Category: DFIR Lab – Binalyze

Enhancing Threat Detection and Analysis during Investigations

In today’s rapidly evolving threat landscape, organizations and MSSPs face growing numbers of cyber adversaries, ranging from sophisticated nation-states to opportunistic cybercriminals. To effectively combat these threats, security professionals require advanced automated tools and methodologies that provide deep insights into attacker tactics and techniques. Binalyze AIR’s automated compromise assessment, DRONE, coupled with the integration of MITRE ATT&CK, represents a powerful arsenal in the cybersecurity armory.

Uncovering the IOCs: Ivanti Connect Secure VPN Exploitation

In the ever-evolving landscape of cybersecurity, the recent exploitation of Ivanti Connect Secure VPN stands out as a stark reminder of the vulnerabilities inherent in even the most trusted security tools. Ivanti Connect Secure, a widely used VPN solution, has been targeted in a sophisticated attack, highlighting the need for constant vigilance and understanding of Indicators of Compromise (IOCs).

Focus investigations with MITRE ATT&CK insights

Last updated: 29th May 2024

 

Integrate automated evidence analysis and mapping into your investigations

Understanding an attacker’s behavior and the tactics, techniques and procedures (TTPs) they use is vitally important to any investigation – it provides critical context that allows for more efficient and effective investigations. This context informs what response actions are appropriate, and improves short, and long-term, response outcomes.  

Offline collection with AIR

The reality of modern incident response is that it’s not always possible to remotely connect with every one of your endpoints. Some assets are required to be standalone and others, such as laptops, some may have become faulty, and others may have been removed as they have been compromised by – or are actively under attack from – the very breach you want to investigate. 

The OneNote malware attack – A retrospective

At Binalyze we’re always actively monitoring for the latest exploits and attack vectors. We’re also in constant conversation with our customers, discussing threats in the wild and sharing best practice. 

In this article, we’re going to discuss the surge in Microsoft OneNote malware attack vectors that started popping up towards the end of January this year, and the potential threat they continue to pose for enterprise security.