This is the third article of 5 articles series on threat integrating threat intelligence into daily security operations. If you have not gone through the first two articles, then I highly recommend you reading that as all articles are connected to one another in a proper sequence. In this article, we are going to talk about phase 2 in which we will discuss what would be the intelligence collection strategy, methods and procedures. Here is article 1 and article 2.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Tuesday, September 17, 2019
Integrate Threat Intelligence program into your daily security operations - Phase 2 - Collecting Intelligence
Labels:
anonymous,
APT,
blueteam,
cyber,
cybersecurity,
darknet,
deepweb,
edr,
hacking,
informationsecurity,
infosec,
intelligence,
malware,
redteam,
security,
threat,
threathunting,
threatintelligence,
threats
Saturday, May 18, 2019
Integrate Threat Intelligence program into your daily security operations - Phase 1 - Planning and Preparation
From the last article located at here, we have now a majority of information to start the preparation and planning. In this article, I am going to explain how we can initiate the project and start preparing plans and procedures. This can be done in two phases.
Initial meetings with internal team to discuss the current threat landscape of an organisation.
Review observations that can help to prepare a perfect plan.
Labels:
anonymous,
APT,
blueteam,
cyber,
cybersecurity,
darknet,
deepweb,
edr,
hacking,
informationsecurity,
infosec,
intelligence,
malware,
redteam,
security,
threat,
threathunting,
threatintelligence,
threats
Wednesday, May 15, 2019
Integrate the Threat Intelligence program into your daily security operations - Phase 0 - Introduction
There is a huge amount
of the increasing use of sophisticated malware, and often organisations fail to
understand the real intent of such activities by a large group of hackers, nation-sponsored
attacks, organized cybercrimes, cyber terrorists. These attacks result in
revenue disruption, damaging public and private reputation and demolishing
business processes and workflow.
Intelligence is staying
ahead of the next threat targeting to your organisation by implementing
protective measures to protect your brand reputation, data, people, process and
technology infrastructure. I am assuming whoever reading this article has a little bit of background knowledge on threat intelligence terminology.
Just having a Threat
intelligence product itself is not sufficient, data should be collected,
classified and correlated with hacking tools, tactics and techniques.
Labels:
anonymous,
APT,
blueteam,
cyber,
cybersecurity,
darknet,
deepweb,
edr,
hacking,
informationsecurity,
infosec,
intelligence,
malware,
redteam,
security,
threat,
threathunting,
threatintelligence,
threats
Sunday, May 6, 2018
Stealing NTLM hash with BadPDF - A Technique to bypass AV and Endpoint protections
On April 26, 2018 checkpoint research team discovered the malicious exploit which can be embedded in PDF files to send further to the victims. After opening the malicious PDF file, victim’s machine will leak NTLM hash via SMB protocol.
I created the malicious PDF and tested on my personal machine which was fully equipped with cutting edge end-point protection technology. It leaked NTLM hash to the attacker. If SMB protocol is opened on victim’s machine, it will leak the hash through it.
I thought disabling SMB protocol will patch this issue. So I turned off the SMB protocol on the machine, downloaded the PDF via the web browser and opened it through the Chrome browser only. In that case, the browser made an HTTP request to attacker’s machine for leaking the NTLM hash value.
I created the malicious PDF and tested on my personal machine which was fully equipped with cutting edge end-point protection technology. It leaked NTLM hash to the attacker. If SMB protocol is opened on victim’s machine, it will leak the hash through it.
I thought disabling SMB protocol will patch this issue. So I turned off the SMB protocol on the machine, downloaded the PDF via the web browser and opened it through the Chrome browser only. In that case, the browser made an HTTP request to attacker’s machine for leaking the NTLM hash value.
Saturday, April 21, 2018
Android OS/Phone Security Hardening Guide
In this article, I am going to list down all security features which can be hardened for any Android phone operating system in order to improve the security of user phone. I believe that there are plenty of articles available online for the same, however, they are missing one or other thing. Hence, my try here is to list down every possible feature that we can use to improve Android phone security.
Labels:
android application,
android hardening,
android os,
hacker,
hacking,
phone security,
security
Friday, February 16, 2018
Datasploit usage using docker container - OSINT
Datasploit performs automated OSINT on a domain / email / username / IP and find out relevant information from different sources. Easy to contribute OSINT Framework. Code for Banner, Main and Output function. Datasploit automatically do rest of the things for you. Useful for Pen-testers, Bug Bounty Hunters, Cyber Investigators, Product companies, Security Engineers, etc.Collaborate the results, show them in a consolidated manner. Tries to find out credentials, api-keys, tokens, sub-domains, domain history, legacy portals, usernames, dumped accounts, etc. related to the target. Can be used as library, automated scripts or standalone scripts.Can generate lists which can be feeded to active scan tools.Generates HTML, along with text files.
Thursday, January 11, 2018
Less perks and more pitfalls of cryptocurrency
I was always wondering to invest or not to invest in cryptocurrency. I started looking all articles that exist on the internet. Majority of articles were reflecting the same in terms of advantages and disadvantages. However, after reviewing almost 50 different articles, what I have analyzed is there are more pitfalls with fewer perks.
So I gathered all pitfalls of bitcoin to cover them in the single article. Those are as follows. Thanks to the industry contributors.
Saturday, September 16, 2017
Android Kiosk Browser Lock down Security Testing Checklist
What is Kiosk Browser Lockdown?
In simple words, if you want to restrict the usability of the device that you are giving to your employee/customer's hand, you can use kiosk browser lockdown facility to make that device single purpose used.
Generally, all finance companies use that at their branches when the customer comes to their branch and any kind of help and representative approaches them with a tablet which has that bank/company's application running on it. Now that device may land into many hands such as a company's all employees and sometimes clients too. So to restrict that device's all functionalities such as settings, other apps on home screen etc.., a company uses kiosk lockdown which can be paid or free software.
Subscribe to:
Posts (Atom)






