Pretty cool #blackhat2023 talk about messing with log files using ANSI escape characters

https://youtu.be/opW_Q7jvSbc?si=qhRSNeoeIN1xPBWU

Weaponizing Plain Text: ANSI Escape Sequences as a Forensic Nightmare

YouTube

What distinguishes a SecOps incident from a NetOps incident? Eldon Koyle shares how the @blackhatevents NOC team was able to get to the truth with Zeek network monitoring data accessed directly within @corelight’s Open NDR Platform and how you can distinguish between network disruption or an attack on core systems. https://corelight.com/blog/open-ndr-platform-for-netops

If you’re at #BHEU, stop by the NOC to see Eldon in action with his other teammates from Corelight, Arista Networks, Cisco Secure, NetWitness, and @paloaltontwks. Want to learn more about Zeek? Follow @zeek and visit our website: https://corelight.com/products/zeek/

#BlackHat #BlackHat2023 #NetworkSecurity #NetOps #Cybersecurity

Black Hat NOC USA 2023 | Corelight

Recapping our learnings from being in the Black Hat NOC at Black Hat USA 2023

We’re proud to be a part of the NOC at @blackhatevents Europe alongside @Arista Networks, Cisco Secure, NetWitness, and @paloaltontwks! Thank you to our @corelight colleagues Ben Reardon, Dustin Lee, Eldon Koyle, James Pope, and Ignacio Arnaldo for their service in the Black Hat NOC all this week—you go team 💪 To learn more about the NOC, be sure to stop by the NOC presentations at 10:20 a.m. on December 6 and at 2:30 p.m. on December 7, as well as our booth with @crowdstrike (432): https://corelight.com/resources/events/2023/black-hat-eu

Want to learn what it’s like to be in the Black Hat NOC? Check out Dustin's latest blog: https://corelight.com/blog/blueprints-from-2023-black-hat-noc

#BlackHat #BlackHat2023 #BlackHatEMEA #BlackHatEurope #NetworkSecurity #Cybersecurity

Black Hat Europe | Corelight (NDR)

Visit us at Black Hat Europe 2023 and learn how Corelight expands visibility, improves threat detection coverage, and accelerates incident response.

Going to #BlackHatEurope? Stop by @blackhatevents booth 432 on Dec. 6-7 to meet with @corelight and @crowdstrike experts to learn how to gain superior attack visibility and improved threat hunting capabilities with our seamless integration. corelight.com/resources/events/2023/black-hat-eu

#BlackHat #BlackHat2023 #BlackHatEMEA #BlackHatEurope #NetworkSecurity #Cybersecurity

@blackhatevents MEA is next week! If you’ll be at the show, stop by Spire Solutions booth H3-G30 to learn more about accelerating network detection and response. Also, be sure to join @corelight's Basil Shahin at 2 p.m. for a special talk where he’ll share how the evidence from your network can turn your security team into threat hunting pros while supporting defensible disclosure. Learn more: https://corelight.com/resources/events/2023/black-hat-mea

#BHMEA23 #BlackHat #BlackHat2023 #NetworkSecurity #ThreatHunting

Black Hat MEA | Corelight (NDR)

Visit us at Black Hat MEA 2023 and learn how Corelight expands visibility, improves threat detection coverage, and accelerates incident response.

In a new blog, @corelight's own Dustin Lee shares the blueprint for a high-functioning security team, a lesson that he learned while serving in the NOC at the @blackhatevents in Asia and Las Vegas. Read Dustin’s reflections as he prepares for his third NOC appearance at #BlackHat Europe in December with Arista Networks, Cisco Secure, NetWitness, and @paloaltontwks, as well as his fellow Corelight NOC colleagues: https://corelight.com/blog/blueprints-from-2023-black-hat-noc

Going to Black Hat MEA in Saudi Arabia next week? Stop by the Spire Solutions booth to talk to our team of experts!

#BlackHat2023 #BlackHatEMEA #BlackHatEurope #NetworkSecurity #Cybersecurity

The Art of Team Building: Blueprints from the Black Hat NOC | Corelight

Here are my learnings from participating in NOCs at Black Hat Asia and Black Hat Las Vegas in 2023.

An alert for a potential command and control check-in for a remote access trojan (RAT) called TripleNine from an internal IP goes off. You think it’s coming from an infected host, but you’re not sure—what do you do next? In a new blog, Mark Overholser shares this exact scenario and what steps his Corelight team and other partners within the #BlackHat NOC took to investigate, validate, and triage the alert with @corelight’s Open NDR Platform and GPT explainability. Read this and other things Mark learned while in the NOC: https://corelight.com/blog/5-takeaways-from-black-hat-noc-usa-2023

A big thank you to our fellow partners within the Black Hat NOC Arista Networks, Cisco Secure, Lumen Technologies, NetWitness, and @paloaltontwks— we enjoyed working with you!

#BlackHat2023 #BlackHatUSA #ThreatDetection #NetworkSecurity #Cybersecurity

Black Hat NOC USA 2023: Five Takeaways for SOC Teams | Corelight

Here are five lessons that me and my NOC teammates learned over the course of our week together at Black Hat NOC USA 2023.

If you went to anything in #lasvrgas #vegas during #HackerSummerCamp like @DianaInitiative, @BSidesLV #bsideslv, #bhusa #blackhat2023, #squadcon...

And especially @defcon for #Defcon31, please get #COVID19 tested!

If you got a positive result, please fill out this forum by @dcskytalks:

https://skytalks.info/summer-camp-2023-covid-dashboard/

#CovidIsNotOver

Summer Camp 2023 COVID Dashboard – Skytalks

China would consider attacks on US railroads, pipelines if it invades Taiwan, Easterly says

CISA Director Jen Easterly did not hold back at the DEF CON conference in describing the threat from China. She openly confirmed concerns raised by White House officials in news reports in July.

#BHUSA and #usesec23 have been a blast! Check out our work "Cookie Crumbles: Breaking and Fixing Web Session Integrity"!

🍪🧑‍🍳🍪

Paper https://www.usenix.org/conference/usenixsecurity23/presentation/squarcina
Slides https://minimalblue.com/data/papers/BHUSA23_cookie_crumbles-slides.pdf
Artifacts https://github.com/SecPriv/cookiecrumbles

With Pedro Adão, Lorenzo Veronese, and Matteo Maffei

#websecurity #webdev #usesec2023 #blackhat #blackhat2023 #cookies

Cookie Crumbles: Breaking and Fixing Web Session Integrity | USENIX