Skip to content

Cybersecurity Awareness

Ideally, we should all know this stuff by heart, but as you know that’s just not the case. It’s far from it. Cybersecurity awareness is an expression that probably bores people to death when they hear it – and rightly so! We are the ones that gave it a bad name, by doing weird and unnatural tests on our users, usually to please auditors/upper management/c level.

This notorious term usually means your organization has provided you with a bunch of videos to look at, that you, as a let’s say someone from sales or accounting, won’t care much about nor will understand fully.

Same goes for the phishing campaigns that are internal for the companies. They can actually work against you, as users can adopt the attitude of everything’s suspicious, I am not going to click or reply to any emails before forwarding them to the Cybersecurity team which is better than clicking on stuff blindly, but can easily saturate your team’s capabilities to investigate, leading to much slower resolutions and other issues. This is one of the more benign examples, but its still quite real. And if your SOC team is checking every email, they might miss some much more important event.

Obviously, social engineering is extremely tough thing to crack and control, especially since emails are also hard to defend from appropriately (not to mention that there’s almost no real solution for detecting a fraudulent email that’s coming from an internal compromised mailbox) and its what’s the crux of the whole issue. As with all things, you need to strike some balance here.

Educate your users of course – I still feel this is one of the (if not the) most important thing, but also set aside some time to understand their context, thus their ‘answers’ if you’ve just did a phishing campaign. There’s usually a reason behind every one of those user-based actions, and ideally you are going to understand your users and why they do such thing.

To conclude, I still feel that education on Cyber awareness is paramount, but if you’re going to do it blindly with out of context surveys, random videos, and phishing campaigns (that you grade on how they passed just to impress upper management) – I dare say better not to do it at all!

With that out of the way, let me try and connect some dots, and talk about the most common things an organization might experience, regardless of its size or maturity.

Common Attacks

For this article, I opted to talk about social engineering (phishing), malware and ransomware, as well as passwords and authentication. In the second, upcoming, part of this article I will talk more about MFA, backups, patches, and other things you can do to stay safer and endorse a better cyber hygiene.

Social Engineering

Social Engineering, sometimes known as People hacking is a term that is used to describe a cyber attack that targets a human, rather than a computer/electronic device.

No need to brute force and waste your CPU/GPU, when you can ask nicely, right?

All jokes aside, these social engineering attack can be extremely complex, and quite devastating to the victim as well. These attacks are usually layered and can escalate quite a bit. Imagine an attacker taking some of your publicly available information to use and obtain more information on your phone, email, ISP.

With these steps, they can eventually escalate to something like your bank account! Check this video out, as it is a prime example of how attackers can obtain your information.

Social engineering is a huge topic! And I mean huge. It also doesn’t necessarily entail a human interaction. Most notorious examples of this are the parking lot ‘lost’ USB an attacker would drop in hopes of an employee plugging it into a computer that belongs to the company. Another one is leaving the charging cable plugged in, in a very public place. Similarly to the lost USB, the cable most likely has some keylogging software or another tool to help the attacker gain control of your device.

Social Engineering: Phishing

Phishing is as we all know one of the most common attacks out there, used by many different types of threat actors, from scammers to more advanced threat actors. This is the stage zero for an attack, usually. This attack vector is used to gain access to your org’s infrastructure, before trying to move laterally, escalate privileges, drop payloads, or anything else.

This is an attack that’s a ‘subgroup’ of the social engineering class of attacks, and as the name implies, is directed against humans instead of computers.

When we say phishing, we usually mean emails, but phishing can be done through voice/calls – aka Vishing or through SMS – aka Smishing.

These are particularly dangerous since threat actors will use these tactics on an enormous scale, usually leveraging leaked/stolen phone numbers and/or emails.

I’ve already talked about most common ways phishing tries to get us to act – e.g., urgency, calling you to action, basically anything to make you act quickly without much contemplation.

