2024-12-23 | Xavier Mertens | Modiloader From Obfuscated Batch File |
2024-03-06 | Bojan Zdrnja | Scanning and abusing the QUIC protocol |
2023-06-29 | Brad Duncan | GuLoader- or DBatLoader/ModiLoader-style infection for Remcos RAT |
2023-06-19 | Xavier Mertens | Malware Delivered Through .inf File |
2023-05-30 | Brad Duncan | Malspam pushes ModiLoader (DBatLoader) infection for Remcos RAT |
2022-06-03 | Xavier Mertens | Sandbox Evasion... With Just a Filename! |
2022-03-18 | Johannes Ullrich | Scans for Movable Type Vulnerability (CVE-2021-20837) |
2022-03-12 | Didier Stevens | ICMP Messages: Original Datagram Field |
2021-05-30 | Didier Stevens | Sysinternals: Procmon, Sysmon, TcpView and Process Explorer update |
2021-04-25 | Didier Stevens | Sysinternals: Procmon and Sysmon update |
2021-04-16 | Xavier Mertens | HTTPS Support for All Internal Services |
2020-04-30 | Xavier Mertens | Collecting IOCs from IMAP Folder |
2020-03-03 | Johannes Ullrich | Introduction to EvtxEcmd (Evtx Explorer) |
2019-04-04 | Xavier Mertens | New Waves of Scans Detected by an Old Rule |
2019-01-02 | Xavier Mertens | Malicious Script Leaking Data via FTP |
2018-05-10 | Bojan Zdrnja | Exfiltrating data from (very) isolated environments |
2016-04-15 | Xavier Mertens | Windows Command Line Persistence? |
2014-04-27 | Tony Carothers | The Dreaded "D" Word of IT |
2014-04-01 | Johannes Ullrich | cmd.so Synology Scanner Also Found on Routers |
2014-02-04 | Johannes Ullrich | Odd ICMP Echo Request Payload |
2013-10-04 | Pedro Bueno | CSAM: WebHosting BruteForce logs |
2013-09-19 | Bojan Zdrnja | Arrays in requests, PHP and DedeCMS |
2013-03-08 | Johannes Ullrich | IPv6 Focus Month: Filtering ICMPv6 at the Border |
2011-11-10 | Rob VandenBrink | Stuff I Learned Scripting - - Parsing XML in a One-Liner |