lade...
random avatar

13reak - Network

Posts Subscribe

I used Game of Active Directory (GOAD) today. There's an extension with Wazuh, so it is also useful for blue teamers.It is really easy to...

https://infosec.exchange/@13reak...

I used Game of Active Directory (GOAD) today. There's an extension with Wazuh, so it is also useful for blue teamers.

It is really easy to setup. One command and Wazuh is added:
install_extension wazuh

github.com/Orange-Cyberdefense

5.3.2025 16:16I used Game of Active Directory (GOAD) today. There's an extension with Wazuh, so it is also useful for blue teamers.It is really easy to...
https://infosec.exchange/@13reak...

https://www.golem.de/news/elon-musk-telekom-chef-will-doge-fuer-europa-2503-193941.htmlNa dann Prost Mahlzeit, jetzt kommen die Oligarchen...

https://infosec.exchange/@13reak...

golem.de/news/elon-musk-teleko

Na dann Prost Mahlzeit, jetzt kommen die Oligarchen auch bei uns in Europa aus den Löchern. Ich hätte gerne einen neuen Telekom Chef, vielleicht gibt's dann ja Mal Glasfaser in Deutschland...

5.3.2025 07:06https://www.golem.de/news/elon-musk-telekom-chef-will-doge-fuer-europa-2503-193941.htmlNa dann Prost Mahlzeit, jetzt kommen die Oligarchen...
https://infosec.exchange/@13reak...

How to filter zeek logs:cat conn.log | zeek-cut <columns> | column -t | less -S(column and less display the columns aligned and...

https://infosec.exchange/@13reak...

How to filter zeek logs:

cat conn.log | zeek-cut <columns> | column -t | less -S

(column and less display the columns aligned and readable)

27.2.2025 12:36How to filter zeek logs:cat conn.log | zeek-cut <columns> | column -t | less -S(column and less display the columns aligned and...
https://infosec.exchange/@13reak...

What don't oligarchs buy? #jamesbond

https://infosec.exchange/@13reak...

What don't oligarchs buy?

20.2.2025 21:23What don't oligarchs buy? #jamesbond
https://infosec.exchange/@13reak...

Anyone ever used https://opendesk.eu/en/ ? Does it work well or is it still a bit buggy?#office #alternative #opensource #foss

https://infosec.exchange/@13reak...

Anyone ever used opendesk.eu/en/ ? Does it work well or is it still a bit buggy?

18.2.2025 18:10Anyone ever used https://opendesk.eu/en/ ? Does it work well or is it still a bit buggy?#office #alternative #opensource #foss
https://infosec.exchange/@13reak...

I encountered some third party firewall logs recently. Timestamps were in Linux format and requests in hexdump. We knew the IP range of the...

https://infosec.exchange/@13reak...

I encountered some third party firewall logs recently. Timestamps were in Linux format and requests in hexdump. We knew the IP range of the attackers and that they uploaded a webshell.

grep is an awesome tool for that. Looking for successful (code 200) uploads (POST requests) from IP:

grep -e "666.666.666.... POST 200" firewall.log > attack.txt

To find the script I searched for the longest request since most legitimate requests were rather short. Word count can give us that with -L:

cat attack.txt | wc -L
1337

And let's extract that longest line with grep:

grep -e "^.{1337}$" attack.txt

Hex requests could then be parsed easily with Cyerchef's From Hex.

Hope that helps someone! Adjust to your needs. :blobsmile:

10.2.2025 20:53I encountered some third party firewall logs recently. Timestamps were in Linux format and requests in hexdump. We knew the IP range of the...
https://infosec.exchange/@13reak...

(sorry, job posting only in German, but still maybe interesting for some)SEC Consult sucht einen Teamleiter und Incident Manager in...

https://infosec.exchange/@13reak...