There are also three main forms in which we can see phishing:

  • Spearphishing – More targeted than general/regular phishing, spearphishing usually aims at an individual or a group. These campaigns are usually more carefully crafted than the email messages and bad sites you can see with general phishing since they are created with the idea to target a specific group. Oftentimes, as a part of a much larger campaign against the said group.
  • Whaling – More targeted than spearphishing, whaling refers to targeting individuals of high-value – think C-level execs. These messages tend to be most sophisticated as well, thus, much harder to notice.
  • Phishing – There’s no personal/individual component here, these attacks are usually of a larger scale, simpler and are generally much easier to spot since the messages are usually not that carefully crafted, and the malicious sites they try to refer you will mostly contain some obvious red flags that will signal for you that it’s time to get the hell out.

Individually, you might encounter general phishing attacks, but if you work at a high level in a big company that’s an interesting target, your business email might be of particular interest to the threat actors, making you become a prime target for these more sophisticated attacks such as whaling and spearphishing.

Good/best practices Recap

I already talked about this extensively, but there’s never enough awareness when it comes to phishing, if you ask me, so let me add these here as well:

  • Untrusted email? Delete without opening, or even better, if you have a Cybersec team at your company, forward it to them. You can also report as a spam to your email provider.
  • Never open attachments from untrusted sources. Even if the contact is legitimate but the content/email message wasn’t expected by you.
  • Do not click on embedded stuff in the emails – if possible, go to that site through your browser (no clicks in your email client!) and try to see the content there.
  • Check for misspelling in the domain names, etc.
  • Try not to publicly share your personal information. Segment your stuff. If necessary, create another email, or even do ‘burner’ email addresses that you will use for a specific purpose before discarding it.

Also remember that any one of us can fall prey to phishing. If this happens to you, change any passwords that are tied to the breach (if you have multiple same passwords – ouch, please don’t do this though – change all the instances of the compromised password). Report immediately to IT/Cybersec team if this happens on the work email.

Malware

It doesn’t matter if our AV solutions are becoming better and better, scanning against large databases that collect malicious hashes/signatures for malware, this is still a big threat and it is always being worked on, developed.

Malware or malicious software is any piece of software that was designed with the intent to do malicious things to your system. There are many different types of malware, and I will be looking into this in the future, but for now I will just focus a bit on one of the most infamous types of malware, that we have all heard being talked about in the past couple of years, a lot – Ransomware.

Ransomware

Ransomware is a special type of malware, used to infect systems while encrypting the data so that it is held for ransom, hence ransomware. In theory, if the victim was to pay the ransom, the data is then returned to its owner. However, most security experts would advise you not to pay ransom but to rather have DLP policies and good backups so you can recover from this attack.

Even if the data’s returned, there’s no guarantee that it wasn’t leaked first. The payment is usually made in cryptocurrencies (such as Bitcoin).

Ransomware spreads by exploiting vulnerabilities in software (think MS Office, Windows, etc.) and can be quite fast to spread. The idea is to infect as much systems as possible, so they are rendered inaccessible and then ask for ransom – paying the attackers to give you their key to decrypt the data.

There’s usually a window that displays the message with the conditions, once the malware completes its encryption.

Wannacry Ransomware window – Instructions on paying the ransom

Tips on how to protect yourself

Generally, its best to combine good awareness with up-to-date systems that are patched up. This is especially important for OSes!

  • Update your OS and other software regularly
  • Don’t open suspicious emails or click on suspicious links. Don’t open attachments. Similar to phishing best practices.
  • Back up your important data and store it somewhere safe and outside of reach
  • Keep you AV solution up-to-date
  • Never plug unknown USBs and other media (cables too) into computers that you care about or are important!!

Lastly, don’t pay the ransom! Rather, have a strategy in place if this happens, and contact authorities. Try to contain the infection as well, by disconnecting your network gear if and where needed. However, keep in mind that you might not want to power off the infected device since this can backfire on you, leaving you with no options to decrypt it without paying the ransom.

Conclusion

There’s much more that threat actors use, and there are many other types of malware out there. In time, I hope to cover most of them, but until then just keep in mind that you don’t necessarily need to be a tech expert or an Infosec pro to stay safe online. Most of the stuff I outlined in this, and previous articles pertains to best practices e.g., adopting good habits. This is something anybody can do and is for sure something that pays off to adopt.

Until next time!

Cover image by Michael Geiger

#cyberawareness #malware #phishing #common-attacks #ransomware

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About VRX
VRX is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.

