Elastic Flattened Fields Explained Threats Elastic has many “Field Types”. Flattened is a type that… rooter November 25, 2024 1 min read 0
Splunk: How to Make Lookup Based on Wildcards Threats 1) Add to transforms.conf stanza: [field_from_sourcetype] batch_index_query = 0 case_sensitive_match… rooter November 25, 2024 1 min read 0
Splunk: How to Output Nested json as One Field Threats Often, especially when providing context to analysts who are responsible… rooter November 25, 2024 1 min read 0
BlackSuit Ransomware Detection: Ignoble Scorpius Escalates Attacks, Targets 90+ Organizations Worldwide Threats Emerging last year as the successor to Royal ransomware, BlackSuit… rooter November 25, 2024 4 min read 0
BianLian Ransomware Detection: AA23-136A Joint Cybersecurity Advisory Details on TTPs Leveraged by BianLian Operators in the Ongoing Malicious Campaigns Threats Following a wave of cyber attacks by the Iran-linked hacking… rooter November 22, 2024 5 min read 0
Fickle Stealer Malware Detection: New Rust-Based Stealer Disguises as Legitimate Software to Steal Data from Compromised Devices Threats A new Rust-based stealer malware dubbed Fickle Stealer has come… rooter November 21, 2024 3 min read 0
PXA Stealer Detection: Vietnamese Hackers Hit the Public and Education Sectors in Europe and Asia Threats Hot on the heels of the recent wave of cyber-attacks… rooter November 18, 2024 5 min read 0
New Remcos RAT Activity Detection: Phishing Campaign Spreading a Novel Fileless Malware Variant Threats Cybersecurity researchers have identified an ongoing in-the-wild adversary campaign, which… rooter November 15, 2024 4 min read 0
Interlock Ransomware Detection: High-Profile and Double-Extortion Attacks Using a New Ransomware Variant Threats Adversaries employ new Interlock ransomware in recently observed big-game hunting… rooter November 12, 2024 4 min read 0
SOC Prime Threat Bounty Digest — October 2024 Results Threats Threat Bounty Rules Releases Welcome to the October results edition… rooter November 12, 2024 4 min read 0