meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 13th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 13 February 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Script Block Logging Deactivation; Zeek and pcaps; Prompt Injection

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, February 13, 2023 edition of the Sands and at Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.3

Got a couple of interesting diaries this weekend. The first one was a brief one by Xavier talking about attackers using PowerShell to disable

0:24.0

script block logging. Script block logging is, well, as the name sort of implies,

0:29.7

used to log what PowerShell scripts do, and attackers don't like that, so they tend to disable it.

0:35.6

In this particular example that Xavier has, there's sort of some obfuscated code being used

0:43.7

using collection generic dictionary object in order to disable this logging.

0:52.7

Interesting little code snippet and probably something kind of

0:55.8

that should be considered suspicious or malicious as is. And SEAC is certainly one of my favorite,

1:04.0

if not the favorite tool to analyze PCAP data. Now often you don't run SEAC at the time that you collect the packets, but you

1:13.3

are running SEACs later on packets that you collected, for example, from some incident.

1:20.5

And Jesse is walking you through the process in a second diary from this weekend, talking about

1:26.6

how to prepare your P-Caps to run them through Seek.

1:30.3

For the most part, well, a Seek will just read P-Caps, but there are a couple of artifacts that sometimes you block that or that you may run into.

1:40.0

One is if the packet capture got sort of disrupted in the middle of capturing a packet,

1:46.0

it often happens if you sort of exit out of T's-B-Dump with Control Z.

1:50.8

Then we also do sometimes want to merge different P-Caps,

1:56.2

and Jesse is just walking you through the process of using PCAP fix

2:00.7

and then a merge cap to actually get the packet capture ready, and then also a couple sort of little hints on using the seek data.

2:10.9

And with new tools come, new vulnerabilities.

2:15.5

One of the interesting tools, of course, being revealed and really sort of

2:20.0

taking off this last month is GPT3-based chat engines, like most notably chat, GPT, but also

2:29.5

the new in limited beta Bing chat bot.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.