πŸ‘οΈ8,960
GitHubLinkedIn
Cybersecurity and Techβ€’β€’9 min readβ€’1776 words

πŸš€ Security - Threat Intelligence

πŸ‘οΈ0reads (human + AI)πŸ€–0AI ingestions
⚑Direct Technical Summary

A Mythic C2 Profile that uses the Microsoft Graph API to communicate through a Microsoft Teams channel The Mythic C2 Profile is a sophisticated threat intelligence tool that lever

πŸš€ Security - Threat Intelligence

A Mythic C2 Profile that uses the Microsoft Graph API to communicate through a Microsoft Teams channel

The Mythic C2 Profile is a sophisticated threat intelligence tool that leverages the Microsoft Graph API to communicate through Microsoft Teams channels. This innovative approach allows for seamless integration with existing Microsoft infrastructure, making it an attractive option for threat actors. The profile's ability to utilize the Microsoft Graph API enables it to bypass traditional security measures, making it a significant concern for security professionals.

Key Points:

  • Microsoft Graph API Integration: The Mythic C2 Profile utilizes the Microsoft Graph API to communicate through Microsoft Teams channels, allowing for seamless integration with existing Microsoft infrastructure.

  • Threat Actor Attraction: The profile's ability to utilize the Microsoft Graph API makes it an attractive option for threat actors, as it allows them to bypass traditional security measures.

  • Security Concerns: The Mythic C2 Profile's integration with Microsoft Teams channels poses significant security concerns, as it can be used to evade detection and compromise sensitive information.

πŸ”— Resources:

  • Original post β†—
  • Original source
  • Microsoft Graph API
  • Brief description: Microsoft Graph API integration for threat intelligence

🚨 Security - Forensic Analysis

My new "field note" shows how a seemingly generic Microsoft Defender alert can lead to a much more useful forensic finding when correlated with filesystem artifacts. Defender detected Behavior:Win32/RegDump.SA, attributed to svchost.exe running as SYSTEM. Looking at the MFT

This field note highlights the importance of correlating Microsoft Defender alerts with filesystem artifacts to uncover more detailed forensic information. By examining the MFT, security professionals can gain a deeper understanding of the threat actor's actions and intentions. The detection of Behavior:Win32/RegDump.SA attributed to svchost.exe running as SYSTEM is a significant finding, as it indicates a potential security breach.

Key Points:

  • Correlating Alerts with Filesystem Artifacts: Correlating Microsoft Defender alerts with filesystem artifacts can lead to more detailed forensic information, providing a deeper understanding of the threat actor's actions and intentions.

  • MFT Examination: Examining the MFT can reveal significant forensic information, including the detection of Behavior:Win32/RegDump.SA attributed to svchost.exe running as SYSTEM.

  • Security Breach Indication: The detection of Behavior:Win32/RegDump.SA attributed to svchost.exe running as SYSTEM indicates a potential security breach, highlighting the importance of prompt action.

πŸ”— Resources:

  • Original post β†—
  • Original source
  • Microsoft Defender
  • Brief description: Microsoft Defender alert correlation with filesystem artifacts for forensic analysis

πŸš€ Security - Threat Detection

We added and updated 40 Suricata rules based on real attacker behavior observed in the wild. Explore the examples and strengthen your detection. #ANYRUNSuricataChangelog 09/07 – 09/13/2026 Here are 10 examples 81001410 | PHISHING [https://ANY.RUN] β†— Generic Phishkit

The addition and update of 40 Suricata rules based on real attacker behavior observed in the wild is a significant development in threat detection. These rules provide security professionals with the necessary tools to strengthen their detection capabilities and stay ahead of emerging threats. The examples provided, including the PHISHING rule 81001410, demonstrate the importance of staying vigilant and adapting to new threat patterns.

Key Points:

  • Suricata Rule Updates: The addition and update of 40 Suricata rules based on real attacker behavior observed in the wild provides security professionals with the necessary tools to strengthen their detection capabilities.

  • Threat Detection Strengthening: These rules enable security professionals to stay ahead of emerging threats and adapt to new threat patterns, ensuring the effectiveness of their detection capabilities.

  • PHISHING Rule Example: The PHISHING rule 81001410 is an example of the types of rules that can be used to strengthen detection capabilities, highlighting the importance of staying vigilant.

πŸ”— Resources:

  • Original post β†—
  • Original source
  • Suricata
  • Brief description: Suricata rule updates for threat detection

🚨 Security - Conference Agenda

The #TheSAS2026 agenda is live: https://thesascon.com β†— Browse the sessions, plan your route, then hit REGISTER if you haven’t already. Yes, there’s still some chaos. A few timings and details may still shift. No, that’s not unusual when active research and fresh findings

The #TheSAS2026 agenda is now live, providing security professionals with a comprehensive overview of the conference sessions and schedule. Despite some minor adjustments, the agenda offers a wealth of information and opportunities for learning and networking. Security professionals are encouraged to register and plan their route in advance to make the most of the conference.

Key Points:

  • Conference Agenda: The #TheSAS2026 agenda is now live, providing security professionals with a comprehensive overview of the conference sessions and schedule.

  • Session Planning: Security professionals are encouraged to plan their route in advance to make the most of the conference, taking into account any minor adjustments to the schedule.

  • Registration: Registration is now open, allowing security professionals to secure their place at the conference and access the latest research and findings.

πŸ”— Resources:


πŸš€ Security - Serverless Framework

serverless sf-core@4.42.0 β€” CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local...

