meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 12th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 12 January 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. NVD CVEScan; Sysinternals Update; Ubiquity Breach; Run-Only AppleScript Reversing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, January 12, 2021 edition of the Sandstone at Storm Center's Stormcast.

0:07.5

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.8

And this week I'm actually teaching the SEC 5-22 defending web application class in Washington, D.C.

0:20.2

At least, well, that's sort of the virtual location

0:23.5

of our Cloud Defender event this week.

0:29.2

Rob today completed his three-part series about how to use the NIST National Vulnerability

0:36.6

database with automated PowerShell tools in order

0:40.1

to augment and assist with your vulnerability management program.

0:46.4

Interesting PowerShell script that he came up with in the end, and it is available on GitHub.

0:54.0

And Microsoft released a new version of the SIS Internals tool

0:58.0

with two significant updates to SysMON and Process Monitor.

1:04.0

SISMON added additional events that will alert you

1:08.0

if a mapped image file in memory doesn't match the on-disc image file.

1:13.6

Also, if the image is locked for exclusive access, which is of course a common sign that process

1:22.6

hollowing does take place.

1:24.6

That's where an attacker essentially modifies an image of a process in memory

1:29.5

in order to inject malicious code. And process monitor will now also monitor the rec safe key,

1:37.5

reg load key, and rec restore key APIs. In particular, the Sysmon update sounds really interesting and would be interesting

1:46.0

to hear from you if that works for you, if you detected anything, if there are any false

1:51.6

positive issues with this new feature. Based on that I in the past have gotten quite a few

1:58.0

requests for how to install our honeypot behind ubiquity

2:02.1

perimeter device. I'm assuming that quite a few of you are using ubiquity equipment,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.