The UK’s Interesting (and Important) Strategy for National Cybersecurity

Defense is arguably the core function of the state – a government will protect its people. In that context, it has been interesting to observe the rise of cyber attacks as a major global threat. Defense agencies are used to protecting people from bombs and bullets, but what is their responsibility to protect against malware or man-in-the-middle attacks?

It’s a fascinating question, I think, without many clear answers. One way to approach it is by looking at the national cybersecurity apparatus in place across comparable companies. How, for instance, does the US promote cybersecurity compared to the UK?

Quite differently, as it turns out. As I will soon explore, the UK takes an active, highly involved approach to defending individuals and organizations against cyber attacks. The US feels more hands-off by comparison.

Granted, US cyber readiness is quickly changing; The State and Local Government Cybersecurity Act of 2021 makes cybersecurity a much bigger national priority. Still, I was struck while reading some recent research by how our friends across the pond handle cybersecurity (a clear and present danger to national security) compared to ourselves. It’s night and day from my perspective – and my hope is that we can learn from the UK way to improve over here, not just in the federal government but at security centers across the public and private sectors.

Get to Know the UK National Cyber Security Centre

Protect the majority of people in the UK from the majority of the harm caused by the majority of the cyber attacks the majority of the time.”

That’s the stated mission of Active Cyber Defence, a program of the UK National Cyber Security Centre (NCSC) that takes a refreshingly realistic approach (the majority is not the entirety) to stopping cyber attacks. More refreshing, however, is the emphasis on active defense designed to prevent attacks and protect proactively.

Other national governments, including the US, work to stop attacks and strengthen security, but that effort often feels underwhelming. To put this issue into perspective, does any US organization struggling with cybersecurity think of the government as their first or best solution? No. They solve problems by buying defenses, subscribing to services, hiring consultants, or recruiting staff. The government feels irrelevant in this equation. At least it does here, but that’s not the case in the UK.

The Active Cyber Defence program has, over the last five years, eliminated countless threats, significantly reduced cyber risk throughout the UK, and prevented gigantic losses. Which is to say, the impact has been real and significant.

To help understand what that impact looks like, consider the still-fresh Solar Winds attack that affected national governments around the world. The US had 9 agencies compromised, including all three branches of the military. It was bad. The UK, by comparison, hand only a few organizations affected, and all in the private sector. It was mild. The efforts of the NCSC don’t deserve all of the credit, but they undoubtedly deserve some. We should learn from what’s working.

What the Brits Do Differently

Let me reiterate that I don’t think the US cybersecurity efforts, handled primarily by the Cybersecurity & Infrastructure Security Agency (CISA), are severely derelict or deficient. They have plenty of successes to celebrate, not to mention more to protect than their counterparts in the UK. But when you compare CISA to NCSC, the differences in approach come into focus.

Here’s an easy exercise: Look over this page of free cybersecurity services and tools offered by the CISA. It’s just a long list of links to (primarily) third-party or open-source solutions. Now compare that to the page of services and tools offered by the NCSC. Not only is the presentation and organization much smarter, but all the resources highlighted were developed by the NCSC specifically.

The quality and character of the resources are different. But it strikes me that the entire approach is different. Consider this quote from the NCSC website – “ACD (active cyber defence) is intended to tackle the high-volume commodity attacks that affect people’s everyday lives, rather than the highly sophisticated and targeted attacks, which NCSC deal with in other ways.” The program targets the most common attacks and strives to prevent them proactively. It’s all about getting in front of attacks. As such, all of the tools, resources, and guidance facilitate finding and fixing weaknesses before they turn into incidents. By offering free assistance to organizations across the UK, the group responsible for lowering cyber risk is accomplishing exactly that. I wouldn’t say the US approach feels passive or reactive, necessarily. But what the Bits do feels a lot more active, agile, and animated to me.

As the emphasis of cybersecurity shifts to prevention (rather than detection and response), I think the Active Cyber Defence program is a model for other national cybersecurity efforts and one that also applies to any organization striving to improve cybersecurity. Make prevention the highest priority, and put the tools in place to make that possible. That’s where real resilience and risk reduction come from.

