PeterM🌻 (@altshiftprtscn) 's Twitter Profile
PeterM🌻

@altshiftprtscn

Work in DFIR, fighting the good fight. Don't go 5 minutes without saying ransomware.
Created as a failsafe: infosec.exchange/@AltShiftPrtScn

ID: 888301897836367872

linkhttp://sophos.com/rapidresponse calendar_today21-07-2017 07:37:31

1,1K Tweet

2,2K Followers

102 Following

PeterM🌻 (@altshiftprtscn) 's Twitter Profile Photo

This makes me want to be Canadian. I know nothing about counterfeting passports but surely this has got to be at the extreme difficulty end of the scale. youtube.com/watch?v=GvoD0i…

Sophos X-Ops (@sophosxops) 's Twitter Profile Photo

Last year, after stopping a #ransomware attack, X-Ops discovered the attackers had managed to sabotage endpoint protection tools using a malicious driver signed by Microsoft. We reported the issue the Microsoft and continued to investigate.

CRN (@crn) 's Twitter Profile Photo

Cybersecurity vendor Sophos’ new retainer option offering seeks to expedite cyber incident response engagements and stand out from other retainers with its fixed-cost agreement, Sophos President Joe Levy told CRN. Sophos Partners bit.ly/3QQVCUZ

PeterM🌻 (@altshiftprtscn) 's Twitter Profile Photo

If you are using Cisco AnyConnect VPN please enforce MFA the #Akira / #Powerranges ransomware lot are heavily targeting them at the moment for initial access.

Gi7w0rm (@gi7w0rm) 's Twitter Profile Photo

⚠️Watch out for your #SharePoint environments in the upcoming weeks... There is now enough info out there to implement a full #exploit chain using #CVE-2023-29357 and #CVE-2023-24955. If SharePoint is anything like Exchange in patchratio we are approaching dangerous waters.

PeterM🌻 (@altshiftprtscn) 's Twitter Profile Photo

#HuntersInternational IOCs - Cobalt: virustotal.com/gui/ip-address… & virustotal.com/gui/ip-address…, Other C2s: virustotal.com/gui/ip-address… & virustotal.com/gui/ip-address…. Rclone->SFTP: virustotal.com/gui/ip-address…. Filnames include vmware.exe, vmware.dll, vm.dll in ProgramData and Windows\Temp.

Brett Callow (@brettcallow) 's Twitter Profile Photo

#AlphV files an SEC complaint against #MeridianLink for not disclosing a breach to the SEC #Ransomware databreaches.net/alphv-files-an…

PeterM🌻 (@altshiftprtscn) 's Twitter Profile Photo

Working in DFIR and dealing with encrypted VMDKs? here is how we have been extracting forensic evidence from them. Well done to everyone involved in developing these methods. news.sophos.com/en-us/2024/05/…

Mark Loman (@markloman) 's Twitter Profile Photo

🚨 Ransomware still beats up-to-date protection - even decade-old strains! Want to know how? See PeterM🌻 in "Know the Enemy". Wednesday, August 7, 11:25 am – 12:15 pm (Business Hall Theater A) More: blackhat.com/us-24/sponsore… #BlackHat

Curated Intelligence (@curatedintel) 's Twitter Profile Photo

⚠️PSA: Curated Intel DFIR has noticed a new trend among Akira Ransomware cases in Summer 2024. For a while, Akira has been exploiting Cisco ASA devices. ➡️ They are now targeting SonicWall SSL-VPNs for access with no MFA (!) and weak passwords (!). Other TTPs remain the same 🔍

PeterM🌻 (@altshiftprtscn) 's Twitter Profile Photo

I get asked a lot "how do you prepare for a ransomware attack". I always give the same answer; have an Incident Response Plan and practice it in advance. But how do you do that easily? well I highly recommend the NCSC's Exercise in a box, it's free! exerciseinabox.service.ncsc.gov.uk

Kostas (@kostastsale) 's Twitter Profile Photo

Another great article full of technical info!👏 Great job by Morgan Demboski and security_dumpster as always for this blog! Chinese State-sponsored TAs have become the punching bag for Sophos this year lol 😂 It inspired me to illustrate how they must be feeling right now😆🎬👇

John Viega (@viega) 's Twitter Profile Photo

This is amazing! Sophos' transparency should be lauded; pretty much all big security vendors have swept things like this under the rug, but this shows the industry could be driving a lot more value if vendors were just willing to be accountable. sophos.com/en-us/content/…

PeterM🌻 (@altshiftprtscn) 's Twitter Profile Photo

Nice post about exfil tools: Ransomware-driven data exfiltration: techniques and implications blog.sekoia.io/ransomware-dri…