Tag: SANS Internet Storm Center, InfoCON: green

[Guest Diary] Comparing Honeypot Passwords with HIBP, (Wed, Oct 1st)

[This is a Guest Diary by Draden Barwick, an ISC intern as part of the SANS.edu Bachelor's Degree in Applied Cybersecurity (BACS) program [1].] This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article:…

New tool: convert-ts-bash-history.py, (Fri, Sep 26th)

In SANS FOR577[1], we talk about timelines on day 5, both filesystem and super-timelines. but sometimes, I want something quick and dirty and rather than fire up plaso, just to create a timeline of .bash_history data, it is nice to…

Webshells Hiding in .well-known Places, (Thu, Sep 25th)

Ever so often, I see requests for files in .well-known recorded by our honeypots. As an example: This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: Webshells Hiding in .well-known Places, (Thu, Sep…