Phishing.web.core.windows.net

EvilGinx is a prime example of some of the amazing tools out there that came be used for Phishing. If you haven't heard of it, EvilGinx was release a few years back and showed us a weak point in 2FA. For most back then, MFA was a sure way to thwart the bad guys and it make the system or user account "impenetrable".....

Living Off The Land: Suspicious System32

The services below are some of the most commonly abused services for malicious parties to "live of the land". Each are built into Windows and inherit trust by default. Because of this, security controls won't ever be able to fully isolate them without affecting the operating system. For example, your endpoint protection can't block command prompt and Powershell because engineers use them for automation tasks, nor can it block task scheduler or certuitl.......

Hacking With Powershell: Malware

With malicious parties continuing to use Powershell as their way in, I thought I would look into how it's being used and what can be done to prevent it. This is something I've covered before, so think of this as a part 3............

What’s This About Zoom?

Zoom has helped millions stay in connect during these hard times and you can see why it was the preferred option. Other services such as Webex or Skype are just too clunky and in my opinion, the simplicity of Zoom was........

Windows Defender: Why Check Your Exclusions

Windows Defender is integrated with Windows 10, so it's no wondering it's up there for the most popular Anti-virus solution. Once you login to your new Windows 10 machine, it's pretty much ready to go. The plus side is that Defender is a pretty solid AV and if you look at Gartner, they even rate them as the best......

Fake GOV_UK SMS Fines Being Sent

This morning, several people are reporting that they had received a text message reporting that they had been fined. These are fake as at this moment in time, the above SMS has been the only confirmed SMS message that has been sent out by the Government.....

Obfuscation With PowerShell

Malicious parties might chose to encode their commands or scripts. The reason why is that if your auditing isn't up to scratch, it may go unseen. In some cases it can also help bypass the AV....

Stealing Passwords From Clipboard

Password Managers are brilliant! They allow users to create and use complex passwords because they give us a nice secure place to store them. Using Password managers also can also prevent users from writing them down or reusing passwords, which is a huge deterrent against hackers looking to compromise your accounts. It's a win, win....or... Continue Reading →

Create a website or blog at WordPress.com

Up ↑