Showing posts with label Incident Response. Show all posts
Showing posts with label Incident Response. Show all posts

Friday, May 5, 2017

The Bondnet Army

A technical overview of the Bondnet Army botnet from GuardiCore:

The Bondnet Army

"GuardiCore Labs has recently picked up Bondnet, a botnet of thousands of compromised servers of varying power. Managed and controlled remotely, the Bondnet is currently used to mine different cryptocurrencies and is ready to be weaponized immediately for other purposes such as mounting DDoS attacks as shown by the Mirai Botnet. Among the botnet’s victims are high profile global companies, universities, city councils and other public institutions."

Wednesday, May 3, 2017

Verizon DBIR Shows Attack Patterns Vary Widely By Industry

From Dark Reading:

Verizon DBIR Shows Attack Patterns Vary Widely By Industry

"It's not always the newest or the most sophisticated threat you need to worry about, Verizon's breach and security incident data for 2016 shows.

Among the many key takeaways in the 2017 edition Verizon’s annual Data Breach Investigations Report (DBIR), released Thursday, is that there are significant differences in why and how organizations across different industries are attacked."

Wednesday, May 13, 2015

The slow death of static security detections: Beginning of SIEM deployments

From Help Net Security:


The slow death of static security detections: Beginning of SIEM deployments


Machines both mechanical and electric have always been good at counting things. Ask anyone from an earlier generation who still uses a Victor Champion adding machine from the early 1950s, even though replacement paper rolls and ink ribbon are required. One may wonder someone wouldn’t just use a battery operated calculator, but we all know that letting go of the old familiar paradigms is hard.

Wednesday, May 6, 2015

Breach Detection, Prevention Harder Than 2 Years Ago Despite Security Spending: Survey

From Security Week:


Breach Detection, Prevention Harder Than 2 Years Ago Despite Security Spending: Survey


A new report from Enterprise Strategy Group found that many enterprises feel breach prevention and detection is more difficult today than two years ago.


According to a survey of 200 IT and information security professionals, 75 percent agreed that detecting and preventing a breach has become harder. Fifty-nine percent said malware has grown more sophisticated during the last 24 months and presents fresh challenges - even though the vast majority (87 percent) said they have increased endpoint security spending during the same period.

Tuesday, May 5, 2015

Netflix Releases FIDO Incident Response Tool

From ThreatPost:


Netflix Releases FIDO Incident Response Tool


Engineers at Netflix have released another one of the company’s bespoke security tools as an open-source application, this time an incident-response system known as FIDO.

USBKill turns thumb drives into computer kill switches

From Help Net Security:


USBKill turns thumb drives into computer kill switches


A coder that goes by the online handle "Hephaestos" has shared with the world a Python script that, when put on an USB thumb drive, turns the device in an effective kill switch for the computer in which it's plugged in.

Tuesday, December 2, 2014

Leveraging the Kill Chain for Awesome

From DarkReading:

Leveraging the Kill Chain for Awesome

I don't think the Cyber Kill chain is the be all end all some claim it to be.  This piece does a good job of explaining how it can be used effectively within an organization.