Here is an overview of content I published in October:
Blog posts:
- New Tool: onion-connect-service-detection.py
- Update: 1768.py Version 0.0.8
- “Public” Private Cobalt Strike Keys
- New Tool: cs-decrypt-metadata.py
YouTube videos:
- CVE-2021-40444 Maldocs: Extracting URLs
- Cobalt Strike: Decrypting C2 Traffic With A “Leaked” Private Key
- Phishing ZIP With Malformed Filename
Videoblog posts:
- Strings Analysis: VBA & Excel4 Maldoc
- CVE-2021-40444 Maldocs: Extracting URLs
- Cobalt Strike: Decrypting C2 Traffic With A ?Leaked? Private Key
- Phishing ZIP With Malformed Filename
SANS ISC Diary entries:
- Video: CVE-2021-40444 Maldocs: Extracting URLs
- Wireshark 3.4.9 Released
- YARA Release v4.1.3
- Reader Malware: ZIP/HTML Phish
- Phishing ZIP With Malformed Filename
- Decrypting Cobalt Strike Traffic With a “Leaked” Private Key
- Sysinternals: Autoruns and Sysmon updates
- Video: Phishing ZIP With Malformed Filename
NVISO blog posts: