Showing posts with label Mandiant. Show all posts
Showing posts with label Mandiant. Show all posts

Monday, May 14, 2012

Threat Intelligence and APT Resources

This post is to share some of the resources I found interesting and useful recently. In addition I would like to thank my friends who interacted with me in the past and also work hard to fight cybercrime and Internet threats in general.

(in random order)

Thanks to Mila from contagio dump blog for linking to my blog from your APT page, which I also recommend reading. Also very useful is the list of browser exploit packs and all the great analysis of targeted attacks.

Thanks Keith for mentioning my tweets on your blog (Thanks for Sharing and Indicators) and for the great work in posting IOCs.

Thanks Kyle for mentions on your blog post Introduction to the Collective Intelligence Framework. I definitely recommend checking out CIF.

Thanks Mandiant for all your free tools (Redline, IOC-Finder etc.), great resources (M-unition blog, webinars) and interesting M-Trends reports.

Thanks Securosis for all the great free resources (Malware Analysis Quant etc.) and research papers published.

Thanks Command-Five for great research papers and C5 SIGMA free network analysis tool.
Command and Control in the Fifth Domain

Here are some blog posts about APT that I can recommend reading:

Eric Huber's blog post To APT or Not To APT?

Mike Cloppert's blog series on SANS computer forensics
Security Intelligence: Introduction (pt 1)
Security Intelligence: Introduction (pt 2)
Security Intelligence: Attacking the Kill Chain
Security Intelligence: Defining APT Campaigns

Update 2012-05-25: here are some more interesting papers that I enjoyed.

Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains [PDF]

Detecting Targeted Malicious Email through Supervised Classification of Persistent Threat and Recipient Oriented Features (Dissertation by Rohan Mahesh Amin, 2011)

Crouching Tiger, Hidden Dragon, Stolen Data [PDF]

Occupying the Information High Ground: Chinese Capabilities for Computer Network Operations and Cyber Espionage [PR]

The Chinese People's Liberation Army Signals Intelligence and Cyber Reconnaissance Infrastructure


So how do you share your threat intelligence with others and how / where do you find it online?

I've been tweeting some indicators in the past and collected some of these tweets on storify "malware intelligence". I've also created IOCs for Ponmocup and other malware (Zeus, debugger persistence and more) and posted them on Mandiant's forums and ioc.forensicartifacts.com.

I will update this post eventually with new, more recent resources and infos available.

If you find this blog useful consider linking to it from your blog (what, you don't have one!? Why not?) or tweet about it.

If you know other useful blogs or resources not mentioned here (or on my recommended blogs list) please let me know.

Thanks for reading all the way to the end ;-)

Saturday, November 19, 2011

Finding Malware and APT activities

Updates and feedbacks will be posted as comments below (unless I chose otherwise)

There are two ways to find infected or breached systems that I know of:
First, looking for known (or suspicious) command and control (C&C) traffic on the network. Second, looking for known bad or suspicious indicators on the hosts.
Well, there's actually a third one, combining the two together.

Indicators of Compromise

Mandiant's Indicators of Compromise (IOC) provide a way to describe host and network based indicators of malicious activity or traits.
IOC Editor is free software to create IOC's. And there's even a free software, IOC Finder, to check hosts for signs of infection. However, IOC Finder has a limited capability of checking for network based indicators on hosts. The commercial product MIR should have much greater network based capabilities I assume.
For sharing IOCs I found these two sites, openIOC and Mandiant's forums about IOC Finder.
Thanks Mandiant for all your great free software and resources!

Network based indicators

Another solution that looks very promising is Damballa's Failsafe, which looks for known bad or suspicious network traffic (DNS, proxy, egress firewall).
There are some demo videos online available with free registration.

Something similar seems to be available from Trisul Networks Analytics. A limited version is available for free. The plugins Badfellas, GeoIP and URLFilter look interesting and promising.

If you have experience with on of these products or know other similar, I'd be interested to hear about.

Any network based solution I guess is only as good as the intelligence of known bad or suspicious patterns to look for.
For some IDS based open source solutions, you might find
Richard Bejtlich's blog post "Seven Cool Open Source Projects for Defenders" interesting.

