Quantcast
Channel: Learning Hub Archives - Unit 42
Browsing index pages (41 articles)
↧

False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity...

North Korean IT workers are reportedly using real-time deepfakes to secure remote work, raising serious security concerns. We explore the implications. The post False Face: Unit 42 Demonstrates the...

View Article


Unit 42 Looks Toward the Threat Frontier: Preparing for Emerging AI Risks

The Unit 42 Threat Frontier report discusses GenAI's impact on cybersecurity, emphasizing the need for AI-specific defenses and proactive security. The post Unit 42 Looks Toward the Threat Frontier:...

View Article


Unit 42 Attack Surface Threat Research: Over 23% of Internet-Connected...

Find out which industries have the most rapidly expanding attack surfaces from a survey of 260+ orgs in Unit 42’s 2024 Attack Surface Threat Report. The post Unit 42 Attack Surface Threat Research:...

View Article

The Contrastive Credibility Propagation Algorithm in Action: Improving...

Our novel contrastive credibility propagation algorithm improves on data loss prevention and has unique applications to sensitive material. The post The Contrastive Credibility Propagation Algorithm in...

View Article

Leveraging DNS Tunneling for Tracking and Scanning

We provide a walkthrough of how attackers leverage DNS tunneling for tracking and scanning, an expansion of the way this technique is usually exploited. The post Leveraging DNS Tunneling for Tracking...

View Article


Navigating the Cloud: Exploring Lateral Movement Techniques

We illuminate lateral movement techniques observed in the wild within cloud environments, including Amazon Web Services (AWS), Google Cloud Platform (GCP) and Microsoft Azure. The post Navigating the...

View Article

Intruders in the Library: Exploring DLL Hijacking

Dynamic-link library (DLL) hijacking remains a popular technique to run malware. We address its evolution using examples from the realm of cybercrime and more. The post Intruders in the Library:...

View Article

Logit-Gap Steering: A New Frontier in Understanding and Probing LLM Safety

New research from Unit 42 on logit-gap steering reveals how internal alignment measures can be bypassed, making external AI security vital. The post Logit-Gap Steering: A New Frontier in Understanding...

View Article


A Mega Malware Analysis Tutorial Featuring Donut-Generated Shellcode

A beginner-friendly tutorial on analyzing .NET malware teaches you how to use common tools, recognize techniques and understand infection chains. The post A Mega Malware Analysis Tutorial Featuring...

View Article


Muddled Libra’s Strike Teams: Amalgamated Evil

A look at the variance within Muddled Libra (aka Scattered Spider, Octo Tempest). Its lack of structure creates multiple teams with distinct skill sets. The post Muddled Libra’s Strike Teams:...

View Article

Muddled Libra: Why Are We So Obsessed With You?

Muddled Libra gets media attention due to its consistent playbook and unique use of vishing. The group's English fluency is another major factor. The post Muddled Libra: Why Are We So Obsessed With...

View Article

Wireshark Tutorial: Exporting Objects From a Pcap

This Wireshark tutorial guides the reader in exporting different packet capture objects. It builds on a foundation of malware traffic analysis skills. The post Wireshark Tutorial: Exporting Objects...

View Article

Exploring the Latest Mispadu Stealer Variant

Evaluation of a new variant of Mispadu, a banking Trojan, highlights how infostealers evolve over time and can be hard to pin to past campaigns. The post Exploring the Latest Mispadu Stealer Variant...

View Article


Threat Vector Podcast

About Threat Vector Threat Vector is the Palo Alto Networks podcast hosted by David Moulton, Unit 42's Director of Thought Leadership. The podcast features in-depth discussions with industry leaders,...

View Article

Wireshark Tutorial: Identifying Hosts and Users

When a host is infected or otherwise compromised, security professionals need to quickly review packet captures of suspicious network traffic to identify affected hosts and users. This tutorial offers...

View Article


Wireshark Tutorial: Display Filter Expressions

This is a tutorial about using Wireshark, a follow-up to "Customizing Wireshark – Changing Your Column Display." It offers guidelines for using Wireshark filters to review and better understand pcaps...

View Article

Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer

RedLine stealer harvests credentials and other data from a Windows host. Part one of this Wireshark tutorial analyzes RedLine traffic to determine what data was stolen. The post Crossing the Line: Unit...

View Article


Cobalt Strike Analysis and Tutorial: Identifying Beacon Team Servers in the Wild

We present new techniques that leverage active probing and network fingerprint technology to help you detect Cobalt Strike’s Team Servers. The post Cobalt Strike Analysis and Tutorial: Identifying...

View Article

Tor 101: How Tor Works and its Risks to the Enterprise

People use Tor for both benign and malicious reasons, but allowing Tor traffic on enterprise networks opens the door to security risks. The post Tor 101: How Tor Works and its Risks to the Enterprise...

View Article

dotnetfile Open Source Python Library: Parsing .NET PE Files Has Never Been...

The dotnetfile library extracts useful information from .NET PE files and can overcome common techniques malware authors use to break parsing. The post dotnetfile Open Source Python Library: Parsing...

View Article
Browsing index pages (41 articles)


Latest Images