Sunday, March 11, 2018

Infosec quotes - disable legacy features

“... Disable Windows Legacy  Features
- Disable WPAD
- Disable LLMNR
- Disable NetBIOS
- Disable Windows Scripting Host (WSH) File Extensions
- Ensure WDigest is disabled
- Remove SMB v1 support 
...”

https://twitter.com/securityfreax/status/972973395926188032?s=21 

Infosec quotes - whole org password reset

“... if you have to reset your whole orgs password, how do you calculate that cost? ...”


https://twitter.com/cowbellsteve/status/973001724964286464?s=21

Infosec quotes - brute login checker

“... With the appropriate login checker and proxy lists to call upon, crooks can turn a single password breach into multiple account breaches, and clean out dozens of accounts within hours of the compromise...”


https://twitter.com/malwaredev/status/972777216168939520?s=21 

Saturday, March 10, 2018

Infosec quotes - red team wins

“... As the Red Team, do we win all the time? Yes we do!  If blue teams improve their defenses, we win because they improve, even if we don't achieve Domain Admin
Remember we are trying to help and improve defenses, otherwise you are missing the point and no better than the attackers...”


https://twitter.com/tyler_robinson/status/972163551795167233?s=21 

Infosec quotes - rar file extension

“... The .rar extension should hopefully be a red flag for users...”


https://twitter.com/teoseller/status/972472251701452801?s=21 

Infosec quotes - threat hunting

“... Engaging in threat hunting means that you are taking a more proactive approach to cyber defense. It often begins with the assumption that, regardless of the defenses in place, that there is always the potential that there is a threat that may have evaded detection...”


https://twitter.com/shawnetuma/status/972506161902751744?s=21 

Infosec quotes - Powershell & sysmon

Powershell & sysmon logging to your SIEM is important for visibility .

“... Without logging ...in place, you won’t be able to detect a memory (RAM) only credential harvesting attack via PowerShell... A centralized logging solution is highly recommended for PowerShell and Sysmon logging...”

https://twitter.com/seanamason/status/971354430787457024?s=21