Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: Diaries by Keyword Diaries by Keyword

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

OLE FILE

2015-07-12Didier StevensJump List Files Are OLE Files

OLE

2020-12-06/a>Didier Stevensoledump's Indicators (video)
2020-11-15/a>Didier Stevensoledump's ! Indicator
2020-11-08/a>Didier StevensQuick Tip: Extracting all VBA Code from a Maldoc
2020-10-12/a>Didier StevensNested .MSGs: Turtles All The Way Down
2020-10-11/a>Didier StevensAnalyzing MSG Files With plugin_msg_summary
2020-09-18/a>Xavier MertensA Mix of Python & VBA in a Malicious Word Document
2019-12-29/a>Guy BruneauELK Dashboard for Pihole Logs
2019-12-23/a>Didier StevensNew oledump.py plugin: plugin_version_vba
2019-12-07/a>Guy BruneauIntegrating Pi-hole Logs in ELK with Logstash
2019-11-25/a>Xavier MertensMy Little DoH Setup
2019-05-10/a>Xavier MertensDSSuite - A Docker Container with Didier's Tools
2019-02-26/a>Russ McReeAd Blocking With Pi Hole
2018-08-19/a>Didier StevensVideo: Peeking into msg files - revisited
2018-08-11/a>Didier StevensPeeking into msg files - revisited
2018-02-19/a>Didier StevensAnalyzing MSI files
2016-06-12/a>Guy BruneauDNS Sinkhole ISO Version 2.0
2016-03-07/a>Xavier MertensAnother Malicious Document, Another Way to Deliver Malicious Code
2015-07-12/a>Didier StevensJump List Files Are OLE Files
2015-07-04/a>Didier StevensA .BUP File Is An OLE File
2015-05-15/a>Didier StevensAnother Maldoc? I'm Afraid So...
2015-05-09/a>Didier StevensMalicious Word Document: This Time The Maldoc Is A MIME File
2015-02-20/a>Tom WebbFast analysis of a Tax Scam
2015-02-19/a>Daniel WesemannMacros? Really?!
2013-11-18/a>Johannes UllrichAm I Sending Traffic to a "Sinkhole"?
2013-05-04/a>Kevin ShorttThe Zero-Day Pendulum Swings
2012-11-16/a>Guy BruneauVMware security updates for vSphere API and ESX Service Console - http://www.vmware.com/security/advisories/VMSA-2012-0016.html
2012-01-21/a>Guy BruneauDNS Sinkhole Scripts Fixes/Update
2011-10-15/a>Guy BruneauDNS Sinkhole Parser Script Update
2011-09-09/a>Guy BruneauIPv6 and DNS Sinkhole
2010-10-28/a>Tony CarothersCyber Security Awareness Month - Day 28 - Role of the employee
2010-06-19/a>Guy BruneauDNS Sinkhole ISO Available for Download
2010-01-10/a>Guy BruneauEasy DNS BIND Sinkhole Setup

FILE

2021-05-02/a>Didier StevensPuTTY And FileZilla Use The Same Fingerprint Registry Keys
2021-04-10/a>Guy BruneauBuilding an IDS Sensor with Suricata & Zeek with Logs to ELK
2021-03-12/a>Guy BruneauMicrosoft DHCP Logs Shipped to ELK
2021-02-12/a>Xavier MertensAgentTesla Dropped Through Automatic Click in Microsoft Help File
2020-06-12/a>Xavier MertensMalicious Excel Delivering Fileless Payload
2020-05-22/a>Didier StevensSome Strings to Remember
2020-05-04/a>Didier StevensSysmon and File Deletion
2020-03-21/a>Guy BruneauHoneypot - Scanning and Targeting Devices & Services
2019-10-03/a>Xavier Mertens"Lost_Files" Ransomware
2019-08-04/a>Didier Stevens Detecting ZLIB Compression
2019-02-19/a>Didier StevensIdentifying Files: Failure Happens
2018-11-05/a>Johannes UllrichStruts 2.3 Vulnerable to Two Year old File Upload Flaw
2017-11-29/a>Xavier MertensFileless Malicious PowerShell Sample
2017-10-30/a>Didier StevensPE files and debug info
2017-10-24/a>Xavier MertensStop relying on file extensions
2017-07-19/a>Xavier MertensBots Searching for Keys & Config Files
2017-07-02/a>Didier StevensPE Section Name Descriptions
2017-05-26/a>Lorna HutchesonFile2pcap - A new tool for your toolkit!
2016-08-24/a>Xavier MertensExample of Targeted Attack Through a Proxy PAC File
2016-05-21/a>Didier StevensPython Malware - Part 2
2016-03-30/a>Xavier MertensWhat to watch with your FIM?
2016-01-20/a>Xavier Mertens/tmp, %TEMP%, ~/Desktop, T:\, ... A goldmine for pentesters!
2015-07-12/a>Didier StevensJump List Files Are OLE Files
2014-03-17/a>Johannes UllrichScans for FCKEditor File Manager
2014-02-28/a>Daniel WesemannOversharing
2014-01-11/a>Guy Bruneautcpflow 1.4.4 and some of its most Interesting Features
2013-08-26/a>Alex StanfordStop, Drop and File Carve
2013-08-21/a>Alex StanfordPsst. Your Browser Knows All Your Secrets.
2011-11-28/a>Tom ListonA Puzzlement...
2011-08-15/a>Mark HofmanHow to find unwanted files on workstations
2009-12-28/a>Johannes Ullrich8 Basic Rules to Implement Secure File Uploads http://jbu.me/48 (inspired by IIS ; bug)
2009-08-13/a>Jim ClausingTools for extracting files from pcaps
2009-06-27/a>Tony CarothersNew NIAP Strategy on the Horizon
2009-05-27/a>donald smithHost file black lists
2009-05-25/a>Jim ClausingMore tools for (US) Memorial Day
2008-03-13/a>Jason LamRemote File Include spoof!?