(sorry, job posting only in German, but still maybe interesting for some)

SEC Consult sucht einen Teamleiter und Incident Manager in Deutschland:

sec-consult.com/de/karriere/de

30.1.2025 08:03(sorry, job posting only in German, but still maybe interesting for some)SEC Consult sucht einen Teamleiter und Incident Manager in...
https://infosec.exchange/@13reak...

Has anyone here used CalyxOS?How easy is it to install? Do all Apps still work?(I'm mostly concerned about 2FA banking apps, if they don't...

https://infosec.exchange/@13reak...

Has anyone here used CalyxOS?

How easy is it to install? Do all Apps still work?
(I'm mostly concerned about 2FA banking apps, if they don't work, I have a problem :blobfrown: )

23.1.2025 20:59Has anyone here used CalyxOS?How easy is it to install? Do all Apps still work?(I'm mostly concerned about 2FA banking apps, if they don't...
https://infosec.exchange/@13reak...

@Daojoan asked what we are going to do about the richest person on earth being a Nazi.A) I quit X/Twitter (a while ago)B) I just quit my...

https://infosec.exchange/@13reak...

@Daojoan asked what we are going to do about the richest person on earth being a Nazi.

A) I quit X/Twitter (a while ago)
B) I just quit my PayPal
C) I quit Facebook (a while ago)
D) I just quit my proton mail

We're the customers who make these people rich.

23.1.2025 12:35@Daojoan asked what we are going to do about the richest person on earth being a Nazi.A) I quit X/Twitter (a while ago)B) I just quit my...
https://infosec.exchange/@13reak...

Pineapple pizza is not pizza.And for my British friends: this also counts for banana pizza or similar.(before some Italians intervene with...

https://infosec.exchange/@13reak...

Pineapple pizza is not pizza.

And for my British friends: this also counts for banana pizza or similar.
(before some Italians intervene with Nutella pizza: Brits put banana on top of passata and mozzarella 🤌)

23.1.2025 08:15Pineapple pizza is not pizza.And for my British friends: this also counts for banana pizza or similar.(before some Italians intervene with...
https://infosec.exchange/@13reak...

Trans-o-flex: collect your parcels yourself.Trans-o-flex: we make it disappear.Trans-o-flex: better call the suicide hotline than...

https://infosec.exchange/@13reak...

Trans-o-flex: collect your parcels yourself.

Trans-o-flex: we make it disappear.

Trans-o-flex: better call the suicide hotline than us.

23.1.2025 08:04Trans-o-flex: collect your parcels yourself.Trans-o-flex: we make it disappear.Trans-o-flex: better call the suicide hotline than...
https://infosec.exchange/@13reak...

Seems like there's quite an influx of new users these days. Spike of 1 million in December 2024 / January 2025? To the new users: welcome!

https://infosec.exchange/@13reak...

Seems like there's quite an influx of new users these days. Spike of 1 million in December 2024 / January 2025? :blobgrin:

To the new users: welcome!

21.1.2025 19:51Seems like there's quite an influx of new users these days. Spike of 1 million in December 2024 / January 2025? To the new users: welcome!
https://infosec.exchange/@13reak...

Detected a C2 framework in RAM today with velociraptor. Dumped the process memory with velo, created a zignature with radare2.Never thought...

https://infosec.exchange/@13reak...

Detected a C2 framework in RAM today with velociraptor. Dumped the process memory with velo, created a zignature with radare2.

Never thought I'd ever reach that level...

Blogpost and velo artifact incoming :blobsmile:

20.1.2025 22:50Detected a C2 framework in RAM today with velociraptor. Dumped the process memory with velo, created a zignature with radare2.Never thought...
https://infosec.exchange/@13reak...

The local model took a while but very impressive still. Expected to get better with training and new hardware.

https://infosec.exchange/@13reak...

The local model took a while but very impressive still. Expected to get better with training and new hardware.

20.1.2025 15:47The local model took a while but very impressive still. Expected to get better with training and new hardware.
https://infosec.exchange/@13reak...