Host based indicators

The host based approach is to look at the memory or disk (binaries, registry, services etc.) for known malware or suspicious patterns. There are certainly many ways to do this besides the already mentioned solutions from Mandiant (and HBGary in a previous post).
Other free tools from Mandiant to check out are Memoryze, Audit Viewer and Redline to inspect memory for malicious or suspicious signs.

David Hoelzer has some interesting screencasts and blog posts (inlucding scripts) about finding signs of infections.

# 19 : Detecting Signs of APT and Malware
# 18 : Detecting APT and Malware through Baseline Auditing

Detecting Malware & APT Like Threats - Domain Wide File Finder
Detecting APT and Other Zero Day Malware through Service Auditing

There are also some open source projects like MIR-ROR, Rapier and probably others I haven't looked at. The two mentioned above haven't been active for a while now.

Feedback welcome

If you have corrections, suggestions or other feedback, please contact me (toms.security.stuff at gmail dot com).

If you found my blog other than from my Twitter profile, feel free to follow me there (@c_APT_ure)



Saturday, August 13, 2011

Lots has hAP(T)ened since... Kill those Shady RATs...

Well, it's been a long time since my last post and lots has happened since. Where should I start...

Earlier this year there were details released about Operation Night Dragon.

Mandiant released its second M-Trends report ("when prevention fails"), also mentioned on Businesswire. There were also some new, interesting "State of the Hack" and "Fresh Prints of Malware" presentations.

And most recently, there was lots of news about the "Operation Shady RAT".
Read Ira Winkler's article about it and make your own opinion.
I'd like to cite one paragraph of it:
"This is the root of the problem with how security vendors are dealing with the chronic issue of APT. They treat their customers' misery as their own intellectual property. Companies that investigate APT-related attacks rarely share their findings. They don't exchange information about the most recent malware obfuscation techniques, the best methods to identify compromised systems, the newest malware signatures, etc. Instead, they keep most of the information to themselves and treat it as a competitive advantage. What sharing there is falls far short of what would be required to encourage a robust response capability."
So what are Indicators of Compromise (IOCs) good for? Well, if they only get used by one security company, they can't reach the full potential.
Or are IOCs widely used and shared and I just don't know about it? Please let me know.

And then there's yet another interesting paper linked in there, which I've previously found, but haven't fully read yet.
"Far more information about this sort of thing came out in 2009, when The US-China Economic and Security Review Commission released a Northrop Grumman-prepared report called "Capability of the People's Republic of China to Conduct Cyber Warfare and Computer Network Exploitation". That paper is infinitely more informative than anything that any security company has been willing to disclose."
Well, now it's time to read it. (before it gets too outdated)


Friday, September 3, 2010

Mandiant's "Indicator of Compromise" (IOC) -- Part 2

Well, lots has happened since my last blog post. I'll try to focus on the things about APT and IOC that might interest you.

Mandiant had some interesting presentations about IOC and released the free tool IOCe to create them. There's also a forum about OpenIOC.
So there's the long overdue update on IOC.

Lots of other interesting things to talk about... as soon as I find time to write more :-)



Friday, April 9, 2010

Mandiant's "Indicator of Compromise" (IOC)

There's another interesting approach from Mandiant:

Combat the APT by Sharing Indicators of Compromise (IOC)

"At DoD CyberCrime 2010 MANDIANT will formally release this format and tools to leverage it in your investigations today. We’ll have full coverage of the release on M-unition – stay tuned."

There's also a Google Group about IOC. But are there any tools available yet, or any IOC's?

I'll update when I find out.


Sunday, March 28, 2010

Commercial products against APT -- useful or useless?

If money is not an issue to your company...

Here are some commercial products that could help in identification (and possibly remediation) of APT infections:

If you have experiences with these products or know other solutions along this line, please contact me.

In this blog I would like to explore how to identify APT infections with freely available tools (like the one's from Mandiant and others) and maybe custom scripts.

Mandiant's webinar "Fresh Prints: Malware Behaving Badly" covers some details that I would like to dive into. The "Malware Rating Index" (MRI) in the free software Audit Viewer sounds interesting.

*** Disclaimer: I'm not affiliated with any of the companies linked in this blog ***