Did you know that since v3.0.0 of misp-modules and v3.0.1 of misp-docker/misp-modules it is possible to load custom misp-modules without building your own image? Just drop them in the corresponding /custom/ directory.
github.com/MISP/misp-do...
github.com/MISP/misp-do...
11.03.2025 20:51
π 0
π 0
π¬ 0
π 0
#homeoffice
14.02.2025 07:46
π 0
π 0
π¬ 0
π 0
Vulnerability in Billion Electric Router - Use of Hard-coded Credentials. vulnerability.circl.lu/vuln/CVE-202... CVE-2025-1143 ; routers typically used in an industrial environment. #cve #ics
11.02.2025 08:30
π 0
π 0
π¬ 0
π 0
A clever technique to fool detection analysts: path masquerading to disguising malware as legit system files in SIEM logs. Unicode tricks make C:\Program Files\Windows Defender look real, hiding payloads in plain sight. www.zerosalarium.com/2025/01/path... #siem #soc #monitoring
10.02.2025 07:14
π 0
π 1
π¬ 0
π 0
Agencies now released guidance on digital forensics & monitoring for edge devices to boost threat detection & incident response. www.ncsc.gov.uk/guidance/gui... #initialaccess #ir
06.02.2025 06:56
π 1
π 0
π¬ 0
π 0
If youβre using @letsencrypt.bsky.social certificates it becomes time to setup a certificate expiration monitor (if you havenβt done already).
04.02.2025 10:28
π 0
π 0
π¬ 0
π 0
"Tear Down The Castle", great writeups @malmoeb.bsky.social on common configuration issues in Active Directory. #pingcastle #lowhangingfruit dfir.ch/posts/tear_d... dfir.ch/posts/tear_d...
31.01.2025 19:49
π 0
π 0
π¬ 0
π 0
Well done to all at @europol-eu.bsky.social and other law enforcement agencies involved in this operation. Two online forums allegedly providing a range of cybercriminal services were taken offline resulting in 2 suspects arrested so far.
www.europol.europa.eu/media-press/...
#cybercrime
30.01.2025 13:35
π 4
π 2
π¬ 0
π 0
Ransomware actors further embracing alternative distribution mechanisms, including botnets. In this case LockBit3 uses Phorpiex botnet. By Cybereason www.cybereason.com/blog/threat-... ; IOCs also available via @mispproject.bsky.social botvrij feed www.botvrij.eu/data/feed-os... #Ransomware #cti
29.01.2025 06:59
π 1
π 0
π¬ 0
π 0
PlushDaemon compromises supply chain of Korean VPN service (IPany) by @esetresearch.bsky.social www.welivesecurity.com/en/eset-rese... #CTI
27.01.2025 06:54
π 0
π 0
π¬ 0
π 0
We are sharing backdoored Ivanti Connect Secure devices that *may* have been compromised as part of a CVE-2025-0282 exploitation campaign (but also we believe may include older or other activity).
379 new backdoored instances found on 2025-01-22:
dashboard.shadowserver.org/statistics/c...
23.01.2025 20:07
π 8
π 4
π¬ 1
π 0
Need to analyse Windows DNS server logs? Extract hostnames & domains from the DNS server analytical logs, save them to CSVs, and check against @mispproject.bsky.social , all without centralised DNS logging. A quick win for investigations! github.com/cudeso/tools... #cti #automation #itsalwaysdns
23.01.2025 11:21
π 1
π 1
π¬ 0
π 0
A quick parser to extract whois and country data from the darkweb forum post listing #Fortinet devices victim (?) to CVE-2022-40684.
Parser at github .com/cudeso/tools/blob/master/CVE-2022-40684/README.md
Affected (?) IPs at github.com/arsolutioner...
16.01.2025 15:54
π 0
π 0
π¬ 0
π 0
Spot-on article by @theregister.com El Reg: βAfter Chinaβs Salt Typhoon, the reconstruction starts now.β www.theregister.com/2025/01/06/o...
