rowhammer is back with a vengence...
DRAM  RAM  ECC  memory  attack  exploit  rowhammer  security  hacking  pentesting 
5 days ago by asteroza
mitre/caldera: An automated adversary emulation system
\An automated adversary emulation system. Contribute to mitre/caldera development by creating an account on GitHub.
security  MITRE  attack  cybersecurity  penTesting  adversaryemulation 
5 days ago by cailenm
Technique: Scheduled Task - MITRE ATT&CK™
Configure event logging for scheduled task creation and changes by enabling the "Microsoft-Windows-TaskScheduler/Operational" setting within the event logging service. [78] Several events will then be logged on scheduled task activity, including: [79]

Event ID 106 - Scheduled task registered
Event ID 140 - Scheduled task updated
Event ID 141 - Scheduled task removed
Tools such as Sysinternals Autoruns may also be used to detect system changes that could be attempts at persistence, including listing current scheduled tasks.
scheduledtasks  attack 
16 days ago by bwiese
Threat Hunting in Linux For Rocke Cryptocurrency Mining Malware
Published research by Unit 42 and Talos Group indicates that Rocke has exploited remote code execution (RCE) vulnerabilities in Oracle Weblogic, Apache Struts, Adobe ColdFusion, phpMyAdmin, Redis, and other public-facing services. It’s ideal but difficult to detect Rocke in near-real-time as the adversary attempts to execute code.
redcanary  attack  cryptojacking  reference 
16 days ago by bwiese
Information Security Mental Models – Chris Sanders
The MITRE ATT&CK matrix is a framework of adversarial tactics that basically presents a categorical list of common techniques to describe computer network attacks. It’s a great model that’s useful in a variety of ways, and honestly, we’ve needed something like this for a while.

abandoned other sound security principles and successful ongoing initiatives in pursuit of “checking things off the list” that is ATT&CK. Similarly, I’ve seen new security organizations center their entire detection and prevention strategies around ATT&CK without first defining their threat model, understanding the high-value assets, and gaining any sense of the risk they want to mitigate

Mental models help us make better decisions and learn faster. Models are tools that help us simplify complexity, and they are critical in the practice of any profession. For information security to evolve past our cognitive crisis we must become more adept at developing, utilizing, and teaching good models.
cybersecurity  risk  modeling  attack  medical  biology 
16 days ago by bwiese

