packet.zip

~/category/security

Security

142 articles

The Art of Ransomware

Ransomware may potentially be the biggest threat in 2016. Criminal organizations are making big money from ransomware. According to a Geek.com article by Lee Mathews, Cryptowall, a ransomware application, generated over $30 million USD for criminals. People simply pay to get their data back, a syste

Aamir Lakhani4 min read

Why I can’t win from a claw machine (and neither can you)

You’ve seen them. They are the cranes we use to try to snatch prizes, commonly referred to as claw machines. They are found in arcades, restaurants, and other establishments. Sometimes they have valuable prizes, and other times….not so much. In either case it is easy to get addicted to them. You thr

Aamir Lakhani4 min read

Mitre ATT&CK Con

We just got back from Mitre ATT&CK Con. Tony G and Packet.Zip were both impressed. Let's talk about creating and testing the ATT&CK framework.

Aamir Lakhani1 min read

Don't Jack my Crypto

Tony G and Packet.Zip discuss crypojacking - is it really a problem? How does it lead to greater security threats? What does it really mean for enterprise organizations? Join us for the Packet.Zip podcast

Aamir Lakhani1 min read

MITRE and RUNDLL

Aamir Lakhani and Tony G talk around MITRE ATT&CK methodology and malware embedded in DLL

Aamir Lakhani1 min read

Crypto Botnets

Aamir Lakhani and "Tony G" discuss the latest techniques in new botnets with hive like awareness.

Aamir Lakhani1 min read

Hunting the Hunter

Organizations of all sizes continue to be targets of cyber criminals and the threats that they present. However, some organizations are taking a proactive approach and are hunting for these threats. But what exactly is “threat hunting"? How does it fit into the SOC? Should my organization be threat

Aamir Lakhani1 min read

Advanced PowerShell Techniques using Magic Unicorn

Magic Unicorn is powerful tool that can be used to generate and bypass commercial antivirus (AV) detection methods. It allows an attacker to implement a PowerShell downgrade attack and inject shellcode directly into memory. It is based on Matthew Graeber’s PowerShell attacks integrated with bypass t

Aamir Lakhani5 min read

Meet Emily Williams – Fake social media ID duped security-aware IT guys

Security experts used fake Facebook and LinkedIn profiles pretending to represent a smart, attractive young woman to penetrate the defenses of a U.S. government agency with a high level of cybersecurity awareness, as part of an exercise that shows how effective social engineering attacks can be, eve

Aamir Lakhani6 min read