Tried the AI feature of radare2, it's really easy to use.Setup:r2pm -r r2ai> -M # list all AI models> -m <AI model> # select...

https://infosec.exchange/@13reak...

Tried the AI feature of radare2, it's really easy to use.

Setup:

r2pm -r r2ai
> -M # list all AI models
> -m <AI model> # select model
> -w # run

Usage inside R2:

(Go to function)
> decai -d # decompile with AI

20.1.2025 15:45Tried the AI feature of radare2, it's really easy to use.Setup:r2pm -r r2ai> -M # list all AI models> -m <AI model> # select...
https://infosec.exchange/@13reak...

New year, new firmware!Don't forget to update your writeblocker, bring it to a pokémon center and give it some cuddles.#dfir #writeblocker...

https://infosec.exchange/@13reak...

New year, new firmware!

Don't forget to update your writeblocker, bring it to a pokémon center and give it some cuddles.

15.1.2025 14:21New year, new firmware!Don't forget to update your writeblocker, bring it to a pokémon center and give it some cuddles.#dfir #writeblocker...
https://infosec.exchange/@13reak...

One can see Mars with the naked eye today - even from a city with all the lights tuned on! The little red dot on the lower left in the...

https://infosec.exchange/@13reak...

One can see Mars with the naked eye today - even from a city with all the lights tuned on!

The little red dot on the lower left in the picture is Mars. (Depending on where you are in the world, it might be somewhere else around the moon)

PS: try binoculars, if you have some.

13.1.2025 19:21One can see Mars with the naked eye today - even from a city with all the lights tuned on! The little red dot on the lower left in the...
https://infosec.exchange/@13reak...

I noticed today that a lot of people are struggling with antivirus alerts, specifically Microsoft Defender:1) try to understand the alarm...

https://infosec.exchange/@13reak...

I noticed today that a lot of people are struggling with antivirus alerts, specifically Microsoft Defender:

1) try to understand the alarm itself and at which point in the attack this would happen: phishing email = early, credential access (especially admin credentials) or suspicious C2 IPs = middle, ransomware/data upload = late.

2) what should be the attackers previous and next step then? (just look at 1 again: early/middle/late)

3) can you see this previous/next step in the logs? Look especially for evidence of execution. Attackers want to "do" something. Executables, scripts, PowerShell, command line, services, scheduled tasks?

If you cannot see any previous or any next steps, ask yourself if you're blind (are your logs empty? Timeframe not available?) or if there really aren't any. If there aren't any, it's likely a false positive. If there are, escalate.

Happy hunting!

10.1.2025 20:39I noticed today that a lot of people are struggling with antivirus alerts, specifically Microsoft Defender:1) try to understand the alarm...
https://infosec.exchange/@13reak...

Ivanti vulnerability CVE-2025-0282 is actively being exploited by attackers.Cases are rising.Details from Ivanti:...

https://infosec.exchange/@13reak...

Ivanti vulnerability CVE-2025-0282 is actively being exploited by attackers.

Cases are rising.

Details from Ivanti: ivanti.com/blog/security-updat

10.1.2025 16:45Ivanti vulnerability CVE-2025-0282 is actively being exploited by attackers.Cases are rising.Details from Ivanti:...
https://infosec.exchange/@13reak...

Has anyone ever tried Kagi search engine? #searchengine #Kagi

https://infosec.exchange/@13reak...

Has anyone ever tried Kagi search engine?

7.1.2025 16:28Has anyone ever tried Kagi search engine? #searchengine #Kagi
https://infosec.exchange/@13reak...
Subscribe
To add news/posts to your profile here, you must add a link to a RSS-Feed to your webfinger. One example how you can do this is to join Fediverse City.
         
Webfan Website Badge
Nutzungsbedingungen   Datenschutzerklärung  Impressum
Webfan | @Web pages | Fediverse Members