SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update;
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 March 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, March 20th, |
| 0:07.8 | 2006 edition of the Sands and then at Storm Center's Stormcast. |
| 0:12.7 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.5 | And this episode is brought you by the Sands.edu credit certificate program in cyber defense operations. |
| 0:25.3 | One of the questions we often get is whether or not any like global events are affecting what we are seeing in our logs. |
| 0:33.6 | Now, we have in the past often seen like disasters and such, for example, being used in scams. |
| 0:40.4 | Guy had an interesting sort of event in his cowrie honeypot that's a little bit related with what's |
| 0:48.1 | happening now in Iran. Essentially a message that the attacker added to the command line here that was executed in the honeypot that just stays magic payload killer here or leave empty. |
| 1:02.0 | And then Iranbot was here. |
| 1:04.6 | This is often kind of just use of as a little indicator whether or not the commands are actually properly processed. Sometimes, |
| 1:12.6 | strings like this are being also used to identify honeypots to see what is then actually |
| 1:17.4 | being returned by the particular shell that they attempt to log into. In this case, |
| 1:25.3 | it wasn't anything remotely sophisticated, just yet so of another |
| 1:29.7 | S-H prude-forcing attack. And sometimes attackers are really also just, you know, |
| 1:35.2 | using these strings for notoriety to maybe be recognized or as such. But yes, not everything |
| 1:43.0 | is sort of nation states if it does mention a nation as part |
| 1:48.8 | of a string in a payload like this. |
| 1:52.3 | Talking about Iran, there was one significant breach that was caused by threat actors associated |
| 1:59.3 | with Iran, and that was against the medical supply |
| 2:03.1 | company Stryker. |
| 2:04.5 | Now, I typically don't talk about breaches much unless there's sort of a lesson to be learned |
| 2:09.7 | or something actionable coming out of it, and that's what we have now. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

