NPD4n6: Nicks DFIR blog

NPD4n6: Nicks DFIR blog

  • Home
  • About
  • Links
  • Resources
  • npd4n6
  • November 24, 2023
    HCK.SYD 2023

    HCK.SYD 2023

    Awesome day out yesterday at HCK.SYD!

  • November 2, 2023
    MFA Bypass – how frameworks like Evilginx are giving threat actors the tools to succeed.

    MFA Bypass – how frameworks like Evilginx are giving threat actors the tools to succeed.

    Hopefully it is well known by now that two-factor/multi-factor authentication (MFA) is not a silver-bullet to all your cyber problems. The tooling – Evilginx I previously wrote about Evilginx and how we are starting to see it more and more, even though the original tool was developed back in 2017: https://github.com/kgretzky/evilginx2 What is it? Evilginx…

  • October 26, 2023
    AISA CyberCon 2023

    AISA CyberCon 2023

    Another year, another Australian Information Security Association (AISA) CyberCon in Melbourne! Always super excited to head down and watch the talks of what the cyber people have uncovered over the past 12 months. Although I didn’t get to nearly as many talks as I would have liked, with so many streams it was hard to…

  • October 19, 2023
    Phishing emails – a breakdown from an Incident Responder getting phished: Part 1.

    Phishing emails – a breakdown from an Incident Responder getting phished: Part 1.

    Finally! A phishing 🎣 email targeted at me to analyse – let’s jump in. This phishing email 📧, and three identical replicas slipped through our email filter and hit my Inbox. Intrigued by my first Gridware phishing email, I’ve taken a closer look at the email and its contents 🕵️‍♂️. Some interesting points to this…

  • October 13, 2023

    Microsoft Entra – adversary token collection

    Great post by Dirk-jan Mollema on token collection via phishing by an adversary https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/

  • September 28, 2023
    Evilginx and Evilginx pro

    Evilginx and Evilginx pro

    Working on a BEC with a MFA bypass looking likely, and stumbled upon a common framework utilised for this attack – Evilginx The creator of EvilGinx shared an interesting demo of how you can be easily Phished on LinkedIn and it even bypasses MFA. These types of attacks are becoming increasingly popular. https://twitter.com/mrgretzky/status/1706735382698582026?s=56&t=-dkNDSDHEzyAagaVN0SDgA This morning…

  • September 20, 2023

    Pizza Hut Australia hit by potential cyber incident

    Another day, another Aussie org hit by a cyber incident. Source: https://www.databreaches.net/pizza-hut-australia-customer-data-hacked-shinyhunters-claims-to-have-more-than-1-million-customers-information/

  • September 15, 2023

    SANS 2023 Incident Response survey

    Some interesting key takeaways: Linke to read the full report here: https://www.sans.org/white-papers/2023-survey-event-incident-response/

  • September 15, 2023
    Invictus Incident Response – AWS Incident Response

    Invictus Incident Response – AWS Incident Response

    Great new tooling put together by the IIR team!! Excited to test this one. https://invictus-ir.medium.com/automated-aws-incident-response-the-next-episode-6d766d95d4f6 Github repo: https://github.com/invictus-ir/Invictus-AWS

  • September 13, 2023
    The anatomy of a forensic investigation

    The anatomy of a forensic investigation

    Yesterday some of the Gridware DFIR team had the pleasure of visiting and presenting to the Clyde & Co cyber team on the anatomy of a forensic investigation. Thanks for having us!

Previous Page
1 2 3 4 … 6
Next Page

Powered by Unit 42 and Coffee ☕️

  • Subscribe Subscribed
    • NPD4n6: Nicks DFIR blog
    • Already have a WordPress.com account? Log in now.
    • NPD4n6: Nicks DFIR blog
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar