I’m a dedicated father and friend. I enjoy technology immensely and feel extremely lucky to have been born at the right place & during the right time. I started out working for the University of Dayton as a co-op student in computer science. I fell in love with the concept of networking – this wasContinue reading “About:me”
Category Archives: Uncategorized
importing wildfire reports into misp and thehive
I’m experimenting with thehive and associated projects (misp in particular) and will be describing some issues I run into & how I’ve fixed them (fingers crossed). One of the first things I tried was to import events from wildfire to misp. I found a package called pan-stix and installed it on my osx box. RunningContinue reading “importing wildfire reports into misp and thehive”
Examining strange wscript behavior
We use cylance with script control, and periodically I review the outliers that have been blocked. I came across this one recently: wscript.exe “C:ProgramData{18E0DD83-92A2-5745-1464-C9078E2642C9}domo.txt” “68747470733a2f2f643237346571343163333972326e2e636c6f756466726f6e742e6e6574” “//B” “//E:jscript” “–IsErIk” I took a copy of the domo.txt script and uploaded to VT: I also ran that hex string through a hex decoder: 68747470733a2f2f643237346571343163333972326e2e636c6f756466726f6e742e6e = https://d274eq41c39r2n.cloudfront.net According toContinue reading “Examining strange wscript behavior”
Update: f5d599a39d02caef1984e95fdc606f838893ffc5.xyz
Unfortunately, as of 16 April 2019, I’m still seeing traffic on this domain. Here are some others I’m seeing: dfbfb63dcaff96fbe9616fb806e4799f.com8d46980d994cc618aeed127df1b5c86d8acd86ce.info07bf396c25d9a624281c97752aee0247e4229b84.xyz07bf396c25d9a624281c97752aee0247e4229b84.com07bf396c25d9a624281c97752aee0247e4229b84.infod234304f57772cf6be78ab6c24a65c91ce896fff.xyzd234304f57772cf6be78ab6c24a65c91ce896fff.comd234304f57772cf6be78ab6c24a65c91ce896fff.info8d46980d994cc618aeed127df1b5c86d8acd86ce.xyzcbb0c7dae8061aca012b8a910062c33f3642e383.comcbb0c7dae8061aca012b8a910062c33f3642e383.xyzcbb0c7dae8061aca012b8a910062c33f3642e383.info
Disabling NTLM
NTLM auditing in an active directory domain with splunk.
Update on f5d599a39d02caef1984e95fdc606f838893ffc5.xyz
I contacted security@nordvpn and they said it will be fixed in the most recent release of NordVPN. As a bonus they gave me 3 years free for reporting the issue 🙂
f5d599a39d02caef1984e95fdc606f838893ffc5.xyz
I’m now the proud owner of these domains: f5d599a39d02caef1984e95fdc606f838893ffc5.com 8d46980d994cc618aeed127df1b5c86d8acd86ce.xyz 10bdc75ab2f0486f008dbdd8f1b0a38d7399598e.xyz Why would I purchase such strange looking domains you ask? It all started long ago, while working for my enterprise. I saw some activity flagged by OpenDNS / Umbrella for some CnC traffic bound for these domains. It was being blocked but as IContinue reading “f5d599a39d02caef1984e95fdc606f838893ffc5.xyz”
choose your own identity
I’ve been working with my team to come up with some visionary thoughts around where we think our services will be in the next 3-5 years. In addition to the typical CMMI-speak, we did come up with a few ideas that I think are revolutionary from a corporate IT perspective. The one term I cameContinue reading “choose your own identity”
i know nothing
Let me just begin by saying that I don’t know anything. There, I said it. And I truly believe it. The more I learn, the more I realize I don’t know shit.Now that I’ve gotten that off my chest, let me talk a little about some things I do know, and I’m OK at (read:Continue reading “i know nothing”
Giving Back
I went to DefCon 2012 this year for the first time ever and I must say that it was a great experience. I met too many people to count, and learned a good deal about some security topics. I also learned some information about password hashes, which is fantastic b/c it’s some timely information withContinue reading “Giving Back”