Tuesday, February 7, 2017

"2017 Planning Ideas and 2016 Lessons Learned"

  Amplify Your Security Awareness Program in 2017 At the end of December I led a webcast reviewing some of the key lessons learned in 2016 and what we can do in 2017 to keep improving the practice, and impact, of security awareness programs. After working with hundreds of clients and awareness officers from around … Continue reading 2017 Planning Ideas and 2016 Lessons Learned

from Securing the Human

"3 Courses for Security Awareness Summit - Sell Out Fast"

Folks, we just added several new courses for the Security Awareness Summit in Nashville on 2/3 August. You may not realize it, but with the summit you can take classes also. The reason I'm telling you now isI'm concerned three of these classes will sell out FAST. If you are interested in any one of … Continue reading 3 Courses for Security Awareness Summit - Sell Out Fast

from lspitzner

Sunday, February 5, 2017

[SANS ISC Diary] Many Malware Samples Found on Pastebin

I published the following diary on isc.sans.org: “Many Malware Samples Found on Pastebin“.

pastebin.com is a wonderful website. I’m scrapping all posted pasties (not only from pastebin.com) and pass them to a bunch of regular expressions. As I said in a previous diary, it is a good way to perform open source intelligence. Amongst many configuration files, pieces of code with hardcoded credentials, dumps of databases or passwords, sometimes it pays and you find more interesting data… [Read more]

[The post [SANS ISC Diary] Many Malware Samples Found on Pastebin has been first published on /dev/random]



from Xavier

Saturday, February 4, 2017

[SANS ISC Diary] Detecting Undisclosed Vulnerabilities with Security Tools & Features

I published the following diary on isc.sans.org: “Detecting Undisclosed Vulnerabilities with Security Tools & Features“.

I’m a big fan of OSSEC. This tools is an open source HIDS and log management tool. Although often considered as the “SIEM of the poor”, it integrates a lot of interesting features and is fully configurable to solve many of your use cases. All my infrastructure is monitored by OSSEC for years… [Read more]

[The post [SANS ISC Diary] Detecting Undisclosed Vulnerabilities with Security Tools & Features has been first published on /dev/random]



from Xavier

Thursday, February 2, 2017

Stopping Cyberthreats in a new era

The explosive growth in the scale and sophistication of cyberthreats is remaking the security landscape. Today, it’s not a matter of if your organization’s data will be compromised, but a matter of when. Having a proactive protection strategy that includes pre- and post-breach components is critical to addressing advanced attacks.

Fortunately, Windows 10 has comprehensive pre-breach solutions and with Windows Defender Advanced Threat Protection (ATP) we added a post-breach layer to the Windows Security stack. And the best part? Windows Defender ATP is built in to Windows 10 and designed to provide the best performance experience on your machine. It doesn’t require any additional software deployment and management.

So do you want the good news or the bad news?

Well, here’s the outcome: New hacking techniques are multiplying exponentially and old pre-breach detection techniques can’t keep up. The numbers are alarming—on average it takes an attacker minutes to get in, and security teams more than 140 days to discover it.

With the release of Windows 10 Anniversary Update, Microsoft offers Windows Defender ATP to complement the existing endpoint security stack of Windows Defender, SmartScreen, and various OS hardening features. The new service, purposely built to detect and respond to advanced attacks, leverages a deep behavioral sensor integrated into Windows 10 combined with a powerful security analytics cloud back end to enable enterprises to detect, investigate, and respond to targeted and sophisticated advanced attacks on their networks.

Next-level protection: Post-breach detection and response

Windows Defender ATP goes wide and deep, working to cover all your bases, with a focus on post-breach challenges. It’s like having a black belt team of security defense experts supporting every machine running Windows 10.

Advanced attack detection. Microsoft makes the most of its strong security analytics and rich intelligence capabilities to provide visibility into anomalies and threats from a broad base of sources. We also leverage the Microsoft Security Intelligence Graph to cull data from Windows updates and search engine results that index billions of URLs to generate potential hack alerts immediately.

Investigation and response. The portal gives SecOps tools and capabilities to investigate and respond to threats on their endpoints. You can also proactively explore your network for signs of attacks, perform forensics on specific machines, track attacker actions across machines in your network, get a detailed file footprint across your organization, submit a file for deep analysis, and with the Creators Update isolate machines, kill processes, or ban files from your network.

Threat intelligence. Get internal and external reports and indicators for known attackers and of prominent attacks (Strontium, for example), validated and enriched by an internal team of security black belts and third-party feeds. With the Creators Update, you can add your own TI to define alerts unique to your environment within Windows Defender ATP, based on IOCs.

Windows 10 and Windows Defender ATP helpgs give you the best defense and offense when it comes to potential and actual data breaches. Learn more by downloading the ebook now.

Discover more about how this new strategic approach can make a real difference at Microsoft Secure.



from Microsoft Secure Blog Staff

"Get Your Security Awareness Roadmap Poster"

The Security Awareness Maturity Model was developed five years ago by a community of security awareness officers to solve a problem. Specifically the awareness community needed a way to visually communicate what stage a security awareness program was currently at and where the organization wanted to take it. The Security Awareness Roadmap builds on the … Continue reading Get Your Security Awareness Roadmap Poster

from lspitzner

Wednesday, February 1, 2017

[SANS ISC Diary] Quick Analysis of Data Left Available by Attackers

I published the following diary on isc.sans.org: “Quick Analysis of Data Left Available by Attackers“.

While hunting for interesting cases, I found the following phishing email mimicking an UPS delivery notification… [Read more]

[The post [SANS ISC Diary] Quick Analysis of Data Left Available by Attackers has been first published on /dev/random]



from Xavier