Responder 2.0 Released!
We have been slaving away long hours since early December last year, but we made it. The 2.0 release of Responder is released. It's amazing. Hard to believe, but it's been two years since we announced...
View ArticleThe Nature of Funded Threats
Most incidents of espionage are never reported - even though tens of investigations are currently underway as you read this. Without consolidated statistics it will be hard to really understand the...
View ArticleActive Reversing
I first presented active reversing in 2007 at the Blackhat show in Vegas. At that time, the concepts were mostly theory, backed by a few prototypes I demo'd during the talk. It's taken us three years...
View ArticleCyber Threat
I imagine cyberspace like in the movies, as points of light. It's like looking down from an airplane at night - mostly vast darkness but interspersed with brightly lit areas of activity. There is a lot...
View ArticleA dose of clarity for the "APT"
Finally a dose of clarity for the "APT". It is an overused word, one used to sell security products, even if these are the 'same' security products you have been using for the past 10 years. In his...
View ArticleArticle 19
Blackhat is almost here again! This has always been one of the coolest security shows with great research presentation. The show is a great place to catch up with friends and colleagues (most of whom I...
View ArticleIntel Validates the End Node
In the security industry, there is an obsession with the perimeter, which is why this Intel-McAfee announcement, at first glance, seems so surprising. McAfee represents visibility and control at the...
View ArticleMalware Persistence in the Cloud
The cloud is certainly going to change some things about malware infection. When a desktop is reset to clean state every time an employee logs in, you now have to wonder how malicious attackers are...
View ArticleCyber Conflict and State Power
There has been a rapid change in the global security paradigm. Cyberspace has fundamentally changed the stability between state and society. New conflict groups are not tied to any one state. There is...
View ArticleRootkit Evolution
Over the last few years HBGary has researched significant advancements in rootkit technology. We are pushing the envelope of what’s possible in the windows kernel. I’m glad to say that we haven’t seen...
View ArticleTwo new threat intelligence papers CSO's will want to read
Industrial Espionage in the Global Energy Market Since 2005, HBGary has been tracking variants of malware created and originated in China that indicate a complex cyber espionage operation targeting...
View ArticleIs APT really about the person and not the malware?
Maybe the “APT is person not malware” pendulum is swinging to the extreme. Understandably it’s a response to commercial enterprises being obsessed with pure-play malware detection. But what is the...
View ArticleStop PDF Exploits Cold
I’m happy to announce that HBGary has released another free tool, similar to the Aurora scanner and the Chinese RAT catcher tools we released in past months. This one isn’t looking for malware,...
View ArticleA Brief History of Physical Memory Forensics
Lately, we have been doing a lot of work around physical memory forensics. Recently, we released the free, community edition of our Responder™ product and plan to release the fourth generation of our...
View ArticleChanging APT Tactics: Remote-Access Tools vs. Stolen Credentials
Advanced Persistent Threats (APT) are adaptive, their tactics will cycle after an intrusion takes place. For example, an APT group may start to lean away from RATs (remote-access tools) and rely more...
View ArticleScripting with Responder™ Community Edition
One of the most powerful features of Responder (all three versions, including the free Community Edition) is the ability to write custom plugins. The entire application is basically a GUI over an API....
View ArticleAsymmetric Warfare and Cyber Terrorism
In the newly released document, “DoD Strategy for Operating in Cyberspace", the Pentagon states that “while the threat to intellectual property is often less visible than the threat to critical...
View ArticleCommand Line Programming with Responder PRO
One little known feature of HBGary’s Responder product is that it ships with the full source code to a command-line version. This command-line version of the product can be customized for automated...
View ArticleShady RAT is Serious Business
Ira Winkler makes some interesting points in his CIO article on Shady RAT. I tend to agree with his observation that security vendors spend too much energy infighting when we all should be facing a...
View ArticleInside an APT Covert Communications Channel
Note: I shortened the title of the post from "Inside an APT “Comment Crew” Covert Communications Channel" to "Inside an APT Covert Communications Channel". To be clear, multiple threat groups are using...
View Article