Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Security

Mastering Cyber Security The Sun Tzu Approach

Progress your cyber security career with our masterclass from James Rees, MD of Razorthorn Security. In part 1, we take a deep dive into one of the oldest and most highly regarded texts in history - Sun Tzu's "The Art of War" - to uncover valuable insights for information security professionals. We can't stress enough just how useful this text is for anyone in the field, and if you haven't had the opportunity to read it before, we highly recommend doing so.

New Sliver C2 Detection Released - Redteam detected

We are excited to announce the release of a new detection package “Sliver”, which identifies and raises alerts related to the Sliver C2 framework. This new package joins our industrial-strength C2 Collection and uses a variety of techniques to detect Sliver, above and beyond our HTTP-C2 package’s existing Sliver coverage. In this blog we provide some basics about Sliver and how it works and then dive deep into the techniques we use to detect this popular and powerful tool.

Fine-tuning Cloud SIEM detections through machine learning

Security engineering teams spend hours every week tuning their security information and event management (SIEM) systems to ensure that they are effective at detecting security threats and minimizing false positives. Such “tuning tax” is common as customers add new SIEM rules to cope with rapidly changing threat landscape and attacker tactics and as their attack surface evolves through automated changes to their application and infrastructure stacks.

Fantastic Rootkits and Where to Find Them (Part 2)

In the previous post (Part 1), we covered several rootkit technique implementations. Now we will focus on kernel rootkit analysis, looking at two case studies of rootkits found in the wild: Husky Rootkit and Mingloa/CopperStealer Rootkit.Through these case studies, we’ll share our insights about rootkit analysis techniques and methodology.

Industrial control systems security with Elastic Security and Zeek

Industrial control systems (ICS) have historically been isolated and less interconnected. Isolation was one of the things that kept these systems more secure behind air gaps, at the cost of lost coordination and collaboration. This is rapidly changing with the rise of Industry 4.0 with increased interconnectivity and integration of smart technologies like Industrial IoT (IIoT) and cloud computing in modern industrial processes.

Patch now! The Mirai IoT botnet is exploiting TP-Link routers

Businesses should patch their TP-Link routers as soon as possible, after the revelation that a legendary IoT botnet is targeting them for recruitment. The notorious Mirai botnet, which hijacks control of vulnerable IoT devices, is now exploiting TP-Link Archer AX21 routers to launch distributed denial-of-service (DDoS) attacks.

Berlin Q&A with Porsche Motorspot Head of IT Tag Heuer Porsche Formula E Team

Decision making during an E-Prix is influenced by the ability to analyze data efficiently at speed. Did you know the TAG Heuer Porsche Formula E Team use multiple channels on a private network to make crucial real-time judgement calls? Watch Friedemann Kurz, Head of IT at Porsche Motorsport, to find out more.

The Tag Heuer Porsche Formula E Team uses a private network at an E-Prix. Here's why:

When it comes to IT architecture, the set-up is the same for the TAG Heuer Porsche Formula E Team, making it easier to identify bottlenecks or malware threats. Thomas Eue, Lead IT Product Manager at Porsche Motorsport, explains why the Team doesn’t connect to public networks at race weekends.