I have more thoughts on what makes this program unique and important. I also want to bring some data into the conversation to illustrate how and why Active Cyber Defence keeps the UK safer than places without it.

Stay tuned for that. In the meantime, I’m curious what this community thinks about national cybersecurity in the US, UK, or around the world? What’s working and what isn’t? And what are the lessons or resources we can bring into private sector security centers? I know this community has expertise in places where I have blind spots, so please bring your own perspectives to the table.

#cybersecurity #CISA #US #UK #Defense #NCSC

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About VRX
VRX is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.

Security Tools – Pt. 2

Intro

Continuing where we left of, we have curated a list of another five tools. These are once again belonging to different branches of Cyber, as per our intention to cover the most ground with the least steps taken. We will expand on the topics, as well as some of these tools, in the future, but for now we would like to introduce them and provide a high level overview of their purpose, capabilities, and general uses.

Burp Suite

Burp Suite probably doesn’t need much introduction as it is well known inside the community, but let’s explain some basics about how Burp works and what are some of the options that are offered. Essentially, Burp Suite is a Web Hacking framework – Web App Pentesting framework, to be precise. Burp Suite is pretty much the industry standard when it comes to web app security, and since its features enable it to test APIs, Burp is also used for mobile apps.

At its core, Burp intercepts the traffic between the webserver and the client, enabling the attacker to manipulate it. We can then issue our own requests for the server as we see fit. Burp also has the ability to forward the captured requests to other parts of the application – something we’ll explore in more depth in the upcoming Burp Suite series.

Burp comes with three different license options: Community, Professional, and Enterprise.

If you’ve used Burp in the past, chances are you’ve used the Community edition. Professional license is a yearly paid subscription, but it offers even more great features. Enterprise is a bit different to the two other versions, as it is intended for continuous scanning – automatically scanning your web apps for vulnerabilities – which would make sense in an enterprise environment.

Generally, there’s no need for the pro version as the Community version is extremely powerful by itself, but the pro version does have more automated and expanded features, such as API integration with other tools, option to save the projects and generate reports, automated vulnerability scanner, unlimited access to add new extensions, and more.

  

Splunk

Splunk name has become synonymous with SIEM (Security Information and Event Management), which is of no surprise as it is being heavily used in the industry, especially in large enterprise environments.

SIEM solutions are basically a centralized location where you can ingest the logs from your environment, from various sources. They are collected and normalized, so that they can be more easily investigated, and queried, by the analyst.

Aside from being able to ingest virtually any data, Splunk also offers a lot of additional capabilities in the form of Splunk apps (you can browse them here). One important Splunk app to mention is TA-Sigma-Searches which we can use to create queries in the sigma format, for easier sharing with other analysts or teams that don’t necessarily us Splunk as their SIEM solution. This is incredibly important since all SIEM solutions have different format for creating queries, and you might be on a team that doesn’t use Splunk – or vice versa.

With Splunk, you can also create alerts that are triggered when a specific condition is met. This is generally used for responding and monitoring of events.

Furthermore, all of this data can be tailored to your own purpose with detailed dashboards and visualizations.

Nessus

Nessus is a vulnerability scanner, which scans your infrastructure for vulnerabilities.

What makes Nessus unique and different from other scanners is the fact that it doesn’t make assumptions. For example, it won’t assume that your port 80 is running a web application.

Nessus can be deployed on almost any platform, including your Raspberry Pi, it also has more than 450 pre-configured templates which can help you quickly address your vulnerabilities. Its reporting capabilities are such that you can configure them as per best aligning formats for your security practices.

MISP

MISP, or short for Malware Information Sharing Platform, is a threat information platform which enables collection, storing, and sharing of threat intelligence and IOCs that relate to cyber attacks, malware, or any other intelligence, between trusted members. After all, two enterprises can both be targeted by the same threat actor, and MISP sees to it that you can safely share intel and collaborate between each other.

Your threat information can in turn be used by SIEMs and NIDS (Network Intrusion Detection Systems). MISP can be used for security investigations, intelligence, risk, and fraud analysis, and more.

MISP functionalities support Indicators of Compromise (IOC) database, data sharing (according to the different distribution models – from open/public, to semi-closed, and private), import and export capabilities, automatic correlation, and API support (you can integrate it with your own systems to obtain and export intelligence).

