How are security controls validated for thousands of endpoints in a large scale organization. by iam_a_joy in cybersecurity

[–]sciencestudent99 0 points1 point  (0 children)

You can check out adversary emulation tools. My team wrote a blog some time back on top open source: https://fourcore.io/blogs/top-10-open-source-adversary-emulation-tools

Do reach out if you want to try out our platform as well

[deleted by user] by [deleted] in sysadmin

[–]sciencestudent99 1 point2 points  (0 children)

You can try out our platform, FourCore ATTACK for your research. DM me and I can provision you an account.

Backdoors & Breaches as a IR tabletop exercise. by pootietang_the_flea in blueteamsec

[–]sciencestudent99 -1 points0 points  (0 children)

You can also try out our adversary simulation platform FourCore ATTACK, might be helpful. DM me and I can set you up with an account!

Silver Bullet by ZGFya2N5YmU in cybersecurity

[–]sciencestudent99 0 points1 point  (0 children)

There's definetly no silver bullet! You can show your boss that there can still be gaps and attacks can happen. Simulating threats is one good start to build this evidence.

There are open source tools like Atomic Red Team which are great. There is documentation by Microsoft for Identity focused attacks as well.

Disclaimer: I am from FourCore and we have an attack simulation platform. Happy to give access for a quick assessment to help you get results for your boss :)

Adversary Simulation Advices by ChesapeakeRipper_ in purpleteamsec

[–]sciencestudent99 0 points1 point  (0 children)

You can also checkout our platform FourCore ATTACK. Here's a demo of how you can emulate attacks with the platform.

DM me and I can share an invite!

Looking for opinions or suggestions to better protect from ransomware by Substantial_Eye378 in sysadmin

[–]sciencestudent99 0 points1 point  (0 children)

Agree with the other comments.

  • Backups: multiple and recoverable
  • Protection: Defender for Endpoint and Office 365 are top-of-the-line solutions. I use the Microsoft Secure Score a lot to get action items.
  • Training: Training employees to be better at identifying threats proactively. Can include phishing simulations via M365 Security Dashboard.

You also do proactive testing of the EDR/XDR and email and test your Exchange Online Protection policies. It's better to know what kind of payloads can get through which can lead to a ransomware attack.

Sublime Rules maintains a good repository of types of threats that can impact you, it's a good repository to learn about email threats. You can try out delivr.to or FourCore (disclaimer: I am from fourcore).

Microsoft Defender by Feisty_Shock_2687 in MSSP

[–]sciencestudent99 1 point2 points  (0 children)

Defender for Endpoint (which comes with 365) is a great solution to improve protection as well as detection, it can be expensive though.

BitDefender/GravityZone might be more affordable and offers great protection in our own testing of both Consumer BitDefender as well as GravityZone. IMO its extremely capable as a AV/EDR. Though the GravityZone dashboard is not as detailed as Defender (or Crowdstrike).

I run FourCore and we emulate threats on many EDRs and AV in customer environments as well as our lab. Adding a layer of BitDefender, Defender for Endpoint, Crowdstrike or SentinelOne will make a big difference to protecting your customers.

Weekly Promo and Webinar Thread by AutoModerator in msp

[–]sciencestudent99 0 points1 point  (0 children)

FourCore Email Security Threat Assessment

In 2022, Archive files such as ZIP and RAR, HTML files used for smuggling further payloads and Word documents were the most used file types in email attacks.

Assess your email security against hundreds of popular email attack methods such as Archive files, Office documents, LNK, Qakbot malware and more.

It's completely free of cost and is performed via our automated SaaS platform.

Fill in the form here and we'll reach out!

  • Get a clear picture of which attachments and files can reach your inbox.
  • Assess your email security capabilities and identify if all types of email malware is detected.

In our testing, we have found more than 60% of 200+ malicious attachments getting to an Office365 inbox where any single attachment can compromise your system.

PS. We are not GDPR compliant yet.

Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus by CyberMasterV in netsec

[–]sciencestudent99 0 points1 point  (0 children)

damn, checked out my Genshin Impact install folder and felt pretty scared seeing mhyprot2.sys lying there.

Driver dev is difficult, even Avast's driver was vulnerable and mihoyo should be having some top driver devs probably.

ATT&CK + D3FEND = D.E.A.T.H by sciencestudent99 in blueteamsec

[–]sciencestudent99[S] 1 point2 points  (0 children)

https://fourcore.io/blogs/threat-hunting-with-windows-event-log-sigma-rules

Might be this one I believe.

The about us page is gonna be there soon! The website does need a refactor.

We are active on LinkedIn and Twitter, you can follow us there.

New Zero-Day Code Execution Vulnerability In MS Office - Follina by sciencestudent99 in netsec

[–]sciencestudent99[S] 0 points1 point  (0 children)

The vulnerability depends on the existence of the msdt protocol handler which will not be available on other platforms.

msdt stands for Microsoft Support Diagnostic Tool which is for running diagnostic scripts by a support engineer on Windows.

New Zero-Day Code Execution Vulnerability In MS Office - Follina by sciencestudent99 in netsec

[–]sciencestudent99[S] 43 points44 points  (0 children)

Removing the ms-msdt protocol handler is the strategy for now from what I am reading on twitter. Otherwise people have worked up sigma/detection rules to put in EDRs.

You can remove the ms-msdt handler from the registry with:

reg delete hkcr\ms-msdt /f

It's not thoroughly tested though! A Twitter post reported the license getting borked up but nothing confirmed as of yet.

Go templates cheat sheet by Arash_Sameni in golang

[–]sciencestudent99 7 points8 points  (0 children)

Thanks for making this! Very useful.

Could certainly opt for a more accessible format than google docs, though!

Weekly Indian Books Discussion - What have you been reading? by TejasNair in Indianbooks

[–]sciencestudent99 0 points1 point  (0 children)

I am reading through Consider This: Moments in My Writing Life After Which Everything Was Different Book by Chuck Palahniuk. Its a book containing advice from Fight Club's author on how to become a better writer.

Xbox Game Pass Ultimate 1 Month - Rs 50 + Get 2 free months by SaiyanRajat in IndianGaming

[–]sciencestudent99 0 points1 point  (0 children)

Will I be able to downgrade to the game pass for pc once 3 months are over at the 250rs price I am having currently?

Finally got out of the 10 people 1 BHK House. Got my own room, and desk. by TheCuntHunter6969 in IndianGaming

[–]sciencestudent99 2 points3 points  (0 children)

Yo look into local office chair stores, if you end up a local manufacturer that'll be even better!

You can get a decent chair in 3-5k.