Learn how threat actors weaponize stealer logs and navigate dark web markets, forums, and C2 networks.
Join us next week with our friends from Flare, where we'll Unravel Infostealer Threat Networks in our free one-hour Anti-Cast.
Learn how threat actors weaponize stealer logs and navigate dark web markets, forums, and C2 networks.
Join us next week with our friends from Flare, where we'll Unravel Infostealer Threat Networks in our free one-hour Anti-Cast.
Ready for more Linux amazingness with @hal_pomeranz ? Then join us for this week's Anti-Cast, "XFS Forensics with xfs_db," Aug. 16 at 12 p.m. EDT! Register here: https://blackhillsinfosec.zoom.us/webinar/register/WN_fCna_N-QRSCOHNT-eqHRww
PreShow Banter™ at 11:30 a.m. EDT.
Despite being a common Linux file system, forensic support for XFS is still largely lacking. In this session, Hal will describe how to turn the humble xfs_db tool into a useful forensic application for examining XFS file system internals and finding critical evidence. Attackers aren’t the only ones who can “live off the land”!
Chat with your fellow attendees in the Antisyphon Discord server here: https://discord.gg/antisyphon -- in the #webcasts-livestreams channel
Despite being a common Linux file system, forensic support for XFS is still largely lacking. In this session, Hal will describe how to turn the humble xfs_db tool into a useful forensic application for examining XFS file system internals and finding critical evidence. Attackers aren’t the only ones who can “live off the land”! Chat with your fellow attendees in the Antisyphon Discord server here: https://discord.gg/antisyphon -- in the #webcast-livestreams channel
"Please hack this server"... thanks for beating up my box, here's a retrospect! All in the name of active defense & cyber deception 😎 Check out how many IPs hit the machine, their login attempts, & what commands they ran for persistence, privesc, & more: https://youtu.be/NWytrZVM6WM
This exercise was inspired by @Antisy_Training @BHinfosecurity and @strandjs Pay What You Can Training and labs for Cyber Deception! Jump into PWYC at whatever cost makes sense for you! https://jh.live/pwyc
🗣Upcoming In-Person Public Speaking :
- 🧢@BlueTeamCon (Chicago, IL) [Aug-26] https://blueteamcon.com/2023/talk-tracks/talk-track-2-30-minutes/
- 🤠Texas Cyber Summit [Sept-29] (Austin, TX) https://texascyber.org/
- 🐄Wild West Hackin' Fest [Oct-17] (Deadwood, SD) https://wildwesthackinfest.com/event/next-level-osint-w-mishaal-khan/
Catch me at any one of these to say hi, have my book signed ✍🏼 📓 or ask for a free copy, I'll keep a few with me to give away.
Talks listed here are ordered alphabetically. Authentication Proxy Attacks: Detection, Response and Hunting Chris Merkel, Chester Le Bron Over five years ago, Evilnginx was released, demonstrating the ease of stealing authentication session tokens from MFA-enabled logon processes with a simple reverse proxy. Despite being a well-known technique, few of these attacks were seen in widespread … Continue reading "Talk Track 2 – 30 Minutes"
Join @hal_pomeranz and the Antisyphon Team this Wednesday at 12 p.m. EDT for our next Anti-Cast, "Forensicating Linux LD_PRELOAD Rootkits"!
Tune in at 11:30 a.m. EDT for PreShow Banter™. Register here: https://zoom.us/webinar/register/WN_T43NCXR2Sg2jDmVpxUZXgw
Widespread availability of PoC Linux LD_PRELOAD rootkits means that even trivial cryptomining attacks are starting to deploy them. This talk demonstrates a simple LD_PRELOAD rootkit and techniques for detecting them in a live response scenario and by memory analysis. Get the jump on your adversaries with this fast-paced, practical introduction.
Chat with your fellow attendees in the Antisyphon Discord server here: https://discord.gg/antisyphon -- in the #webcasts-livestreams channel
Widespread availability of PoC Linux LD_PRELOAD rootkits means that even trivial cryptomining attacks are starting to deploy them. This talk demonstrates a simple LD_PRELOAD rootkit and techniques for detecting them in a live response scenario and by memory analysis. Get the jump on your adversaries with this fast-paced, practical introduction. Chat with your fellow attendees in the Antisyphon Discord server here: https://discord.gg/antisyphon -- in the #webcast-livestreams channel
Trap hackers with cyber deception: set Dirbuster, gobuster, feroxbuster or any web crawlers off into an infinite rabbit hole with Spidertrap! Maybe some inspiration for you to craft your own countermeasures and give defense _more time_ to respond to attacks.
https://youtu.be/PS--LR0nrWc
This is a showcase of the Spidertrap lab and exercise from @strandjs & @Antisy_Training Pay What You Can training: thanks for their sponsorship & support! You can learn more Cyber Deception: https://jh.live/pwyc
Join us for an Anti-Cast this Wednesday with the Linux master himself, @hal_pomeranz ! Webcast starts at 12 p.m. ET, PreShow Banter™ at 11:30 a.m. ET. Register here: https://zoom.us/webinar/register/WN_1OQ0y_kMRPydr6ECFizHjg
If you’ve been using the Linux command line for a long time, you may have missed out on some sweet new features of common commands that can make your life much better. Join Sensei Hal as we break down some practical examples and demonstrate some useful new functionality.
Chat with your fellow attendees in the Antisyphon Discord server here: https://discord.gg/antisyphon -- in the #webcasts-livestreams channel
Check out Hal's class, "Linux Command Line for Analysts & Operators," that he will be teaching live, in-person at @WWHackinFest - Deadwood 2023. → https://wildwesthackinfest.com/conference/pre-conference-training/
If you’ve been using the Linux command line for a long time, you may have missed out on some sweet new features of common commands that can make your life much better. Join Sensei Hal as we break down some practical examples and demonstrate some useful new functionality. Chat with your fellow attendees in the Antisyphon Discord server here: https://discord.gg/antisyphon -- in the #webcast-livestreams channel
New to Azure pentesting and feel like you could use a little guidance? Then be sure to check this past Black Hills Information Security webcast, "Getting Started in Pentesting The Cloud–Azure," with @dafthack!
Watch the webcast here: https://www.youtube.com/watch?v=u_3cV0pzptY
Register for "Breaching the Cloud" with Beau June 27-30: https://cvent.me/VKRn0e?RefId=BHIS203_MD
Webcast published 6/2/21