Internet Storm Center
Sign In
Sign Up
Handler on Duty:
Jan Kopriva
Threat Level:
green
Date
Author
Title
OLE FILE
2015-07-12
Didier Stevens
Jump List Files Are OLE Files
OLE
2023-12-31/a>
Tom Webb
Pi-Hole Pi4 Docker Deployment
2023-05-04/a>
Xavier Mertens
Infostealer Embedded in a Word Document
2023-03-29/a>
Didier Stevens
Extracting Multiple Streams From OLE Files
2023-03-16/a>
Xavier Mertens
Simple Shellcode Dissection
2023-02-26/a>
Didier Stevens
oledump & MSI Files
2022-07-24/a>
Didier Stevens
Video: Maldoc: non-ASCII VBA Identifiers
2022-07-21/a>
Didier Stevens
Maldoc: non-ASCII VBA Identifiers
2022-05-14/a>
Didier Stevens
Quick Analysis Of Phishing MSG
2022-03-13/a>
Didier Stevens
YARA 4.2.0 Released
2022-03-05/a>
Didier Stevens
oledump's Extra Option
2022-02-20/a>
Didier Stevens
Video: YARA's Console Module
2022-01-30/a>
Didier Stevens
YARA's Console Module
2021-12-16/a>
Brad Duncan
How the "Contact Forms" campaign tricks people
2021-10-21/a>
Brad Duncan
"Stolen Images Evidence" campaign pushes Sliver-based malware
2021-07-03/a>
Didier Stevens
Finding Strings With oledump.py
2021-06-30/a>
Johannes Ullrich
CVE-2021-1675: Incomplete Patch and Leaked RCE Exploit
2021-06-28/a>
Didier Stevens
CFBF Files Strings Analysis
2021-06-24/a>
Xavier Mertens
Do you Like Cookies? Some are for sale!
2021-06-20/a>
Didier Stevens
Video: oledump Cheat Sheet
2020-12-06/a>
Didier Stevens
oledump's Indicators (video)
2020-11-15/a>
Didier Stevens
oledump's ! Indicator
2020-11-08/a>
Didier Stevens
Quick Tip: Extracting all VBA Code from a Maldoc
2020-10-12/a>
Didier Stevens
Nested .MSGs: Turtles All The Way Down
2020-10-11/a>
Didier Stevens
Analyzing MSG Files With plugin_msg_summary
2020-09-18/a>
Xavier Mertens
A Mix of Python & VBA in a Malicious Word Document
2019-12-29/a>
Guy Bruneau
ELK Dashboard for Pihole Logs
2019-12-23/a>
Didier Stevens
New oledump.py plugin: plugin_version_vba
2019-12-07/a>
Guy Bruneau
Integrating Pi-hole Logs in ELK with Logstash
2019-11-25/a>
Xavier Mertens
My Little DoH Setup
2019-05-10/a>
Xavier Mertens
DSSuite - A Docker Container with Didier's Tools
2019-02-26/a>
Russ McRee
Ad Blocking With Pi Hole
2018-08-19/a>
Didier Stevens
Video: Peeking into msg files - revisited
2018-08-11/a>
Didier Stevens
Peeking into msg files - revisited
2016-06-12/a>
Guy Bruneau
DNS Sinkhole ISO Version 2.0
2016-03-07/a>
Xavier Mertens
Another Malicious Document, Another Way to Deliver Malicious Code
2015-07-12/a>
Didier Stevens
Jump List Files Are OLE Files
2015-07-04/a>
Didier Stevens
A .BUP File Is An OLE File
2015-05-15/a>
Didier Stevens
Another Maldoc? I'm Afraid So...
2015-05-09/a>
Didier Stevens
Malicious Word Document: This Time The Maldoc Is A MIME File
2015-02-20/a>
Tom Webb
Fast analysis of a Tax Scam
2015-02-19/a>
Daniel Wesemann
Macros? Really?!
2013-11-18/a>
Johannes Ullrich
Am I Sending Traffic to a "Sinkhole"?
2013-05-04/a>
Kevin Shortt
The Zero-Day Pendulum Swings
2012-11-16/a>
Guy Bruneau
VMware security updates for vSphere API and ESX Service Console - http://www.vmware.com/security/advisories/VMSA-2012-0016.html
2012-01-21/a>
Guy Bruneau
DNS Sinkhole Scripts Fixes/Update
2011-10-15/a>
Guy Bruneau
DNS Sinkhole Parser Script Update
2011-09-09/a>
Guy Bruneau
IPv6 and DNS Sinkhole
2010-10-28/a>
Tony Carothers
Cyber Security Awareness Month - Day 28 - Role of the employee
2010-06-19/a>
Guy Bruneau
DNS Sinkhole ISO Available for Download
2010-01-10/a>
Guy Bruneau
Easy DNS BIND Sinkhole Setup
FILE
2024-12-20/a>
Xavier Mertens
Christmas "Gift" Delivered Through SSH
2024-12-15/a>
Johannes Ullrich
Exploit attempts inspired by recent Struts2 File Upload Vulnerability (CVE-2024-53677, CVE-2023-50164)
2024-09-16/a>
Xavier Mertens
Managing PE Files With Overlays
2024-05-31/a>
Xavier Mertens
"K1w1" InfoStealer Uses gofile.io for Exfiltration
2023-11-20/a>
Jesse La Grew
Overflowing Web Honeypot Logs
2023-09-29/a>
Xavier Mertens
Are You Still Storing Passwords In Plain Text Files?
