Skip to main content
← All Articles

Tag

#SANS ISC

11 articles

Advertisement

INFO
Threat Intel

DShield SIEM Update: ELK Stack 8.19.15 and Enhanced Logging

SANS ISC updates the DShield SIEM to ELK stack 8.19.15, introducing enhanced logging capabilities and new dashboards for improved honeypot data analysis.

Runtime Rebel Intel
3 min read · Jul 15, 2026
MEDIUM
Malware

MSI Malware Detection: Statistical Analysis for Base64 Payloads

Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.

Runtime Rebel Intel
4 min read · Jun 15, 2026
MEDIUM
Threat Intel

Detecting API Discovery Scans for swagger.json: Security Guide

Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.

Runtime Rebel Intel
3 min read · Jun 3, 2026
LOW
Threat Intel

YARA-X 1.17.0 Release: Enhanced Performance for Malware Analysis

YARA-X version 1.17.0 release introduces five performance improvements and a bugfix for the Rust-based malware detection engine. Enhance your scanning speed.

Runtime Rebel Intel
3 min read · May 31, 2026
INFO
Threat Intel

DShield Honeypot Updates: Ensuring Timely Threat Data Collection

SANS ISC announces upcoming updates for DShield honeypots. Learn why these automatic updates are crucial for maintaining effective threat intelligence collection.

Runtime Rebel Intel
4 min read · May 4, 2026
MEDIUM
Threat Intel

IPv6 Security: Mitigating Rogue Router Advertisements and NDP Risks

Analysis of IPv6 Neighbor Discovery Protocol vulnerabilities and why security teams must prioritize RA Guard and monitoring to prevent traffic interception.

Runtime Rebel Intel
3 min read · Apr 14, 2026

Advertisement

MEDIUM
Identity & Access

Honeypot Data Analysis: Predictable Year and Season Password Patterns

SANS ISC research reveals how attackers exploit predictable password patterns, such as years and seasons, driven by outdated rotation policies.

Runtime Rebel Intel
3 min read · Apr 9, 2026
INFO
Threat Intel

AI-Assisted Code Review: Uncovering Common Python Flaws

A SANS ISC diary highlights how AI identifies long-standing, common security and logic errors in Python scripts, emphasizing the need for robust code review.

Runtime Rebel Intel
5 min read · Mar 24, 2026
MEDIUM
Threat Intel

Phishing Credential Exfiltration via EmailJS and React Frameworks

Security analysis of a sophisticated React-based phishing kit that leverages the EmailJS service for stealthy exfiltration of user credentials.

Runtime Rebel Intel
3 min read · Mar 13, 2026
MEDIUM
Malware

Phishing Campaign Leverages Donut Loader via Spoofed FedEx Alerts

Analysis of a phishing campaign using fake FedEx delivery notifications to deliver the Donut loader framework for in-memory shellcode execution.

Runtime Rebel Intel
4 min read · Feb 27, 2026
MEDIUM
Threat Intel

Hypervisor-Based Persistence: Abusing Virtual Machines for Stealth

Analysis of how threat actors leverage virtualization platforms to host malicious guest OSs, bypassing host-level EDR and maintaining persistent access.

Runtime Rebel Intel
4 min read · Feb 26, 2026