Ben Reardon (@benreardon) 's Twitter Profile
Ben Reardon

@benreardon

@[email protected] , Security Researcher, works at Corelight. View are my own, etc

ID: 24290590

linkhttps://datavizcomau.wordpress.com calendar_today14-03-2009 00:22:07

462 Tweet

691 Takipçi

275 Takip Edilen

Joakim Kennedy (@joakimkennedy) 's Twitter Profile Photo

Chinese #APTs are currently very active. Here is a technical analysis on a #Linux backdoor with kernel level #rootkit used one of them... intezer.com/blog/malware-a… 👏 Avigayil Mechtinger

Ben Reardon (@benreardon) 's Twitter Profile Photo

Detecting Linux based C2 ‘RedXOR’ on the wire. I wanted this to be like a tutorial/example of how you can use Zeek’s state keeping functionality. corelight.blog/2021/04/20/det… #RedXor #DFIR #Zeek #C2 #RHEL

Ben Reardon (@benreardon) 's Twitter Profile Photo

Yet more content from the Labs team Corelight. A Zeek package and Suricata rule for detection of CVE-2021-31166 - a wormable Windows HTTP Protocol Stack vulnerability. This detects the current publically available POC expoit. enjoy! github.com/corelight/CVE-… Anthony Kasza

Ben Reardon (@benreardon) 's Twitter Profile Photo

A follow up from Corelight Labs team on the HTTP vuln #CVE-2021-31166. Some Insight into our Zeek and Suricata detections, plus the evolution of the threat with winRM being a vector on TCP port 5985. corelight.blog/2021/05/27/det… Aaron Soto Anthony Kasza Alex Kirk Paul Dokas

Ben Reardon (@benreardon) 's Twitter Profile Photo

A Zeek package for detection of the recent Apache path traversal bug in 2.4.49 and 2.4.50 CVE-2021-41773 github.com/corelight/CVE-… . The notice includes a snipit of the POST content for handier-than-pcap triage - when the target is things like /bin/sh

Ben Reardon (@benreardon) 's Twitter Profile Photo

TIL the patent on #SSH fingerprinting “HASSH” I submitted while Salesforce was granted after a few years in the USPO queue. Guess I'm now a legit inventor! hat tip to my co-inventors/pals Adel Ka John Althouse Jeff Atkinson #shouldersofgiants #DFIR #NDR #Zeek patents.google.com/patent/US11095…

Corelight (@corelight_inc) 's Twitter Profile Photo

You may not think CVE-2021-42292 can be detected at the network level, but our @Corelight_inc Labs team (big shout-out to Keith J. Jones, Ph.D. Alex Kirk @ynadji Ben Reardon) shows you how on the blog today: corelight.com/blog/detecting… #CyberSecurity #DFIR #ThreatHunting #OpenNDR

You may not think CVE-2021-42292 can be detected at the network level, but our @Corelight_inc Labs team (big shout-out to <a href="/keithjjones/">Keith J. Jones, Ph.D.</a> <a href="/alexgkirk/">Alex Kirk</a> @ynadji <a href="/benreardon/">Ben Reardon</a>) shows you how on the blog today: corelight.com/blog/detecting… 
#CyberSecurity #DFIR #ThreatHunting #OpenNDR
Ben Reardon (@benreardon) 's Twitter Profile Photo

Some #log4j detection content from Corelight Labs team. Creates notices, PLUS a bonus log4j.log containing payload IP:port:uri that is used to watch for subsequent traffic to (read: pwned). corelight.com/blog/simplifyi… and the code github.com/corelight/cve-…

Ben Reardon (@benreardon) 's Twitter Profile Photo

Detecting second stage/callback #log4j payloads. AKA when Java GETs Java, you’re going to want to know about it… The third installment of log4j open sourced content from the Corelight Labs Team. corelight.com/blog/detecting… #Log4Shell #DFIR #zeek

Ben Reardon (@benreardon) 's Twitter Profile Photo

Detection of vulnerable servers and exploit attempts against #OpenSSL punycode vulnerability #CVE-2022-3602. github.com/corelight/CVE-… Corelight

Ben Reardon (@benreardon) 's Twitter Profile Photo

One of my favourite moments at hacker summer camp was catching up with my old mate Adel Adel Ka and exchanging country gifts. Make sure you check out his talk at Defcon!

One of my favourite moments at hacker summer camp was catching up with my old mate Adel <a href="/0x4D31/">Adel Ka</a> and exchanging country gifts. Make sure you check out his talk at Defcon!
Ben Reardon (@benreardon) 's Twitter Profile Photo

Detect the brand new "SSHAMBLE" scanner (just dropped by HD at Blackhat USA) with this fingerprint: hassh=c6c8b23b1c966dad1173df11c4e4f431 . More on this later! Corelight customers already have the hassh package available, we also open source it here: github.com/corelight/hassh.