Quantcast
Channel: Blue Team – NVISO Labs
Browsing index pages (40 articles)
↧

Image may be NSFW.
Clik here to view.

Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 2:...

Firewall network traffic logs are the largest driver of Microsoft Sentinel ingestion costs. Yet they remain a critical source of information for threat detection, investigations & incident...

View Article


Image may be NSFW.
Clik here to view.

Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 1:...

This blog is the first in a series exploring how Summary Rules, together with Auxiliary or Data Lake storage, can help organizations optimize SIEM costs without compromising core threat detection and...

View Article


Image may be NSFW.
Clik here to view.

The Detection & Response Chronicles: Covert Operations Through QEMU

Adversaries have always relied on legitimate tools to carry out their attacks. These tools are already trusted by security solutions, which allows them to blend in with normal activity, maintain a low...

View Article

Image may be NSFW.
Clik here to view.

Detection Engineering: Practicing Detection-as-Code – Tuning – Part 8

In Part 7, we showcased how we can leverage automation to continuously monitor the performance and trigger rate of our deployed detections. In this part, we are going to investigate how we can...

View Article

Image may be NSFW.
Clik here to view.

Security’s Blind Spot: Physical Keyloggers That Bypass Antivirus Entirely

Keyloggers: A Persistent Threat Nowadays, virtually all digital services rely on logins and authentication, from email inboxes to help desks. These involve login credentials to prove identity,...

View Article


Image may be NSFW.
Clik here to view.

The Axios npm supply chain incident: fake dependency, real backdoor

On March 31, 2026, two malicious Axios versions (1.14.1 and 0.30.4) were briefly published to npm via a compromised maintainer account. The only change performed was the addition of a trojanized...

View Article

Image may be NSFW.
Clik here to view.

Ivanti EPMM ‘Sleeper Shells’ not so sleepy?

In late January 2026 an advisory covering two remote code execution vulnerabilities (CVE-2026-1281 & CVE-2026-1340) in Ivanti Endpoint Manager Mobile (EPMM) was published. Shortly after reports (in...

View Article

Image may be NSFW.
Clik here to view.

Capture the Kerberos Flag: Detecting Kerberos Anomalies

Kerberos is one of the most common protocols in organizations that utilize Windows Active Directory, and an essential part of Windows authentication used to verify the identity of a user or a host [1]....

View Article


Image may be NSFW.
Clik here to view.

ConsentFix (a.k.a. AuthCodeFix): Detecting OAuth2 Authorization Code Phishing

ConsentFix (a.k.a.AuthCodeFix) is the latest variant of the fix-type phishing attacks, initially identified by Push Security. In this technique, the adversary tricks the victim into generating an OAuth...

View Article


Image may be NSFW.
Clik here to view.

The Detection & Response Chronicles: Exploring Telegram Abuse

Adversaries utilizing popular messaging apps throughout different attack phases is nothing new. Telegram, in particular, has constantly been the subject of abuse by multiple threat actors, favoured for...

View Article

Image may be NSFW.
Clik here to view.

Managing SIEM Log Collectors at Scale with Ansible and GitHub Actions – Part 1

A Security Operations Center (SOC) watches an organization’s IT systems for cyber threats 24/7. It quickly finds and fixes security problems and uses Security Information and Event Management (SIEM)...

View Article

Image may be NSFW.
Clik here to view.

Contagious Interview Actors Now Utilize JSON Storage Services for Malware...

NVISO reports a new development in the Contagious Interview campaign. The threat actors have recently resorted to utilizing legitimate JSON storage services like JSON Keeper, JSONsilo, and npoint.io to...

View Article

Image may be NSFW.
Clik here to view.

Detection Engineering: Practicing Detection-as-Code – Monitoring – Part 7

In this part, we are going to introduce automation to effectively monitor our deployed detections. By setting up automations at this phase we adopt a proactive approach towards maintenance, allowing...

View Article


Image may be NSFW.
Clik here to view.

Lunar Spider Expands their Web via FakeCaptcha

Key Findings Lunar Spider has expanded its initial access methods by compromising vulnerable websites, particularly in Europe, using Cross-Origin Resource Sharing (CORS) vulnerabilities. These websites...

View Article

Image may be NSFW.
Clik here to view.

Securing Microsoft Entra ID: Lessons from the Field – Part 1

This multipart blog series is focused on the real-world lessons learned while securing Microsoft Entra ID. Based on hands-on experience across various environments and organizations, we’ll explore the...

View Article


Image may be NSFW.
Clik here to view.

Detection Engineering: Practicing Detection-as-Code – Deployment – Part 6

The deployment phase is one of the most challenging steps in the Detection Development Life Cycle due to its implementation complexity. In this part, we will explore the principles and practices of...

View Article

Image may be NSFW.
Clik here to view.

Detection Engineering: Practicing Detection-as-Code – Versioning – Part 5

Versioning in the detection library is crucial for maintaining traceability and tracking changes to individual detections and content packs. It enables us to pinpoint the exact state of specific...

View Article


Image may be NSFW.
Clik here to view.

Detection Engineering: Practicing Detection-as-Code – Documentation – Part 4

Sufficiently documenting our detections is essential in detection engineering as it provides context around the the purpose, detection logic, and expected behaviour of each detection rule. Just as...

View Article

Image may be NSFW.
Clik here to view.

Shedding Light on PoisonSeed’s Phishing Kit

Key Findings: NVISO identified and analyzed the MFA-resistant phishing kit employed by the threat actor PoisonSeed, which is loosely aligned with Scattered Spider and CryptoChameleon. This kit is still...

View Article

Image may be NSFW.
Clik here to view.

Detection Engineering: Practicing Detection-as-Code – Validation – Part 3

In this part, we focus on implementing validation checks to improve consistency and ensure a minimum level of quality within the detection repository. Setting up validation pipelines is a key step, as...

View Article
Browsing index pages (40 articles)


Latest Images