Infosec.Pub
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
digicatM to blueteamsecEnglish · 8 months ago

Detecting ManualFinder/PDF Editor Malware Campaign with KQL

www.lindensec.com

external-link
message-square
0
link
fedilink
5
external-link

Detecting ManualFinder/PDF Editor Malware Campaign with KQL

www.lindensec.com

digicatM to blueteamsecEnglish · 8 months ago
message-square
0
link
fedilink
The ManualFinder and PDF Editor malware campaign represents a chain attack that turns legitimate-looking applications (well, I guess..) into information stealers and more. In this post, we'll walk through building a comprehensive KQL hunting query that leverages external IOC sources for real-time threat detection. -----------------------------------------------------------------------------------------------------------------The Campaign OverviewOver the past week, Expel’s team dropped a blog po
alert-triangle
You must log in or # to comment.

blueteamsec

blueteamsec

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !blueteamsec@infosec.pub

For [Blue|Purple] Teams in Cyber Defence - covering discovery, detection, response, threat intelligence, malware, offensive tradecraft and tooling, deception, reverse engineering etc.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 11 users / day
  • 96 users / week
  • 311 users / month
  • 1.01K users / 6 months
  • 231 local subscribers
  • 684 subscribers
  • 3.04K Posts
  • 228 Comments
  • Modlog
  • mods:
  • digicat
  • BE: 0.19.17
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org