/explore

Click through on any links that interest you or select the planets on the right to continue exploring the Outer Web.
You are here

0xcybery.github.io
| | cocomelonc.github.io
1.2 parsecs away

Travel
| |
| | forensicitguy.github.io
1.1 parsecs away

Travel
| | In this post I want to take a look at a PowerShell-based Cobalt Strike beacon that appeared on MalwareBazaar. This particular beacon is representative of most PowerShell Cobalt Strike activity I see in the wild during my day job. The beacons often show up as service persistence during incidents or during other post-exploitation activity. If you want to follow along at home, the sample I'm using is here:
| | cocomelonc.github.io
2.1 parsecs away

Travel
| |
| | blog.eclecticiq.com
19.3 parsecs away

Travel
| Sandworm APT targets Ukrainian users with Trojanized Microsoft KMS tools for cyber espionage, leveraging pirated software to exfiltrate sensitive data and compromise critical infrastructure.