Much more great information on MISP can be found here, and on the MISP Project Github repo here.

REMnux

REMnux is a Linux toolkit for reverse-engineering and analysis of malicious software. REMnux can help you with:

  • Analyzing malicious MS Office macros (most common way malware developers distribute their payloads)
  • Identifying and analyzing malicious payloads in various formats (.pdf’s, .exe’s, etc.)
  • Memory forensics on infected systems
  • Gathering and analyzing threat data
  • Exploring network interactions for behavior analysis
  • Investigating system-level interactions of malware

and more!

Tools inside this REMnux bundle are free, however, they have their own individual licenses, and it’s up to you to figure out how you’re going to use them, in accordance with their respective restrictions. Other contents that are part of the REMnux toolkit, like configuration and code, are licensed under the GNU General Public License v3.0 – unless otherwise stated.

The easiest and fastest way to start with REMnux is to download the REMnux distro .OVA file and run it on the hypervisor software of your choice (there’s a separate download for Virtual Box). You can also run the REMnux distro as a Docker container, as well as install it on a dedicated machine.

Conclusion

So, we’ve scratched over an incredibly large surface and probably opened up a bunch of new questions; that is why in the upcoming articles we will ‘zoom in’ more into some of these tools. Of course, aside from writing a full-fledged book, we can’t hope to ever cover them all in the way they would deserve, even if we were to make series out of every one of the tools mentioned.

With all that in mind, you could think of this mini-series of articles as our Cyber-appetizers to the main course – which is fully up to your discretion. We hope some of the links shared will help you create it for yourselves, in accordance with your palate.

Bon appetit!

Cover image by Immo Wegmann

#Burp #MISP #Splunk #Nessus #Tooling #Cybersec

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About VRX
VRX is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.

Exploiting Google SLO Generator with Python YAML Deserialization Attack

Introduction

A patch was released in September of 2021, so users who updated their code won’t be exposed to this attack. Users who have not updated should do so as soon as possible. It is unknown how many of the ~167,000 applications that use this library are running vulnerable versions. The purpose of this exercise is to encourage developers to update to an adequately protected version, detailed throughout this blog.

What is SLO Generator?

According to their Github page, SLO Generator is a tool to compute and export Service Level Objectives, Error Budgets and Burn Rates, using Configurations written in YAML or JSON. In layman’s terms, it’s a tool for engineers who wish to track their web API performance. Many Google services, along with other projects wishing to record these metrics, use this tool.

SLO Generator Python library can be directly installed from PyPI with pip

Figure 1: Installing the SLO Generator Python library

Usage

Once installed, it is easy to generate the SLO report with the command line interface

“`slo-generator compute -f slo_config -c shared_config –export“`

Here, 

Compute argument to the slo-generator indicates that we want to generate a SLO report

The tool also provides the functionality to migrate older, version 1 configuration to newer, version 2 configuration.

“`slo-generator migrate -s old_config/ -t new_config -b error_budget_policy/config.yaml “`

For a successful migration, the migrate command needs 3 inputs from the user:

  1. a directory containing old SLO configurations.
  2. a directory containing newer slo configurations
  3. a yaml file containing error_budget_policy

Exploitation

There are several techniques to find a potential vulnerability in older versions, such as manually combing through the source code, fuzzing the application, or analyzing recent patches to the application. 

Let’s analyze the recent patches first, attempting to discover any potential vulnerabilities. SLO Generator is an open-source tool; this information is all publicly available on their Github repository.

Looking through the release notes of version 2.0.1, we can see that they fixed the yaml loader security issue, meaning older versions of SLO Generator (i.e. v 2.0.0) would have the yaml loader vulnerability.

Figure 2: Version 2.0.1 fixes the yaml loader security issue

Looking at the changed files, we can see that in the patch, developers have replaced yaml.Loader, which is vulnerable, with yaml.SafeLoader.

Figure 3: Developers replace yaml.Loader with yaml.SafeLoader

Looking at the official documentation for pyyaml, it is mentioned that calling yaml.load on any untrusted data is as dangerous as pickle.load, a common attack path making it possible to provide malicious shellcode as input, causing remote code execution.