2023-07-23/a>
Guy Bruneau
Install & Configure Filebeat on Raspberry Pi ARM64 to Parse DShield Sensor Logs
2023-06-09/a>
Xavier Mertens
Undetected PowerShell Backdoor Disguised as a Profile File
2023-04-04/a>
Johannes Ullrich
Analyzing the efile.com Malware "efail"
2023-02-24/a>
Brad Duncan
URL files and WebDAV used for IcedID (Bokbot) infection
2023-01-21/a>
Guy Bruneau
DShield Sensor JSON Log to Elasticsearch
2023-01-04/a>
Rob VandenBrink
Update to RTRBK - Diff and File Dates in PowerShell
2022-12-20/a>
Xavier Mertens
Linux File System Monitoring & Actions
2022-07-25/a>
Xavier Mertens
PowerShell Script with Fileless Capability
2022-07-17/a>
Didier Stevens
Python: Files In Use By Another Process
2022-06-25/a>
Xavier Mertens
Malicious Code Passed to PowerShell via the Clipboard
2022-06-04/a>
Guy Bruneau
Spam Email Contains a Very Large ISO file
2022-06-03/a>
Xavier Mertens
Sandbox Evasion... With Just a Filename!
2022-05-29/a>
Didier Stevens
Extracting The Overlay Of A PE File
2022-05-28/a>
Didier Stevens
Huge Signed PE File: Keeping The Signature
2022-05-26/a>
Didier Stevens
Huge Signed PE File
2022-05-23/a>
Johannes Ullrich
Attacker Scanning for jQuery-File-Upload
2022-05-20/a>
Xavier Mertens
A 'Zip Bomb' to Bypass Security Controls & Sandboxes
2022-03-24/a>
Xavier Mertens
Malware Delivered Through Free Sharing Tool
2021-09-11/a>
Guy Bruneau
Shipping to Elasticsearch Microsoft DNS Logs
2021-05-02/a>
Didier Stevens
PuTTY And FileZilla Use The Same Fingerprint Registry Keys
2021-04-10/a>
Guy Bruneau
Building an IDS Sensor with Suricata & Zeek with Logs to ELK
2021-03-12/a>
Guy Bruneau
Microsoft DHCP Logs Shipped to ELK
2021-02-12/a>
Xavier Mertens
AgentTesla Dropped Through Automatic Click in Microsoft Help File
2020-06-12/a>
Xavier Mertens
Malicious Excel Delivering Fileless Payload
2020-05-22/a>
Didier Stevens
Some Strings to Remember
2020-05-04/a>
Didier Stevens
Sysmon and File Deletion
2020-03-21/a>
Guy Bruneau
Honeypot - Scanning and Targeting Devices & Services
2019-10-03/a>
Xavier Mertens
"Lost_Files" Ransomware
2019-08-04/a>
Didier Stevens
Detecting ZLIB Compression
2019-02-19/a>
Didier Stevens
Identifying Files: Failure Happens
2018-11-05/a>
Johannes Ullrich
Struts 2.3 Vulnerable to Two Year old File Upload Flaw
2017-11-29/a>
Xavier Mertens
Fileless Malicious PowerShell Sample
2017-10-30/a>
Didier Stevens
PE files and debug info
2017-10-24/a>
Xavier Mertens
Stop relying on file extensions
2017-07-19/a>
Xavier Mertens
Bots Searching for Keys & Config Files
2017-07-02/a>
Didier Stevens
PE Section Name Descriptions
2017-05-26/a>
Lorna Hutcheson
File2pcap - A new tool for your toolkit!
2016-08-24/a>
Xavier Mertens
Example of Targeted Attack Through a Proxy PAC File
2016-05-21/a>
Didier Stevens
Python Malware - Part 2
2016-03-30/a>
Xavier Mertens
What to watch with your FIM?
2016-01-20/a>
Xavier Mertens
/tmp, %TEMP%, ~/Desktop, T:\, ... A goldmine for pentesters!
2015-07-12/a>
Didier Stevens
Jump List Files Are OLE Files
2014-03-17/a>
Johannes Ullrich
Scans for FCKEditor File Manager
2014-02-28/a>
Daniel Wesemann
Oversharing
2014-01-11/a>
Guy Bruneau
tcpflow 1.4.4 and some of its most Interesting Features
2013-08-26/a>
Alex Stanford
Stop, Drop and File Carve
2013-08-21/a>
Alex Stanford
Psst. Your Browser Knows All Your Secrets.
2011-11-28/a>
Tom Liston
A Puzzlement...
2011-08-15/a>
Mark Hofman
How to find unwanted files on workstations
2009-12-28/a>
Johannes Ullrich
8 Basic Rules to Implement Secure File Uploads http://jbu.me/48 (inspired by IIS ; bug)
2009-08-13/a>
Jim Clausing
Tools for extracting files from pcaps
2009-06-27/a>
Tony Carothers
New NIAP Strategy on the Horizon
2009-05-27/a>
donald smith
Host file black lists
2009-05-25/a>
Jim Clausing
More tools for (US) Memorial Day
2008-03-13/a>
Jason Lam
Remote File Include spoof!?
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Contact Us
Contact Us
About Us
Handlers
About Us
Slack Channel
Mastodon
Bluesky
X
Make the web a better place by
sharing the SANS Internet Storm Center
with others