mthcht

@mthcht.bsky.social

Threat Hunting - DFIR - Detection Engineering 🐙 https://github.com/mthcht 🐦 https://x.com/mthcht 📰 https://mthcht.medium.com

Launching oauthsentry.github.io Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub). Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit 🦾

OAuthSentry - OAuth application intelligence for defenders

Search OAuth Application IDs across Microsoft Entra, Google Workspace and more. Three classification feeds for defenders: compliance, risky, and malicious. Includes investigation playbooks, forensic t...

oauthsentry.github.io

Adding VSXSentry-Guard A VS Code extension that automatically blocks and removes malicious extensions from the VSXSentry feed. No enterprise policy management needed - one click and you're protected. marketplace.visualstudio.com/items?itemNa...

mthcht@mthcht.bsky.social · 4mo ago

💠 VSXSentry 💠 vsxsentry.github.io VS Code Extensions threat intel feeds for multiple platforms, VSIX analyzer, scripts & policy generator, remediation and forensic traces guide

Launching oauthsentry.github.io Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub). Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit 🦾

OAuthSentry - OAuth application intelligence for defenders

Search OAuth Application IDs across Microsoft Entra, Google Workspace and more. Three classification feeds for defenders: compliance, risky, and malicious. Includes investigation playbooks, forensic t...

oauthsentry.github.io

Nehboro, a browser extension blocking phishing attempts on page load nehboro.github.io ⚡️ Dedicated IOCs feed - Blocking BAD AS IP ranges, domains & reported urls 📊 97 heuristic detections for all kind of scams 🤖 AI Analysis on demand hopefully in the webstore soon

Nehboro - Community Threat Intelligence

Community-powered browser extension with 97 dynamic detections, static IOC feeds, and optional Claude AI analysis. Protection against phishing, ClickFix, and malware.

nehboro.github.io

🧩 ExtSentry 🧩 extsentry.github.io Browser Extensions threat intel feeds for multiple platforms + extension checker, permissions analyzer, policy generator, forensic traces guide, remediation playbook & endpoint inventory scripts github.com/ExtSentry/Ex...

GitHub - ExtSentry/ExtSentry.github.io: Browser Extension Threat Intelligence feed - extsentry.github.io

Browser Extension Threat Intelligence feed - extsentry.github.io - ExtSentry/ExtSentry.github.io

github.com

If you want to experiment with the Splunk MCP Server splunkbase.splunk.com/app/7931, I just published a client to interact with it: github.com/mthcht/Splun... it cost around 5 cents per splunk query, an automated case investigation cost an average of 50 cents depending on the complexity.

GitHub - mthcht/Splunk-MCP-Client: Query Splunk in natural language using Claude AI and the Splunk MCP Server.

Query Splunk in natural language using Claude AI and the Splunk MCP Server. - mthcht/Splunk-MCP-Client

github.com

It took just 3 hours: RCE → Metasploit C2 → Anydesk for remote GUI-access → LockBit ransomware Interestingly, we observed the threat actor using PDQ Deploy, a patch management tool. Read the report here:

Confluence Exploit Leads to LockBit Ransomware

Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.…

thedfirreport.com

In case you don't want to do this yourself, I just discovered that you can request access to a complete list of all existing domains across 1131 TLDs on czds.icann.org for free, including NS records! The lists are updated every month, approval is required for each TLD 🌍

mthcht@mthcht.bsky.social · last yr.

I have a list of NS used for sinkhole domains and seized servers: raw.githubusercontent.com/mthcht/awesome… I'm searching for the domains, on my server I can resolve a record type for ~400 million domains per day with github.com/blechschmidt/m��� 😃 Massive improvement compared to other solutions!

Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time www.splunk.com/en_us/blog/s.... Thrilled to share my first blog at @splunk! @mhaggis.bsky.social and I take a deep dive into the weird & exciting world of SDDL and ACEs - what they are, how they work, and how attackers can abuse them.

Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time | Splunk

Explore SDDL in Windows security with our comprehensive guide to help enhance your defensive strategy against privilege escalation attacks.

splunk.com

Most SOCs handle hundreds to thousands of detection rules in their SIEM. Proper categorization is essential when creating a new detection, as it helps define criticality, urgency, implementation effort, and verbosity level. Keeping things structured will reducing alert fatigue!

BildBild