4.9 • 696 Ratings
🗓️ 23 June 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, June 23rd, 2025 edition of the Sands Internet Storm Center's Stormcast. |
0:08.4 | My name is Johannes Ulrich, and this episode brought you by the Graduate Certificate Program in Industrial Control Systems Security is recorded in Stockholm, Germany. |
0:21.1 | So off this podcast, I have mentioned the mark of the web |
0:25.4 | and also alternate data streams. |
0:28.0 | Now, if you're running Windows and you're using the NTFS file system, |
0:33.7 | then, well, the mark of the web is encoded in the file as an alternate data stream. |
0:39.4 | But of course, we sometimes also have other interesting data, sometimes malicious data, |
0:44.8 | hidden in alternate data streams. |
0:47.3 | DDA today talked about how to decode some of these alternate data streams using some of his tools, |
0:56.0 | most notably cut-bytes.py. |
1:00.0 | That's one of the many Python tools that Didi maintains, |
1:04.0 | but he also has file scanner, which is faster, it's written in C, |
1:10.0 | but not maybe quite as flexible as the cut bytes tool. |
1:15.4 | Both tools make it really easy to get the information out of these alternative data streams. |
1:19.4 | And personally, I think specifically for the mark of the web to sort of see the provenance of a particular file that was downloaded. |
1:31.3 | Well, that's certainly quite useful. And Microsoft made some changes to make their virtualized cloud PCs more secure. |
1:38.3 | Now, this affects virtual cloud PCs running in Windows 11. |
1:43.3 | And really, the goal of these cloud PCs is to have sort of this isolated system in the cloud |
1:49.0 | that's, well, not really connected to anything locally. |
1:53.0 | Of course, by default, this hasn't been true in the past. |
1:57.0 | For example, by default clipboards were connected connected or you had USB pass through enabled. |
2:04.8 | This is now disabled by default, starting in the second half of the year. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.