This indicates that if we can control the data which is passed to the yaml.load function, we can perform a python deserialization attack to get the code execution on the application.

Looking through the changes, we see there is a function called ‘ebp_v1tov2’, which is calling the yaml.load function on a variable called “conf”. As we can see on line 262, every file in the variable ebp_paths will be passed through yaml.load as “conf”.

Figure 4: Dissecting code line 264 for yaml.load

As per line 70, ebp_paths is a list containing files in error_budget_policy_path which we pass to the application.

Figure 5: Code line 70

Creating the Exploit

Our first step is to create a malicious python deserialization object that we store in a yaml path. Next, we call the migrate function with error_budget_policy_path pointing to our malicious file. Our malicious file will be loaded by the application and our code will be executed.

As generating a yaml deserialization payload is out of the scope, we will find a common deserialization payload and copy it to our attack yaml file as exploit.yaml.

Figure 6: Deserialization payload with exploit.yaml

Now, running the following command to exploit the application:

Figure 7: Command to execute payload

As SLO Generator is a widely used python library, a code execution vulnerability makes it more severe. A typical exploit scenario would be executed in a web application to migrate user-supplied configuration.

Solution

All instances of SLO Generator should be updated to the latest version. Most applications handle user-supplied yaml data. Yaml data should always be handled correctly. Avoid using unsafe functions such as yaml.load, and replace it with yaml.SafeLoad. At an absolute minimum, it is imperative that all instances be updated past ‘yaml loader security issue 173’ to protect against this exploit.

Key Takeaways

This exploit shows the severity of using unsafe functions such as yaml.load. Any application that processes user data directly should always handle data with extreme caution. From an attacker’s perspective, if an application is processing user input directly to a yaml.load function, the application could be vulnerable to the Python YAML deserialization attack.

Best Practices

  • Always keep all dependencies up to date with a dependency manager.
  • Never use unsafe functions to directly process user data.
  • Check for and install updates/patches when available.

Conclusion

Although this version of SLO Generator has been updated since September 2021, it nonetheless highlights the importance of proper and timely stewardship of software tools. As we have explored in this blog, it is relatively easy for an attacker to create an exploit for an out-of-date version. There are thousands of web applications being built with libraries such as these. Dependencies can be a useful tool, but can also come back to haunt you if not looked after properly. Lookin’ at you, Log4j.

References

1. Agrawal, A. (2014, November 18). Understanding Python pickling and how to use it securely. Synopsys blog.

https://www.synopsys.com/blogs/software-security/python-pickling/#:~:text=Dangers%20of%20Python%20pickling,data%20received%20over%20the%20network.

#exploit #python #google #slo_generator #YAML #vicarius_blog

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About VRX
VRX is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.

Threat Inteligence – Basics

Intro

In short, Threat Intelligence (aka Threat Intel) is the process of analysing data and information, with the use of techniques and tools with the goal to generate meaningful insight and patterns as to how you would mitigate potential risk that are associated with existing or emerging threats that are targeting orgs, industries, governments, etc.

We are generally interested in who is attacking us, why, and what are their capabilities. Also, we care about what IOCs and artefacts we should look for, when investigating our environment (for a particular group/threat actor).

Since Threat Intel tries to understand the connection between your operational environment and the threat actor, it usually gets broken down into the following:

  • Strategic Intel
  • Technical Intel
  • Tactical Intel
  • Operational Intel

Strategic Intel – Here, you look at your org’s threat landscape, mapping the risk areas based on trends, patterns and emerging threats that might be able to impact your business’ decisions.

Technical Intel – IR teams use this intel to create an attack surface to analyse and create defence mechanisms. Usually done by looking at the IOCs and artefacts that are tied to the threat actor.

Tactical Intel – Assessment of the TTPs used by the threat actor.

Operational Intel – Investigates the threat actors’ intent and motives for the attack. This intel may be used to understand what some of the critical assets are the org has that can be targeted. (people, technologies, etc.)

