RE: https://infosec.exchange/@BleepingComputer/115770545217304518
I know this shit isn't new, but @Dio9sys and @da_667 if I send you one of these fake PoCs sometime, let me know. Depending on the day, I wouldn't mind some fuckery.
Security researcher by day, weird deer lady by night. Big fan of usenet and smolnet and prone to talking in equal measure about Linux and stuffed animals.
She/her
| Gemini capsule | gemini://dio9sys.fun |
| neocities | https://dio9sys.neocities.org/ |
| uwu or owo | uwu |
RE: https://infosec.exchange/@BleepingComputer/115770545217304518
I know this shit isn't new, but @Dio9sys and @da_667 if I send you one of these fake PoCs sometime, let me know. Depending on the day, I wouldn't mind some fuckery.
@Mustardfacial @cR0w @Dio9sys Well, the good news is, you don't have to guess how I do what I do for a living, I wrote a lot this year about that subject.
IoC Pivoting and the Pyramid of Pain: https://community.emergingthreats.net/t/introduction-to-ioc-pivoting-and-the-pyramid-of-pain/2566
Flexible Rule Writing: Seeing Around the Bend: https://community.emergingthreats.net/t/flexible-rule-writing-seeing-around-the-bend/2568
But more particularly, towards exploit reproduction, this is the good stuff:
Come Sail the CVEs, Part 1: https://community.emergingthreats.net/t/flexible-rule-writing-seeing-around-the-bend/2568 (building a decent RSS feed)
Come Sail the CVEs, Part 2: https://community.emergingthreats.net/t/come-sail-the-cves-part-2-turning-data-into-rules/2751 (exploit modification and reproduction)

Couple of days ago, my boss introduced me to this great blog post by sekoia.io, about the PolarEdge botnet. I love tearing apart research to make (hopefully) good IDS sigs for finding future exploit attempts, and/or retrohunting for evidence of other exploit attempts. Sekoia delivered me a trove of information. I have HTTP requests for CVEs used to compromise boxes. HTTP structs used for installing backdoors, HTTP structs for interacting with the backdoors, interaction with the C2, Domains, IP ...
Voxel deer head at gradually larger resolutions. So far I'm most proud of the larger one!
I should probably start dialing in how wide i want the head to be. The muzzle is starting to read a little bit like a big beardy cat mouth
I found canned brown bread (with raisins!) at the store. This is not something I have ever had, so I bought it.
So tell me, people of fedi....what do you do with canned brown bread?
