10/05

Prioritization of the Detection Engineering Backlog | by Joshua Prager | Oct, 2022 | Posts By SpecterOps Team Members

https://posts.specterops.io/prioritization-of-the-detection-engineering-backlog-dcb18a896981
Prioritization of the Detection Engineering Backlog | by Joshua Prager | Oct, 2022 | Posts By SpecterOps Team Members

Deliver a Strike by Reversing a Badger: Brute Ratel Detection and Analysis | Splunk

https://www.splunk.com/en_us/blog/security/deliver-a-strike-by-reversing-a-badger-brute-ratel-detection-and-analysis.html
Deliver a Strike by Reversing a Badger: Brute Ratel Detection and Analysis | Splunk

Remove All The Callbacks – BlackByte Ransomware Disables EDR Via RTCore64.sys Abuse – Sophos News

https://news.sophos.com/en-us/2022/10/04/blackbyte-ransomware-returns/
Remove All The Callbacks – BlackByte Ransomware Disables EDR Via RTCore64.sys Abuse – Sophos News

Added simple command to test CVE_2022_33679. · tyranid/Rubeus@3092e1f · GitHub

https://github.com/tyranid/Rubeus/commit/3092e1f11164bf379708b815a05061783653e834
Added simple command to test CVE_2022_33679. · tyranid/Rubeus@3092e1f · GitHub

Dissect 3.2-1-gca63b48 documentation

https://docs.dissect.tools
Dissect 3.2-1-gca63b48 documentation

Mitigation for Exchange Zero-Days Bypassed! Microsoft Issues New Workarounds

https://thehackernews.com/2022/10/mitigation-for-exchange-zero-days.html
Mitigation for Exchange Zero-Days Bypassed! Microsoft Issues New Workarounds

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/d3788e69dd125449af3d985de93701c49cef0658bc98e3b449185f86cbee027d/
MalwareBazaar | Browse Checking your browser

Qakbot/Qakbot_BB_05.10.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB_05.10.2022.txt
Qakbot/Qakbot_BB_05.10.2022.txt at main · pr0xylife/Qakbot · GitHub

Tracking Earth Aughisky’s Malware and Changes

https://www.trendmicro.com/en_us/research/22/j/tracking-earth-aughiskys-malware-and-changes.html
Tracking Earth Aughisky’s Malware and Changes

Malicious Tor Browser spreads through YouTube | Securelist

https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/
Malicious Tor Browser spreads through YouTube | Securelist

Securing Developer Tools: A New Supply Chain Attack on PHP

https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/
Securing Developer Tools: A New Supply Chain Attack on PHP

Malware-IOCs/2022-10-04 Remcos IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2022-10-04%20Remcos%20IOCs
Malware-IOCs/2022-10-04 Remcos IOCs at main · executemalware/Malware-IOCs · GitHub

eset_threat_report_t22022.pdf

https://www.welivesecurity.com/wp-content/uploads/2022/10/eset_threat_report_t22022.pdf
eset_threat_report_t22022.pdf