Matt B·Jan 1, 2024Bringing Back 100 Days of LCRestarting the 100DaysofLC series with a new lab and detection opportunities :)
Matt B·Apr 15, 2021Precedence to Remember: FBI Operation Removed Web Shells from Exchange Servers (Part 2)This post is Part 2 of a two-part series examining the April 2021 FBI operation to remove malicious web shells from hundreds of systems.
Matt B·Apr 15, 2021A Precedence to Remember: FBI Operation Removed Web Shells from Exchange Servers (Part 1)On April 13, 2021, we learned of what I believe will be monumental event for cybersecurity in the United States.
Matt B·May 29, 2019What Happens Before Hello?Identifying BlueKeep scanning and exploitation via RDP protocol analysis
Matt B·May 26, 2019pollen version 1.1 — Codename Tsim Sha TsuiNew release of pollen, including command-line and color features!
Matt B·May 16, 2019pollen — A command-line tool for interacting with TheHiveI’d like to introduce pollen, an incident response-focused, command-line tool for interacting with TheHive.
Matt B·Mar 15, 2019TheHive Scripting: Task ImportsLooking to import tasks into TheHive using the Python API? Here we go!
Matt B·Mar 22, 2017Morning Read: UNC Health Care Informs 1,300 Prenatal Patients of Possible Data BreachWelcome to the Morning Read, a daily post where I recommend and discuss a white paper, blog post, chapter of a book, or some sort of text I…
Matt B·Mar 22, 2017The Ken Johnson DFIR ScholarshipFor today’s post, I’d like to bring attention to the newly-announced Ken Johnson DFIR Scholarship. Created in partnership between SANS and…