meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, August 29th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 August 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cobalt Strike False Pos; Analyzing HTTP/2; Sysmon Update; Paypal/Coinbase Phish; eth.link at risk

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, August 29th, 2020 edition of the Sands Internet Storm Center's

0:07.5

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

This weekend, we had a number of nice Internet Storm Center diary posts, so let's start with one by DDA showing how to deal with false positives when scanning

0:26.2

memory dumps for Cobalt Strike Beacons.

0:29.9

To do so, DDA updated his 1768.PY tool.

0:36.1

This tool typically searches for the beacon information in memory dumps by looking for the header.

0:42.3

But while that particular pattern may show up in unrelated memory segments and that of course gets you then false positives, a new option to the tool will now apply additional sanity checks, removing the false positives

0:57.7

from the output.

0:59.0

Now, the sanity checks that they introduced will check if the payload type and the public

1:04.5

key values are reasonable, basically whatever numbers come back for payload type, that

1:09.5

is one that's actually being

1:12.0

used. One cause of these false positives is also that antivirus signatures will sometimes

1:19.2

contain those patterns. Of course, they're also looking for those patterns. And that sort of is

1:26.5

how they end up in memory. An additional feature that the 1768.P.Y.

1:34.7

tool has is to offer a verbose mode. With the verbose mode, you'll sort of get a little memory dump,

1:41.5

basically, around the area where the signature was matched.

1:50.8

And in the case of antivirus tools, you often then see strings indicating essentially the malware signature, the malware name that is then being associated with that signature.

1:58.5

So that usually gives you a good idea that you're dealing here with signatures,

2:02.0

not with the actual malware.

2:05.7

And Gion, Saturday, took a look at HDP2,

2:08.8

somewhere to seeing TLS requests to non-TLS servers.

2:13.5

If you have an HTP2 request

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.