Reducing Detection from Months to Minutes: Detecting Credentials in the Clear
Welcome back to our blog series on reducing detection time from months to minutes. In our first and second posts, we showed how you can use metadata to quickly resolve phishing attacks and investigate...
View ArticleOperation TradeSecret: Cyber Espionage at the Heart of Global Trade
In late February, Fidelis Cybersecurity observed a strategic web compromise on a prominent U.S. lobbying group that served up malware to a very specific set of targets. The malware we observed has...
View ArticleGoing Back in Time: Investigating Threats Retroactively
Welcome back to reducing detection time from months to minutes. In the first post in this series, we showed how metadata holds the power to quickly disarm one of the most effective cyberattack methods...
View ArticleCISO, Welcome to the Boardroom: New Regulations Likely to Impact CISO Role
Interesting changes are happening in the world of cybersecurity legislation. Notably, these changes are impacting the role of the chief information security officer (CISO). No longer are CISOs just...
View ArticleUsing Yara for Intrusion Prevention
Nviso Labs recently published a fascinating blog post illustrating the use of the Lua programming language over the Suricata DPI engine to detect obfuscations in PDF files. Deep analysis of content...
View ArticlePhind the Phish - Reducing Phishing Detection from Months to Minutes
Every day, attackers tunnel under, sneak through, go around, go over and squeeze past your security technologies.While you’re armed with more security tools than you can count, most of them are hiding...
View ArticleWIDESPREAD EXPLOITATION ATTEMPTS USING CVE-2017-5638
Many research teams have reported on their observations of exploits involving the use of the Apache Struts vulnerability CVE-2017-5638 since Cisco Talos published their post on Wednesday March 8....
View Article5 Requirements for Stopping Modern Intrusions
There’s a reason why airport security x-rays your bags. It’s because the only way you can tell if something is a true threat is to actually look at the contents.It’s the same with network security....
View ArticleModern Messaging OPSEC: Popular App Gives Scammers a Boost
Modern messaging apps, many of which offer end-to-end encryption, are used every day by millions of people. These apps come with the expectation of privacy. However, we recently observed an...
View ArticleUnderstanding the SmokeLoader Downloader
Downloaders and droppers (aka malware that delivers other malware) have been forced to live in the shadow of more famous stages of the exploit kit chain, like landing pages or the malware that's...
View ArticleRSA 2017: Join Fidelis Cybersecurity in San Francisco
We're counting down the last few days to RSA 2017. As you pack your suitcase and map out your schedule, plan on joining us for a demo at Booth #933. Stop by and say hello and grab your limited edition...
View ArticleSpying on GoldenEye Ransomware
Producers of the 1995 James Bond film “GoldenEye” packed the plot with all the signature elements fans expect from the successful franchise. Over-the-top supervillain – check. Cool spy gadgets –...
View ArticleFive Security Trends to Watch in 2017
What does 2017 hold for security professionals and the industry as a whole?To answer this question, let’s take a quick look at what has not changed. For one, ransomware continues to be an effective...
View ArticleRevenge of the DevOps Gangster: Open Hadoop Installs Wiped Worldwide
Earlier this month, security news media reported attackers holding internet-exposed MongoDB and Elasticsearch databases for ransom. Attackers said they’d return the data if they got paid -- otherwise,...
View ArticleSorting Out the Next Generation of Security
Security got the boring end of the stick when names for the generations were handed out. Instead of Millennials, Gen X, Baby Boomers or the Greatest Generation, we're stuck with "Next Gen." What...
View ArticleThe Best of Both Worlds: A New Approach to Endpoint Security
There are two types of runners: long-distance runners and sprinters. Everything about them is different. Sprinters are built for power while marathoners are built for endurance. But what if you could...
View ArticleDid You Hire Your IPS for a Job of the Past?
In Part 1 of this series we asked the question: Would you re-hire your IPS if you interviewed it today? But it’s not a totally fair question. Because, before you hire someone (or in this case buy...
View ArticleVawtrak DGA Round 2
Vawtrak, a.k.a. Neverquest, has been a prominent trojan in the banking world and numerous researchers have reported their findings about this malware. In August 2016, we blogged about the addition of a...
View ArticleDown the H-W0rm Hole with Houdini's RAT
Commodity Remote Access Trojans (RATs) -- which are designed, productized and sold to the casual and experienced hacker alike -- put powerful remote access capabilities into the hands of criminals....
View ArticleTen Impossible Things You Can Do with Metadata, Part 2
Metadata gathered from your network can be a powerful ally in the battle against cyberattacks. In fact, you can do seemingly impossible things with the right metadata. In Part 1, we explored how...
View Article