Microsoft recommended block rules (Windows 10) | Microsoft Docs
Oh hey, a list of known MS signed binaries that allow for unsigned execution, AKA LOLbins.
january 2019 by asteroza
Worksmart — Crossover
Welcome to white collar hell, where they cap your screen every 10, and use the webcam to check if you are seated there.
may 2017 by asteroza
realparisi/WMI_Monitor: Log newly created WMI consumers and processes
Sets up a new WMI subscription to dump new WMI subscriptions/actions to windows application log, which can then be scraped by various SIEM means to detect persistence/lateral movement.
august 2016 by asteroza
Well, every WAF vendor trembled a bit just now...
october 2015 by asteroza
Active Directory Protection | Identity Theft Detection | Aorato™
Active Directory protection software, that looks for irregular logon or authentication behavior compared to learned profiles of users. Since AD stuff gets more exposed as you federate to outside services, squelching attacks by finding anomalous authentication behavior becomes more important.
january 2014 by asteroza
Dream Cheeky USB Drivers for Webmail Notifier and Stress Button - View Discussion
Alternative software for the DreamCheeky Big Red Button (AKA stress button, self destruct button) USB plunger mushroom switch. Necessary since it turns out is isn't really a fake keyboard type USB device.
october 2012 by asteroza
Looks like the ZigBee Alliance is punting using the 920MHz band for IEEE 802.15.4g compatible PHY/MAC layer services for ECHONETlite, the new japanese standard for electric appliance/equipment energy management and connectivity to HEMS applications.
august 2012 by asteroza
FlashVideoReplacer :: Add-ons for Firefox
Tool for forcing webM modes, or redirecting flash video content to an external app, rather than having flash run internal to a browser.
january 2012 by asteroza
App that creates an embedded secure partition to isolate work apps/email/data. In theory allows a work/play divide on an otherwise personal phone. As to how safe it is, well, encrypted partition generally only provides you security for data at rest if implemented well, and various levels of security for data on teh move (when the secure partition is mounted). There's also the security issues between apps. Android may be UNIX multiuser, but it was designed fundamentally as a single GUI user/operator OS, with resulting design compromises. VMware's Horizon hypervisor setup is a slightly better security solution since that takes the OS out of the equation in theory...
october 2011 by asteroza
For paranoid japanese girlfriends, this is a spyware app/service to keep tabs on a boyfriend's android phone. 3 day free trial, then needs a monthly payment to keep the logs (assuming the logs a trickled to their servers). Tracks app installation/usage, call logs, GPS location (this seems to push GPS location to their server pretty regularly), and a few other odds and ends. The privacy outrage is already starting, but the more interesting part is will it show up under various app killer apps/task managers, and is it killable?
august 2011 by asteroza
SANS: Application Security Procurement Language
Recommended language to tighten up software dev contracts to make the programmer responsible for security issues.
february 2010 by asteroza
