meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 22nd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 January 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Blue ; EFS Ransomware; Fake Data Leak Compensation; Fake Job Site Scam

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 22nd, 2020 edition of the Sands and the Storms on us Stormcast.

0:08.3

My name is Johannes Ulrich.

0:09.8

And then I'm recording from Jacksonville, Florida.

0:14.3

Today we got a nice write-up by Russ about Deep Blue CLY.

0:19.1

Deep Blue CLY is a power shell script that allows you to quickly and efficiently search and

0:26.3

summarize Windows event logs.

0:29.2

It actually comes from the Sands Blue team and Eric Conrad is sort of leading this effort.

0:36.4

It's a pretty interesting script and Russ is sort of running through a couple scenarios here.

0:42.3

What you can find with the script, like just for example interesting events like starting and stopping of the event log service itself or finding evidence of the use of a interpreter and such.

0:56.6

So it has a number of things that's looking for new users being added to the system.

1:02.5

It's another one that I actually like because that's something attackers tend to do if they

1:08.7

have sufficient access to the system. So if you want to check it out,

1:13.9

it's a free tool and Russ is also linking to the respective GitHub repository.

1:22.4

Security company SafeBridge has a blog post that shows how the Windows encrypted file system or EFS could potentially be used by a ransomware against the user.

1:35.0

I'm not trying to have been sure how significant of an issue this is.

1:39.7

I think in general the problem with ransomware is that it does turn the security feature of encryption against the user itself.

1:49.0

Now, of course, with encrypted file system, the problem is that it itself is often sort of a white listed from various anti-mail-ver that does try to detect if any software all of a sudden starts to

2:02.8

encrypt files.

2:04.2

If you're using the encrypted file system to do that, then your anti-malware is probably

2:08.7

not going to alert you.

2:11.6

Now, another interesting quirk to this is that the files will remain usable to the regular user until the attacker

2:21.5

decides to flush the EFS data from memory, and apparently there is a specific undocumented

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.