ISC StormCast for Monday, March 25th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 March 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, March 25th, 2004 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. 1768.P.I is a tool that the DDA developed quite a while ago to analyze cobalt strike beacons. |
| 0:23.4 | 1768, by the way, is the melting point of cobalt, which led to the name of the tool. |
| 0:30.6 | It's not that year 1768 or so was special in any way. |
| 0:36.5 | Well, this tool keeps evolving as cobalt strike beacons keep evolving. |
| 0:42.5 | The latest update that DDA wrote about this weekend is what DDA calls experimental mode. |
| 0:50.2 | A recent sample that DDA looked at did use alternative data structures in order to store the |
| 0:58.0 | runtime configuration. That caused the old tool to crash. Well, this new tool in experimental mode |
| 1:04.5 | now does support this alternative configuration option. So hopefully that'll work. |
| 1:11.7 | Of course, D.D.A. is surely happy to hear if you are able to use this tool successfully. |
| 1:19.7 | For example, you will be able to extract, for example, the URLs it's connecting to and such. |
| 1:25.0 | It's really, really handy, in particular if you're dealing with incident |
| 1:28.4 | response and a cobalt strike beacon was used. And then you've got an interesting paper by |
| 1:35.7 | researchers from the Helmholtz Center for Information Security in Germany with details regarding |
| 1:41.7 | a new UDP-based application layer loop denial-of-service attack. |
| 1:47.6 | Now, these type of UDP-based amplification attacks have been around for a while. |
| 1:53.9 | We have seen them a lot being abused, for example, for DNS with some of these amplified attacks. |
| 2:00.5 | Traditionally, these attacks have used a small packet to trigger one large response, |
| 2:07.2 | in some cases several large responses. |
| 2:10.9 | Now, the new thing here is that we are actually dealing with a loop. |
| 2:15.9 | The way this particular attack works is that an attacker would spoof a packet to a vulnerable |
| 2:22.7 | service. |
| 2:24.0 | That vulnerable service will respond, and that response to an actual existing system will trigger |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