06.01.2025 16:22
π 1
π 0
π¬ 0
π 0
Examples of threat actor names to use and to avoid
MISP has introduced a new Threat Actor Naming Standard
www.misp-standard.org/blog/Naming-...
02.01.2025 15:18
π 18
π 10
π¬ 1
π 3
Interesting talk by @pylos.co at @firstdotorg.bsky.social CTI "The Disclosure Dilemma and Ensuring Defense" www.youtube.com/watch?v=Cuhs... A nuanced topic with no one-size-fits-all answer. Requires rethinking per case, considering context, nuances and conditions of available options #CTI #sharing
02.01.2025 14:00
π 2
π 0
π¬ 0
π 0
Automating Cyber Threat Intelligence: A Practical Approach to Managing Emerging Vulnerabilities
YouTube video by FIRST
Watched @datadoghq.bsky.social talk at @firstdotorg.bsky.social CTI on "Automating Cyber Threat Intelligence" www.youtube.com/watch?v=t8M3... Great tips on streamlining vulnerability classification, gather abuse data, and report it to customers. Also check HASH github.com/datadog/HASH #cti
02.01.2025 11:30
π 2
π 1
π¬ 0
π 0
Vulnerability Coordination in the EU
YouTube video by FIRST
Presentation by ENISA on "Vulnerability Coordination in the EU" during the @firstdotorg.bsky.social VulnCon www.youtube.com/watch?v=MY0W... #CVD #CVE #responsibledisclosure #vulnerability
02.01.2025 10:29
π 0
π 0
π¬ 0
π 0
MISP Tip of the Week
A collection of tips for using MISP.
Itβs been a while since I posted a new @mispproject.bsky.social tip, but in the meantime you can now also enjoy the tips via a simple HTML page at cudeso.github.io/misp-tip-of-...
11.12.2024 18:25
π 0
π 0
π¬ 0
π 0
Report from RecordedFuture : BlueAlpha leverages Cloudflare Tunneling as staging infrastructure for GammaDrop. Monitor activity tied to trycloudflare[.]com. go.recordedfuture.com/hubfs/report... Indicators also shared via www.botvrij.eu/data/feed-os...
08.12.2024 13:29
π 1
π 0
π¬ 0
π 0
The NCA reports on βOperation Destabilise', exposes and disrupts a Russian money laundering network. MO consists of, ao., collecting funds in one country and make the equivalent value available in another, often by swapping cryptocurrency for cash.
www.nationalcrimeagency.gov.uk/news/operati...
06.12.2024 21:42
π 0
π 0
π¬ 0
π 0
Reviewing 2022 KA SAT incident & implications for distributed communication environments -Joe Slowik
YouTube video by Virus Bulletin
Remember the wiper attack against KA-SAT/Viasat during Russia's invasion of Ukraine? Joe (@pylos.co) provides a great overview of this campaign. The talk also covers alignment with #Sandworm, a little-known DHCP DoS attack and risks with satellite comms for ICS/SCADA.
youtu.be/0a-qza6YSZA
04.12.2024 09:51
π 4
π 4
π¬ 0
π 0
MISP playbooks
MISP Playbooks
You can now browse the @mispproject.bsky.social playbooks on GitHub Pages: misp.github.io/misp-playboo... . The playbooks are automatically converted into easy-to-navigate HTML pages. Dive in and explore!
03.12.2024 13:34
π 2
π 2
π¬ 0
π 0
"Seeing Through a GLASSBRIDGE: Understanding the Digital Marketing Ecosystem Spreading Pro-PRC Influence Operations." Interesting discoveries by TAG on PRC influence behaviour, similar to Russian and Iranian actors. cloud.google.com/blog/topics/... #IO #inauthenticcontent
01.12.2024 16:32
π 0
π 0
π¬ 0
π 0