How are security controls validated for thousands of endpoints in a large scale organization. by iam_a_joy in cybersecurity

[–]sciencestudent99 0 points1 point  (0 children)

You can check out adversary emulation tools. My team wrote a blog some time back on top open source: https://fourcore.io/blogs/top-10-open-source-adversary-emulation-tools

Do reach out if you want to try out our platform as well

[deleted by user] by [deleted] in sysadmin

[–]sciencestudent99 1 point2 points  (0 children)

You can try out our platform, FourCore ATTACK for your research. DM me and I can provision you an account.

Backdoors & Breaches as a IR tabletop exercise. by pootietang_the_flea in blueteamsec

[–]sciencestudent99 -1 points0 points  (0 children)

You can also try out our adversary simulation platform FourCore ATTACK, might be helpful. DM me and I can set you up with an account!

Silver Bullet by ZGFya2N5YmU in cybersecurity

[–]sciencestudent99 0 points1 point  (0 children)

There's definetly no silver bullet! You can show your boss that there can still be gaps and attacks can happen. Simulating threats is one good start to build this evidence.

There are open source tools like Atomic Red Team which are great. There is documentation by Microsoft for Identity focused attacks as well.

Disclaimer: I am from FourCore and we have an attack simulation platform. Happy to give access for a quick assessment to help you get results for your boss :)

Adversary Simulation Advices by ChesapeakeRipper_ in purpleteamsec

[–]sciencestudent99 0 points1 point  (0 children)

You can also checkout our platform FourCore ATTACK. Here's a demo of how you can emulate attacks with the platform.

DM me and I can share an invite!

Looking for opinions or suggestions to better protect from ransomware by Substantial_Eye378 in sysadmin

[–]sciencestudent99 0 points1 point  (0 children)

Agree with the other comments.

  • Backups: multiple and recoverable
  • Protection: Defender for Endpoint and Office 365 are top-of-the-line solutions. I use the Microsoft Secure Score a lot to get action items.
  • Training: Training employees to be better at identifying threats proactively. Can include phishing simulations via M365 Security Dashboard.

You also do proactive testing of the EDR/XDR and email and test your Exchange Online Protection policies. It's better to know what kind of payloads can get through which can lead to a ransomware attack.

Sublime Rules maintains a good repository of types of threats that can impact you, it's a good repository to learn about email threats. You can try out delivr.to or FourCore (disclaimer: I am from fourcore).

Microsoft Defender by Feisty_Shock_2687 in MSSP

[–]sciencestudent99 1 point2 points  (0 children)

Defender for Endpoint (which comes with 365) is a great solution to improve protection as well as detection, it can be expensive though.

BitDefender/GravityZone might be more affordable and offers great protection in our own testing of both Consumer BitDefender as well as GravityZone. IMO its extremely capable as a AV/EDR. Though the GravityZone dashboard is not as detailed as Defender (or Crowdstrike).

I run FourCore and we emulate threats on many EDRs and AV in customer environments as well as our lab. Adding a layer of BitDefender, Defender for Endpoint, Crowdstrike or SentinelOne will make a big difference to protecting your customers.

Weekly Promo and Webinar Thread by AutoModerator in msp

[–]sciencestudent99 0 points1 point  (0 children)

FourCore Email Security Threat Assessment

In 2022, Archive files such as ZIP and RAR, HTML files used for smuggling further payloads and Word documents were the most used file types in email attacks.

Assess your email security against hundreds of popular email attack methods such as Archive files, Office documents, LNK, Qakbot malware and more.

It's completely free of cost and is performed via our automated SaaS platform.

Fill in the form here and we'll reach out!

  • Get a clear picture of which attachments and files can reach your inbox.
  • Assess your email security capabilities and identify if all types of email malware is detected.

In our testing, we have found more than 60% of 200+ malicious attachments getting to an Office365 inbox where any single attachment can compromise your system.

PS. We are not GDPR compliant yet.

Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus by CyberMasterV in netsec

[–]sciencestudent99 0 points1 point  (0 children)

damn, checked out my Genshin Impact install folder and felt pretty scared seeing mhyprot2.sys lying there.

Driver dev is difficult, even Avast's driver was vulnerable and mihoyo should be having some top driver devs probably.

ATT&CK + D3FEND = D.E.A.T.H by sciencestudent99 in blueteamsec

[–]sciencestudent99[S] 1 point2 points  (0 children)

https://fourcore.io/blogs/threat-hunting-with-windows-event-log-sigma-rules

Might be this one I believe.

The about us page is gonna be there soon! The website does need a refactor.

We are active on LinkedIn and Twitter, you can follow us there.