TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

OSINT for Incident Response (Part 2)

BHIS · 2024-03-07 · Read original ↗

ATT&CK techniques detected

6 predictions
T1657Financial Theft
97%
"were still getting robbed. i ’ m sure all financial services institutions suffer from some measure of loss due to fraudulent transactions. but ffsi bank ( “ fictitious financial services institution bank, ” because that ’ s just how creative i am ) was seeing a significant increa…"
T1588.004Digital Certificates
74%
"in the “ index of ” image above. a smoking gun and a gold mine in one fell swoop! what about other potentially malicious sites? let ’ s pull on the “ certificate ” thread and see what we can find! next, i visited https : / / search. censys. io to leverage their certificate servic…"
T1588.003Code Signing Certificates
56%
"in the “ index of ” image above. a smoking gun and a gold mine in one fell swoop! what about other potentially malicious sites? let ’ s pull on the “ certificate ” thread and see what we can find! next, i visited https : / / search. censys. io to leverage their certificate servic…"
T1588.003Code Signing Certificates
40%
"/ legit. but i noticed a pattern of three or four certificates with “ common name ” ( cn ) and a slight misspelling of the word “ bank ” ( as above ). re - running the search and filtering on “ let ’ s encrypt ” as a certificate services provider, it became clear that there were …"
T1588.004Digital Certificates
32%
"/ legit. but i noticed a pattern of three or four certificates with “ common name ” ( cn ) and a slight misspelling of the word “ bank ” ( as above ). re - running the search and filtering on “ let ’ s encrypt ” as a certificate services provider, it became clear that there were …"
T1657Financial Theft
30%
"osint for incident response ( part 2 ) osint for incident response ( part 2 ) be sure to read part 1! metadata and a new - fashioned bank robbery let ’ s face it, some cases are just more interesting than others and, when you do incident response for a living, you ’ ve got to fin…"

Summary

Be sure to read PART 1! Metadata and a New-Fashioned Bank Robbery Let’s face it, some cases are just more interesting than others and, when you do incident response for […]

The post OSINT for Incident Response (Part 2) appeared first on Black Hills Information Security, Inc..