By now, everyone should have seen that FireEye got breached and their red team tools got stolen. What is truly unique about their response is publishing detection rules&#;x26;#;xc2;&#;x26;#;xa0;to detect the use of those tools in the wild. However, the nature of some of those rules is that the detection will be short-lived. This isn&#;x26;#;39;t necessarily a fault of FireEye (as I will explain below) but it is useful as an exercise in writing Yara rules (or Snort, HXIOC, STIX, et al).
Ähnliche Beiträge
Auch interessante Nachrichten Writing Yara Rules for Fun and Profit: Notes from the FireEye Breach Countermeasures, (Thu, Dec 10th)
Thematisch verwandte Begriffe: Writing, Yara, Rules, Profit · 6 Treffer
Stopping Vulnerable Driver Attacks
OpenAI Confirms AI Agents Wrote to Multiple Internet Sites in ‘Wiki Incident’
REVSTEALER ramps up: analysis of up-and-coming infostealer
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
SOCIAL SHARE CARD GENERATOR