Advertisement
DShield SIEM Update: ELK Stack 8.19.15 and Enhanced Logging
SANS ISC updates the DShield SIEM to ELK stack 8.19.15, introducing enhanced logging capabilities and new dashboards for improved honeypot data analysis.
MSI Malware Detection: Statistical Analysis for Base64 Payloads
Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.
Detecting API Discovery Scans for swagger.json: Security Guide
Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.
YARA-X 1.17.0 Release: Enhanced Performance for Malware Analysis
YARA-X version 1.17.0 release introduces five performance improvements and a bugfix for the Rust-based malware detection engine. Enhance your scanning speed.
DShield Honeypot Updates: Ensuring Timely Threat Data Collection
SANS ISC announces upcoming updates for DShield honeypots. Learn why these automatic updates are crucial for maintaining effective threat intelligence collection.
IPv6 Security: Mitigating Rogue Router Advertisements and NDP Risks
Analysis of IPv6 Neighbor Discovery Protocol vulnerabilities and why security teams must prioritize RA Guard and monitoring to prevent traffic interception.
Advertisement
Honeypot Data Analysis: Predictable Year and Season Password Patterns
SANS ISC research reveals how attackers exploit predictable password patterns, such as years and seasons, driven by outdated rotation policies.
AI-Assisted Code Review: Uncovering Common Python Flaws
A SANS ISC diary highlights how AI identifies long-standing, common security and logic errors in Python scripts, emphasizing the need for robust code review.
Phishing Credential Exfiltration via EmailJS and React Frameworks
Security analysis of a sophisticated React-based phishing kit that leverages the EmailJS service for stealthy exfiltration of user credentials.
Phishing Campaign Leverages Donut Loader via Spoofed FedEx Alerts
Analysis of a phishing campaign using fake FedEx delivery notifications to deliver the Donut loader framework for in-memory shellcode execution.
Hypervisor-Based Persistence: Abusing Virtual Machines for Stealth
Analysis of how threat actors leverage virtualization platforms to host malicious guest OSs, bypassing host-level EDR and maintaining persistent access.