Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: Diaries by Keyword Diaries by Keyword

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title
2021-09-11Guy BruneauShipping to Elasticsearch Microsoft DNS Logs
2021-05-02Didier StevensPuTTY And FileZilla Use The Same Fingerprint Registry Keys
2021-04-10Guy BruneauBuilding an IDS Sensor with Suricata & Zeek with Logs to ELK
2021-03-12Guy BruneauMicrosoft DHCP Logs Shipped to ELK
2021-02-12Xavier MertensAgentTesla Dropped Through Automatic Click in Microsoft Help File
2020-06-12Xavier MertensMalicious Excel Delivering Fileless Payload
2020-05-22Didier StevensSome Strings to Remember
2020-05-04Didier StevensSysmon and File Deletion
2020-03-21Guy BruneauHoneypot - Scanning and Targeting Devices & Services
2019-10-03Xavier Mertens"Lost_Files" Ransomware
2019-08-04Didier Stevens Detecting ZLIB Compression
2019-02-19Didier StevensIdentifying Files: Failure Happens
2018-11-05Johannes UllrichStruts 2.3 Vulnerable to Two Year old File Upload Flaw
2017-11-29Xavier MertensFileless Malicious PowerShell Sample
2017-10-30Didier StevensPE files and debug info
2017-10-24Xavier MertensStop relying on file extensions
2017-07-19Xavier MertensBots Searching for Keys & Config Files
2017-07-02Didier StevensPE Section Name Descriptions
2017-05-26Lorna HutchesonFile2pcap - A new tool for your toolkit!
2016-08-24Xavier MertensExample of Targeted Attack Through a Proxy PAC File
2016-05-21Didier StevensPython Malware - Part 2
2016-03-30Xavier MertensWhat to watch with your FIM?
2016-01-20Xavier Mertens/tmp, %TEMP%, ~/Desktop, T:\, ... A goldmine for pentesters!
2015-07-12Didier StevensJump List Files Are OLE Files
2014-03-17Johannes UllrichScans for FCKEditor File Manager
2014-02-28Daniel WesemannOversharing
2014-01-11Guy Bruneautcpflow 1.4.4 and some of its most Interesting Features
2013-08-26Alex StanfordStop, Drop and File Carve
2013-08-21Alex StanfordPsst. Your Browser Knows All Your Secrets.
2011-11-28Tom ListonA Puzzlement...
2011-08-15Mark HofmanHow to find unwanted files on workstations
2009-12-28Johannes Ullrich8 Basic Rules to Implement Secure File Uploads (inspired by IIS ; bug)
2009-08-13Jim ClausingTools for extracting files from pcaps
2009-06-27Tony CarothersNew NIAP Strategy on the Horizon
2009-05-27donald smithHost file black lists
2009-05-25Jim ClausingMore tools for (US) Memorial Day
2008-03-13Jason LamRemote File Include spoof!?