Jeremy Mill  

200 Followers
234 Following
828 Posts

I released v2.1.0 of RMML. The big changes in the past few days are:

- A full export of sigma rules for detections
- The addition of Jump Desktop signatures

https://github.com/LivingInSyn/RMML/releases

#cybersecurity #infosec

Releases · LivingInSyn/RMML

A list of RMMs designed to be used in automation to build alerts - LivingInSyn/RMML

GitHub
I propose we replace semantic versioning with pride versioning

NGC 6727: The Rampaging Baboon Nebula

Image Credit & Copyright: Alpha Zhang & Ting Yu

https://apod.nasa.gov/apod/ap240924.html #APOD

APOD: 2024 September 24 – NGC 6727: The Rampaging Baboon Nebula

A different astronomy and space science related image is featured each day, along with a brief explanation.

@catsalad that's just character deny-listing by another name 😂

Someone wrote a cool blog post using RMML for building detections

https://frank-korving.com/posts/kql_and_rmms/

#cybersecurity #infosec

Detecting RMMs using KQL · Frank Korving

Introduction This is a short write-up on using Kusto Query Language (KQL) to detect Remote Monitoring and Management (RMM) artefacts in your process- and network telemetry. It uses multiple open-source projects that aggregate and centrally collect information on available RMMs. Threat actors often make use of legitimate and well-known RMM solutions during real world intrusions. These remote access tools are typically used as initial access vectors after a successful social engineering campaign and then used as a beachhead into the compromised network to pivot, deploy new tooling or exfiltrate data.

Interesting notes from the RMML traffic (https://github.com/LivingInSyn/RMML)

The most looked up RMMs are:

- AnyDesk (49)
- ngrok (20)
- GoToMyPC (14)
- TeamViewer (14)
- N-Able (12)

#cybersecurity #infosec

GitHub - LivingInSyn/RMML: A list of RMMs designed to be used in automation to build alerts

A list of RMMs designed to be used in automation to build alerts - LivingInSyn/RMML

GitHub

@krausedw it's a fair point. This question first came up with ngrok and we had a debate on if we should include it or not. Ultimately we decided that we should since it fit the threat category even if it wasn't a true rmm

Maybe we can add a metadata tag to the definitions so if users only want RMMs they can exclude anything that isn't

I cut release v.1.5.0 of RMML (a list of RMMs designed to be used by security tools in an automated fashion) to include VSCode tunnels which are under use by threat actors

https://github.com/LivingInSyn/RMML/releases/tag/v1.5.0

#cybersecurity #infosec

Release v1.5.0: Merge pull request #39 from LivingInSyn/vscode_tunnel · LivingInSyn/RMML

v1.5.0 Added a definition for VSCode tunnels v1.4.1 Updates on QuickAssist and Aterna definitions by @Korving-F Typo fixed in TailScaleD by @ruppde v1.4.0 Added meshagent Added JSON to CI v1....

GitHub

Pushed v1.4.1 of RMML: https://github.com/LivingInSyn/RMML (a repository of RMM definitions designed to be used in automations)

Includes two new contributors and some updated definitions!

#infosec #cybersecurity

GitHub - LivingInSyn/RMML: A list of RMMs designed to be used in automation to build alerts

A list of RMMs designed to be used in automation to build alerts - LivingInSyn/RMML

GitHub

Pushed v1.4.1 of RMML: https://github.com/LivingInSyn/RMML (a repository of RMM definitions designed to be used in automations)

Includes two new contributors and some updated definitions!

#infosec #cybersecurity

GitHub - LivingInSyn/RMML: A list of RMMs designed to be used in automation to build alerts

A list of RMMs designed to be used in automation to build alerts - LivingInSyn/RMML

GitHub