The serverless sf-core@4.42.0 framework provides a comprehensive CLI solution for deploying and managing serverless applications on AWS Lambda. This framework utilizes YAML infrastructure and local development capabilities, making it an attractive option for developers and security professionals. The sf-core framework enables seamless integration with AWS Lambda, allowing for efficient deployment and management of serverless applications.

Key Points:

  • Serverless Framework: The serverless sf-core@4.42.0 framework provides a comprehensive CLI solution for deploying and managing serverless applications on AWS Lambda.

  • YAML Infrastructure: The framework utilizes YAML infrastructure, enabling developers to define and manage serverless applications in a structured and efficient manner.

  • Local Development: The sf-core framework supports local development capabilities, allowing developers to test and deploy serverless applications without the need for external infrastructure.

πŸ”— Resources:

  • Original post β†—
  • Original source
  • serverless sf-core
  • Brief description: Serverless framework for AWS Lambda

🚨 Security - Malware Update

Big news for malware enjoyers: more malware has been pushed to prod. It is more than I can count on my fingers and toes. Bigger news for people who continually ask me for pictures of cats: I’ve attached a picture of a cat to this post.

The update on malware activity is a significant concern for security professionals, as it indicates a substantial increase in malicious activity. The sheer volume of malware pushed to production is staggering, highlighting the need for robust security measures and vigilant monitoring. The inclusion of a cat picture serves as a lighthearted reminder of the importance of taking breaks and maintaining a sense of humor in the face of adversity.

Key Points:

  • Malware Activity: The update on malware activity indicates a substantial increase in malicious activity, posing a significant concern for security professionals.

  • Robust Security Measures: The need for robust security measures and vigilant monitoring is highlighted by the sheer volume of malware pushed to production.

  • Importance of Humor: The inclusion of a cat picture serves as a reminder of the importance of taking breaks and maintaining a sense of humor in the face of adversity.

πŸ”— Resources:


πŸš€ Security - Threat Actor Activity

RATs, stealers, and loaders all moved higher last week. #LokiBot nearly tripled in activity, while #Remcos jumped by more than 50% alongside growth in #XWorm, #AgentTesla, and #XLoader. Trend to watch: sharp increases like these can quickly change which threats require

The recent surge in RATs, stealers, and loaders is a concerning trend for security professionals. The significant increase in activity for #LokiBot, #Remcos, and other threats highlights the need for vigilant monitoring and adaptation. The trend to watch is the potential for sharp increases in threat activity to quickly shift the landscape, emphasizing the importance of staying ahead of emerging threats.

Key Points:

  • RATs, Stealers, and Loaders: The recent surge in RATs, stealers, and loaders is a concerning trend for security professionals, highlighting the need for vigilant monitoring and adaptation.

  • Threat Activity Increase: The significant increase in activity for #LokiBot, #Remcos, and other threats emphasizes the need for security professionals to stay ahead of emerging threats.

  • Trend to Watch: The trend to watch is the potential for sharp increases in threat activity to quickly shift the landscape, underscoring the importance of adaptability.

πŸ”— Resources:


🚨 Security - IP Blocking

Some newer IPs trying to exploit or probe for the recent #MikroTik SSH authentication bypass. You may want to block these in your firewalls. 146[.]19[.]216[.]125 172[.]104[.]114[.]238 178[.]62[.]124[.]12 187[.]15[.]135[.]119 212[.]11[.]29[.]24 45[.]61[.]177[.]253

The recent #MikroTik SSH authentication bypass has led to a surge in exploitation attempts, with newer IPs attempting to probe for vulnerabilities. Security professionals are advised to block these IPs in their firewalls to prevent potential security breaches. The list of IPs provided serves as a valuable resource for security professionals to stay ahead of emerging threats.

Key Points:

  • IP Blocking: Security professionals are advised to block the listed IPs in their firewalls to prevent potential security breaches.

  • MikroTik SSH Authentication Bypass: The recent #MikroTik SSH authentication bypass has led to a surge in exploitation attempts, highlighting the need for vigilance.

  • Emerging Threats: The list of IPs provided serves as a valuable resource for security professionals to stay ahead of emerging threats.

πŸ”— Resources:


πŸš€ Security - IP Information

146[.]19[.]216[.]125 | 134677 | 146[.]19[.]216[.]0/24 | AS134677 | SG | Dromatics Systems Pte Ltd 172[.]104[.]114[.]238 | 63949 | 172[.]104[.]96[.]0/19 | AS63949 | SG | Akamai Technologies, Inc[.] 178[.]62[.]124[.]12 | 14061 | 178[.]62[.]64[.]0/18 | AS14061 | US | DigitalOcean,

The provided IP information includes details on IP addresses, AS numbers, and associated organizations. This information serves as a valuable resource for security professionals to understand the context and potential risks associated with these IPs. The list of IPs and associated information highlights the importance of staying informed and vigilant in the face of emerging threats.

Key Points:

  • IP Information: The provided IP information includes details on IP addresses, AS numbers, and associated organizations.

  • Contextual Understanding: This information serves as a valuable resource for security professionals

πŸ“‚Source / Implementation:Cybersecurity and Tech / resources-210.md
GitHub Repository↗

Related Cybersecurity and Tech Breakdowns

Drishtant Ghosh (Drix10)
Drishtant Ghosh (Drix10)β€’Author & Engineer

Technical founder and engineer working across AI systems, developer infrastructure, and cybersecurity.