KoifSec

@koifsec.bsky.social

Detection engineer, also writing for https://detect.fyi. Base64 Enjoyer. Clippy is a threat actor.

TL;DR LUMEN is a privacy-first, browser-native EVTX analysis platform that combines WebAssembly parsing, 2,349 SIGMA detection rules, optional AI-powered analysis, and advanced correlation capabilities — all running entirely client-side. Check it out: koifsec.medium.com/introducing-...

Introducing LUMEN: Your EVTX Companion

TL;DR LUMEN is a privacy-first, browser-native EVTX analysis platform that combines WebAssembly parsing, 2,349 SIGMA detection rules…

koifsec.medium.com

Hello everyone! I'm looking for individuals experienced in Powershell and solving CTFs, ideally both, to collaborate on an exciting new CTF initiative for the community. If you believe you have something interesting to contribute, even if you're not experienced, feel free to connect with me.

Bild

𝗦𝗲𝗲𝗶𝗻𝗴 𝘀𝗼𝗺𝗲 𝘀𝗲𝗰𝗿𝗲𝘁𝘀𝗱𝘂𝗺𝗽 𝗮𝗰𝘁𝗶𝘃𝗶𝘁𝘆 𝗶𝗻 𝘁𝗵𝗲 𝘄𝗶𝗹𝗱 𝗹𝗮𝘁𝗲𝗹𝘆, 𝗮𝗻𝗱 𝗶𝘁’𝘀 𝘁𝗿𝗶𝗰𝗸𝘆 𝘁𝗼 𝗰𝗮𝘁𝗰𝗵 𝗯𝗲𝗰𝗮𝘂𝘀𝗲 𝗼𝗳 𝗮𝗹𝗹 𝘁𝗵𝗲 𝗳𝗮𝗹𝘀𝗲 𝗽𝗼𝘀𝗶𝘁𝗶𝘃𝗲𝘀. The recent NetExec update (codename SmoothOperator) pushed me to share this one 👇 🔗 www.netexec.wiki/news/v1.4.0-... 𝗙𝗶𝗿𝘀𝘁 𝗲𝘃𝗲𝗻𝘁 (𝟰𝟲𝟳𝟮) Special privileges assigned to new logon:

𝗥𝗲𝗮𝗱 𝘁𝗵𝗲 𝗳𝘂𝗹𝗹 𝗮𝗿𝘁𝗶𝗰𝗹𝗲: kostas-ts.medium.com/detecting-ab... 𝗦𝗶𝗴𝗺𝗮 𝗣𝗥: github.com/SigmaHQ/sigm... 𝗜'𝗱 𝗹𝗼𝘃𝗲 𝘁𝗼 𝗵𝗲𝗮𝗿 𝘆𝗼𝘂𝗿 𝘁𝗵𝗼𝘂𝗴𝗵𝘁𝘀: • Have you encountered similar permissive trial access in other security platforms? We need to document things before it's too late. Hope you enjoy reading the post!

Detecting Abuse of OpenEDR’s Permissive EDR Trial: A Security Researcher’s Perspective

1. Introduction

kostas-ts.medium.com

1/ In today's BEC (Business E-Mail Compromise) case, I stumbled (again) over the "Set-MailboxJunkEmailConfiguration" operation. I talked about it a while back. [1] The attacker also created a new Inbox rule for moving incoming emails for target personnel to a designated folder.

Bild