GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 22-Jun-2024 09:00:54 JST Kevin Beaumont Kevin Beaumont

    Good find by Elastic - North Korean based threat actors using an unfixed bug in Windows to execute code, undetected across all vendors until that point (and as of writing only Elastic detect still)

    They’ve named it GrimResource https://www.elastic.co/security-labs/grimresource

    #threatintel

    In conversation about a year ago from cyberplace.social permalink

    Attachments


    1. https://cyberplace.social/system/media_attachments/files/112/657/325/354/409/173/original/8be1d000eeccd8c4.jpeg
    2. Domain not in remote thumbnail source whitelist: www.elastic.co
      GrimResource - Microsoft Management Console for initial access and evasion — Elastic Security Labs
      Elastic researchers uncovered a new technique, GrimResource, which allows full code execution via specially crafted MSC files. It underscores a trend of well-resourced attackers favoring innovative initial access methods to evade defenses.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 25-Jun-2024 19:46:48 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Still essentially zero detection for GrimResource. PoC that spawns calc: https://gist.github.com/joe-desimone/2b0bbee382c9bdfcac53f2349a379fa4

      #threatintel

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: github.githubassets.com
        grimresource.msc
        from joe-desimone
        GitHub Gist: instantly share code, notes, and snippets.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 25-Jun-2024 22:56:43 JST Kevin Beaumont Kevin Beaumont
      in reply to

      This GrimResource issue is.. Grim. Here's the PoC listed above, it's just easy code execution as the HTML code executes as the local computer context. I expect this one to explode in crimeware groups as it is so easy to exploit. Microsoft need to fix it.

      I can see clear historic misuse on VirusTotal - also red team firms using .msc files via MMC to, for example, get SMB hashes via WebDAV as it appears MMC just yolo contacts anything and auto logs in.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/677/568/138/470/832/original/cbfe22ed50af4ece.png
    • Embed this notice
      TheTomas (thetomas@social.toot9.de)'s status on Tuesday, 25-Jun-2024 23:09:09 JST TheTomas TheTomas
      in reply to

      @GossiTheDog Again, Software Restriction Policies, deployed via GPO help... *sigh*

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 26-Jun-2024 19:53:38 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Microsoft Defender AV started rolling some detection coverage for GrimResource 🥳

      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.