meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 18th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 18 February 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Snap Patches; Properties in Office Docs, Bro-Sysmon, Cryptojacking

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, February 18th, 2019 edition of the Sansonet Storm Center's Stormcast.

0:07.2

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.9

Last week I mentioned the vulnerability in the snappy packet manager that is distributed by Canonical, the company Bied Hein

0:22.2

Ubuntu, and of course it is used by Ubuntu but the listener pointed out that

0:27.6

yes it's used by other distributions too. It can install it pretty much on any

0:32.6

distribution you choose to. Now patches are now available not, not just for Ubuntu, but also for other

0:40.2

distributions. So double check and make sure that you applied this patch. And in the show notes,

0:46.3

you will find a link to the Ubuntu page that has references to patches for different

0:54.1

distributions.

0:55.0

And for all the reverse engineers out there, based on some reader feedback,

1:02.0

DDE updated his famous OLLI Dumb tool in order to also find PowerShell commands hidden in

1:09.0

a property alternative text so if you're

1:11.8

interested in this over the weekend DDA published diary explaining how this

1:16.6

works and also a video with a little walk through through this latest

1:21.1

version of his tool and the Salesforce team is added again with releasing some pretty neat security tools.

1:31.0

The latest one that they released was ProSysmon and they now have a nice blog post, how to set it all up

1:38.6

and how to also integrate it with their SSL fingerprinting libraries like JA3.

1:45.0

Now, what Pro-Sysmon really does is it uses data from SISMON.

1:51.0

SISMON is an add-on tool for Windows that you can use to, for example,

1:56.0

monitor outbound network connections, among other things.

2:00.0

And the way sort of a pro or seek

2:02.8

feeds in there is that it would be nice to know which particular program on a Windows host did

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.