ISC StormCast for Tuesday, April 9th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 April 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, April 9th, 2024 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from London, England. |
| 0:13.2 | In today's diary, we got a nice case study by one of our undergraduate interns looking at how the threat hunting team and the security |
| 0:23.6 | operation teams can work together in order to analyze activity and find potential compromises. |
| 0:31.4 | In this particular case, I think one of the important lessons to me at least is how important |
| 0:36.9 | it is to really close the loop when it comes to threat intel, |
| 0:41.4 | where the threat hunting team looks for the anomalies, find something, hands it over to secure the operations team that can then dive in deeper, figure out what exactly happens, |
| 0:53.1 | and then again feed that information back to the |
| 0:56.4 | threat hunt team to hopefully find new and exciting compromises. Well, maybe not that exciting, |
| 1:03.2 | and also, as in this case, find them in time before any significant damage happens. |
| 1:10.5 | Interesting little case study, and certainly thanks to Nathaniel Jakuts for contributing |
| 1:17.1 | this article. |
| 1:20.7 | And then we have, well, yet again, problems with new top-level domains. |
| 1:25.0 | This time it's the plus top level domain. Someone registered the domain |
| 1:31.1 | name Notepad. Plus and is using it now apparently to sort of impersonate the website for |
| 1:39.5 | the famous editor Notepad Plus Plus. This is currently not obviously malicious if you're going to Notepad. |
| 1:49.6 | Plus, you're going to be redirected to the official Notepad++ website. |
| 1:56.4 | But that, of course, could change at any time. |
| 2:00.7 | And it's possible that this initial redirection |
| 2:03.6 | is really sort of more a confidence builder where the bad actors, if they have in the end, |
| 2:10.1 | bad intention, are going to use traffic that's currently going through their site to either |
| 2:16.6 | profile visitors, maybe redirect |
| 2:18.8 | some of these visitors to a malicious site, or maybe just trying to establish some history, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