Abuse.ch

This project started as one man’s initiative but is today a community driven threat intel platform for cyber threats. In their own words:

abuse.ch‘s main goal is to identify and track cyber threats, with a strong focus on malware and botnets. We not only publish actionable threat intelligence data on cyber threats but also develop and operate platforms for IT security researchers and experts enabling them sharing relevant threat intel data with the community.

Their platforms are:

Malware Bazaar – For sharing malware samples with the community and threat intel providers

Feodo Tracker – Tracking botnet C&C infrastructure associated with Emotet, Dridex and Trickbot

SSL Blacklist – Resource for collecting and providing blocklist for malicious SSL certificates and JA3/JA3s fingerprints

URL Haus – For sharing malware distribution sites with the community and threat intel providers

Threat Fox – Resource for sharing IOCs (Indicators of Compromise) with the community and threat intel providers

Yaraify – Resource for hunting suspicious files with YARA. Also, for sharing your YARA rules with the community

 

Malware Bazaar

This platform acts as a malware collection and analysis database.

You can upload malware samples through browser/API, consequently adding to the intelligence database. This threat intel can also be integrated into your SIEM.

You can also hunt for malware setting, by making alerts that would match different signatures, YARA rules or vendor detection.

 

Feodo Tracker

This platform looks to share intel on botnet C2 (command & control – C&C) servers that are associated with Dridex, Emotet (Heodo), TrickBot, etc.

This is done by giving the C&C servers db’s to the security analysts that can then investigate any IP address they deem suspicious or have seen already. There’s also information on IP and IOC blocklists, and mitigations used to avoid infections by botnets.

SSL Blacklist

This tool identifies and detects malicious SSL connections, further blacklisting the SSL certificates used by botnet C&C servers. It also identifies JA3 fingerprints which can help you detect and block botnet C&C comms within the TCP layer.

You can sift through the SSL certs and JA3 fingerprints, but you can also download them and add them to your deny list/threat hunting ruleset.

URL House

As an analyst, this is an awesome tool for you to perform some validation for your investigation. You can look through the database for URLs, hashes, domains and other malicious filetypes. You can also contribute with your own malware URLs in order to help others protect their networks.

URL House can also give you information on AS numbers, TLDs and associated countries.

ThreatFox

The ThreatFox platform is made with the idea of sharing and exporting IOCs that are associated with malware. You can export the threat intel from ThreatFox in many formats (JSON, CSV, MISP events, Suricata IDS ruleset, Domain Host files, etc.)

Recap

Threat intelligence (aka TI or Cyber Threat Intelligence) is what you would use to supply information regarding threat landscape – TTPs, threat actor groups, etc.

To be considered threat intel (TI) the data must become actionable, and to become actionable, you would want to analyze it first. Thus, the data needs some context in order to qualify for becoming a viable piece of threat intel.

The threat intelligence usually changes quickly, as the threat actors change their TTPs often.

Companies and vendors can share their threat intel within ISACs – Information Sharing and Analysis Centers.

Another breakdown of the TI process can be like this:

  • Strategic – Helping management make informed decisions when it comes to security and strategy.
  • Operational – Interacting with IOCs and learning more about how threat actors do their work
  • Tactical – Interacting with the TTPs and attack models to learn more about the specific threat actor group and its patterns of attack

I also suggest checking out these two great resources to learn more about APTs and their techniques (TTPs):

(I will add a few more links at the end of this article)

Conclusion

Okay! So, I looked into the TI process for a bit. This is a big landscape, with a lot of events that are constantly happening. To stay current, you would need to find good resources to follow, as well as create an adequate process at your company on how to handle it, why, and in what ways/cases.

The most interesting part (at least for me) is the fact that when you investigate this behaviour (let’s say you’re using the aforementioned Feodo Tracker to investigate C2 botnet servers) you’re actually learning about what the adversary does and this is the most precious thing to have. You’re learning realistic things, that are happening all the time around the globe, all the while trying to prevent your organization from getting compromised.

You’re not only being proactive, but you’re also learning about what is really used in some of those breaches you can usually read about. This is invaluable, as it can give you the edge against adversaries, when it comes to securing your environment against them.

Stay safe out there, and gather some TI!

Additional Resources

Cover image by Alexandre Debieve

#threat_intel #abuse.ch #ioc

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About VRX
VRX is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.