> | Xavier Mertens | Quick Analysis of a Modular InfoStealer |
2021-03-04/a> | Xavier Mertens | From VBS, PowerShell, C Sharp, Process Hollowing to RAT |
2021-02-24/a> | Brad Duncan | Malspam pushes GuLoader for Remcos RAT |
2021-02-04/a> | Bojan Zdrnja | Abusing Google Chrome extension syncing for data exfiltration and C&C |
2020-10-14/a> | Xavier Mertens | Nicely Obfuscated Python RAT |
2020-09-30/a> | Johannes Ullrich | Scans for FPURL.xml: Reconnaissance or Not? |
2020-09-28/a> | Xavier Mertens | Some Tyler Technologies Customers Targeted with The Installation of a Bomgar Client |
2020-08-25/a> | Xavier Mertens | Keep An Eye on LOLBins |
2020-08-18/a> | Xavier Mertens | Using API's to Track Attackers |
2020-08-10/a> | Bojan Zdrnja | Scoping web application and web service penetration tests |
2020-08-04/a> | Johannes Ullrich | Internet Choke Points: Concentration of Authoritative Name Servers |
2020-05-14/a> | Rob VandenBrink | Patch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe |
2020-04-17/a> | Xavier Mertens | Weaponized RTF Document Generator & Mailer in PowerShell |
2020-02-05/a> | Brad Duncan | Fake browser update pages are "still a thing" |
2020-01-10/a> | Xavier Mertens | More Data Exfiltration |
2019-10-29/a> | Xavier Mertens | Generating PCAP Files from YAML |
2019-09-27/a> | Xavier Mertens | New Scans for Polycom Autoconfiguration Files |
2019-09-25/a> | Brad Duncan | Malspam pushing Quasar RAT |
2019-09-19/a> | Xavier Mertens | Agent Tesla Trojan Abusing Corporate Email Accounts |
2019-09-19/a> | Xavier Mertens | Blocklisting or Whitelisting in the Right Way |
2019-04-26/a> | Rob VandenBrink | Pillaging Passwords from Service Accounts |
2019-04-24/a> | Rob VandenBrink | Where have all the Domain Admins gone? Rooting out Unwanted Domain Administrators |
2019-03-06/a> | Xavier Mertens | Keep an Eye on Disposable Email Addresses |
2018-11-27/a> | Rob VandenBrink | Data Exfiltration in Penetration Tests |
2018-09-19/a> | Rob VandenBrink | Certificates Revisited - SSL VPN Certificates 2 Ways |
2018-09-05/a> | Rob VandenBrink | Where have all my Certificates gone? (And when do they expire?) |
2018-08-24/a> | Xavier Mertens | Microsoft Publisher Files Delivering Malware |
2018-06-15/a> | Lorna Hutcheson | SMTP Strangeness - Possible C2 |
2018-05-19/a> | Xavier Mertens | Malicious Powershell Targeting UK Bank Customers |
2018-05-10/a> | Bojan Zdrnja | Exfiltrating data from (very) isolated environments |
2017-12-13/a> | Xavier Mertens | Tracking Newly Registered Domains |
2017-11-03/a> | Xavier Mertens | Simple Analysis of an Obfuscated JAR File |
2017-08-17/a> | Xavier Mertens | Maldoc with auto-updated link |
2017-06-08/a> | Tom Webb | Summer STEM for Kids |
2017-05-10/a> | Johannes Ullrich | Read This If You Are Using a Script to Pull Data From This Site |
2017-04-20/a> | Xavier Mertens | DNS Query Length... Because Size Does Matter |
2016-09-04/a> | Russ McRee | Kali Linux 2016.2 Release: https://www.kali.org/news/kali-linux-20162-release/ |
2016-07-26/a> | Johannes Ullrich | Command and Control Channels Using "AAAA" DNS Records |
2016-06-15/a> | Richard Porter | Warp Speed Ahead, L7 Open Source Packet Generator: Warp17 |
2016-04-02/a> | Russell Eubanks | Why Can't We Be Friends? |
2015-12-24/a> | Xavier Mertens | Unity Makes Strength |
2015-11-09/a> | John Bambenek | Protecting Users and Enterprises from the Mobile Malware Threat |
2015-09-03/a> | Xavier Mertens | Querying the DShield API from RTIR |
2014-08-22/a> | Richard Porter | OCLHashCat 1.30 Released |
2014-08-09/a> | Adrien de Beaupre | Complete application ownage via Multi-POST XSRF |
2014-07-19/a> | Russ McRee | Keeping the RATs out: the trap is sprung - Part 3 |
2014-07-18/a> | Russ McRee | Keeping the RATs out: **it happens - Part 2 |
2014-07-16/a> | Russ McRee | Keeping the RATs out: an exercise in building IOCs - Part 1 |
2014-03-13/a> | Daniel Wesemann | Identification and authentication are hard ... finding out intention is even harder |
2013-06-18/a> | Russ McRee | Volatility rules...any questions? |
2013-04-25/a> | Adam Swanger | Guest Diary: Dylan Johnson - A week in the life of some Perimeter Firewalls |
2013-04-17/a> | John Bambenek | UPDATEDx1: Boston-Related Malware Campaigns Have Begun - Now with Waco Plant Explosion Fun |
2013-04-16/a> | John Bambenek | Fake Boston Marathon Scams Update |
2013-04-15/a> | John Bambenek | Please send any spam (full headers), URLs or other suspicious content scamming off Boston Marathon explosions to handlers@sans.org |
2013-03-03/a> | Richard Porter | Uptick in MSSQL Activity |
2013-02-06/a> | Johannes Ullrich | Are you losing system logging information (and don't know it)? |
2012-10-30/a> | Mark Hofman | Cyber Security Awareness Month - Day 30 - DSD 35 mitigating controls |
2012-05-22/a> | Johannes Ullrich | nmap 6 released |
2012-01-03/a> | Rick Wanner | Analysis of the Stratfor Password List |
2011-12-25/a> | Deborah Hale | Another Company Falls Victim |
2011-10-26/a> | Rick Wanner | Critical Control 17:Penetration Tests and Red Team Exercises |
2010-10-03/a> | Adrien de Beaupre | Canada's Cyber Security Strategy released today |
2010-08-23/a> | Manuel Humberto Santander Pelaez | Firefox plugins to perform penetration testing activities |
2010-08-16/a> | Raul Siles | Blind Elephant: A New Web Application Fingerprinting Tool |
2010-07-08/a> | Kyle Haugsness | Pirate Bay account database compromised |
2010-06-06/a> | Manuel Humberto Santander Pelaez | Nice OS X exploit tutorial |
2010-04-13/a> | Adrien de Beaupre | Web App Testing Tools |
2010-03-06/a> | Tony Carothers | Integration and the Security of New Technologies |
2010-02-22/a> | Rob VandenBrink | New Risks in Penetration Testing |
2009-07-27/a> | Raul Siles | New Hacker Challenge: Prison Break - Breaking, Entering & Decoding |
2009-04-21/a> | Bojan Zdrnja | Web application vulnerabilities |
2009-01-20/a> | Adrien de Beaupre | Obamamania |
2008-11-25/a> | Andre Ludwig | The beginnings of a collaborative approach to IDS |
2008-09-20/a> | Rick Wanner | New (to me) nmap Features |
2008-07-18/a> | Adrien de Beaupre | Exit process? |
2008-03-30/a> | Mark Hofman | Mail Anyone? |