Windows Console Command History: Valuable Evidence for Live Response Investigation

Posted by Tom Sela on Jan 11, 2018 8:01:49 AM

Note:  This blog is an updated version of a piece originally published in the March 2017 edition of eForensics Magazine

Read More


Phishing the Phishers: Using Attackers’ Own Tools to Combat APT-style attacks

Posted by Dolev Ben Shushan on Dec 28, 2017 6:49:04 AM

As a deceptions researcher, part of my job is to design deceptions against attackers by manipulating or reverse-engineering the common toolkits attackers use. Deceptions are pieces of false information that are planted across the organization and appear as real, relevant information to the attacker. For example, browser deceptions — pieces of information specifically planted in browser history, saved forms, etc. — can be created to lure malicious hackers and insiders to deceptive web servers. In this article, we will show how phishing can be used to catch attackers and how phishing kits can be used for defensive purposes.

Read More


Cyber attacks continue to target SWIFT: The Globex Bank Incident Reminds Us of Urgent Actions to Prevent Fraud Losses

Posted by Matan Kubovsky on Dec 22, 2017 5:22:45 PM

As 2017 comes to a close, the string of recent attacks on SWIFT and other financial messaging systems are emerging as one of the main threat trends. News has just surfaced of another such attack – this time impacting Globex Bank in Russia, which took place on December 15th. Attackers apparently attempted to steal almost $1M by manipulating international transfer requests through the systems within the bank that connect to the SWIFT messaging service. 

Read More


Case Study: Deception Catches an Insider Threat

Posted by Hadar Yudovich on Dec 21, 2017 4:16:21 AM

People usually associate “advanced persistent threat” (APT) with malicious outsiders—nation-state or other sophisticated attackers. Generally, once an APT attacker has established an initial foothold, they conduct “low-and-slow”-style attacks involving a prolonged period of reconnaissance and lateral movement. Insider threats are usually thought of as intentional (or sometimes accidental) acts of data theft or other compromise committed by trusted users who know their way around and have legitimate, open access to sensitive assets.

Read More


MoneyTaker: A Simple Step to Avoid Being the Next APT Target

Posted by Matan Kubovsky on Dec 13, 2017 3:16:22 PM

The threat news of the week is about MoneyTaker – a cybercrime group apparently responsible for theft of over $10M from 18 banks in the US and Russia. If you’ve read any of the online accounts, it’s easy to be overwhelmed by the details and the growing sophistication of cybercrime groups. While it’s important not to downplay their fierceness and the growing risks associated with advanced persistent threats, it’s also important to focus on the relatively simple capability organizations can embrace to combat them.

Read More


From Honeypots to Endpoint-Based Deception: Deception Becomes a Cybersecurity “Must-Have”

Posted by Beth Ruck on Dec 7, 2017 8:22:48 AM

It goes without saying that rigorous security controls are irreplaceable. But no matter how strong an organization’s cybersecurity defenses are, determined attackers will still get in. Whether malicious insiders or external actors, persistent attackers fly below the radar and reside for months inside a network. They’re patient, studying the infrastructure and carefully planning their attack because what they’re typically after are the crown jewels of your business: essential data volumes, intellectual property, financial transactions, or revenue-dependent business operations.

Read More


Stay up to date!

Popular Posts

  

> Share Post