<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[ilovesec]]></title><description><![CDATA[ilovesec]]></description><link>https://ilovesec.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!zIoO!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd39638a-b9af-4bbf-9d96-64dd56f7784f_1280x1280.png</url><title>ilovesec</title><link>https://ilovesec.substack.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 14 May 2026 18:07:27 GMT</lastBuildDate><atom:link href="https://ilovesec.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Joshua Morgan]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ilovesec@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ilovesec@substack.com]]></itunes:email><itunes:name><![CDATA[Joshua Morgan]]></itunes:name></itunes:owner><itunes:author><![CDATA[Joshua Morgan]]></itunes:author><googleplay:owner><![CDATA[ilovesec@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ilovesec@substack.com]]></googleplay:email><googleplay:author><![CDATA[Joshua Morgan]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Vegas and the Lucky Number 7]]></title><description><![CDATA[The Annual DEF CON trek]]></description><link>https://ilovesec.substack.com/p/vegas-and-the-lucky-number-7</link><guid isPermaLink="false">https://ilovesec.substack.com/p/vegas-and-the-lucky-number-7</guid><dc:creator><![CDATA[Joshua Morgan]]></dc:creator><pubDate>Tue, 02 Sep 2025 21:32:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z12I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Las Vegas. Early August. Every Year. Except that <em><strong>ONE</strong></em> year.</p><p>If you know me, you can expect you'll know where I'll be the first week of August every year: DEF CON!!</p><p>I've been absolutely blessed to have been able to attend every DC since 26 and always find myself rejuvenated afterwards. The connections, the new ideas, the camaraderie with like-minded people is amazing.</p><h1>A Year of Change</h1><p> This year was quite different and a somber experience at the con. I lost my brother earlier this year in a senseless situation. Another person I worked with, but consider a very good friend, mentor, brother - bind - passed. Bind is very much woven into the fabric of this industry and touched so many lives. At a time where I was at my lowest, he was able to help pull me out and give me encouragement to persevere. This year felt different.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z12I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z12I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 424w, https://substackcdn.com/image/fetch/$s_!Z12I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 848w, https://substackcdn.com/image/fetch/$s_!Z12I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 1272w, https://substackcdn.com/image/fetch/$s_!Z12I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z12I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png" width="792" height="1034" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1034,&quot;width&quot;:792,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1659369,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z12I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 424w, https://substackcdn.com/image/fetch/$s_!Z12I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 848w, https://substackcdn.com/image/fetch/$s_!Z12I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 1272w, https://substackcdn.com/image/fetch/$s_!Z12I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f65588e-f929-47d0-aa49-8681cf390ddb_792x1034.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>A Bit of Blue</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1spF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1spF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 424w, https://substackcdn.com/image/fetch/$s_!1spF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 848w, https://substackcdn.com/image/fetch/$s_!1spF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 1272w, https://substackcdn.com/image/fetch/$s_!1spF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1spF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png" width="1456" height="1185" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1185,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1305934,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1spF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 424w, https://substackcdn.com/image/fetch/$s_!1spF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 848w, https://substackcdn.com/image/fetch/$s_!1spF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 1272w, https://substackcdn.com/image/fetch/$s_!1spF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb5fd95-8656-43fa-8224-2d3ce998927d_1494x1216.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I was able to present again at <a href="https://www.blueteamvillage.org">Blue Team Village</a> for the third time (Incident Response 101: What Happens After the Hack?) to a crowded audience to kick off the start of DEF CON. The Blue Team Village entrusted ME to lead off the whole thing. I'm honored and can only hope I lived up to expectations. I'm always thankful for the ability to share what I learn, give back to the community and help shape new minds. Getting feedback that audience members found value in the content we provided is absolutely amazing!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_-un!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_-un!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 424w, https://substackcdn.com/image/fetch/$s_!_-un!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 848w, https://substackcdn.com/image/fetch/$s_!_-un!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 1272w, https://substackcdn.com/image/fetch/$s_!_-un!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_-un!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png" width="1456" height="1074" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1074,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5267922,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_-un!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 424w, https://substackcdn.com/image/fetch/$s_!_-un!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 848w, https://substackcdn.com/image/fetch/$s_!_-un!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 1272w, https://substackcdn.com/image/fetch/$s_!_-un!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edb3c30-fe28-4916-8102-08a182f00451_1850x1364.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Over the past year, I had the privilege to work alongside a great team of rock stars at Project Obsidian in Blue Team Village to help build the annual Blue Team Village <a href="https://ctf.blueteamvillage.org/">Project Obsidian Capture the Flag (CTF) competition</a>. Getting to create challenges to try to stump some of the brightest minds, while getting to teach blue team tactics along the way is exhilarating. Working alongside a great group helped so very very much!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b6N9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b6N9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 424w, https://substackcdn.com/image/fetch/$s_!b6N9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 848w, https://substackcdn.com/image/fetch/$s_!b6N9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 1272w, https://substackcdn.com/image/fetch/$s_!b6N9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b6N9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png" width="1176" height="462" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:462,&quot;width&quot;:1176,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1031552,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b6N9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 424w, https://substackcdn.com/image/fetch/$s_!b6N9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 848w, https://substackcdn.com/image/fetch/$s_!b6N9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 1272w, https://substackcdn.com/image/fetch/$s_!b6N9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bee42ff-f9ba-47eb-bd04-572e7e41944d_1176x462.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h1>All Tangled Up</h1><p>Not only did I get to help at BTV, I got to help out at Packet Hacking Village (PHV) during the con. My journey into the PHV began in 2021, thanks to my friend bind encouraging me to give back and volunteer. His lasting impression on me was to give back, to teach others what I know. I've tried to build upon that and give back wherever I can, and PHV is one of the outlets that I was able to sink my teeth into.</p><p>This DC, I was able to assist in two areas: Packet Inspector/Packet Detective and the Hardwired. PI/PD was amazing, as always. The sheer number of people who come to check out and work through the challenges never cease to amaze me. </p><p>Hardwired was different for me - I had never had the opportunity to help with that area in the five years I had been volunteering. Now I get to show others how to make Ethernet cables. How fun!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NSji!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NSji!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 424w, https://substackcdn.com/image/fetch/$s_!NSji!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 848w, https://substackcdn.com/image/fetch/$s_!NSji!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 1272w, https://substackcdn.com/image/fetch/$s_!NSji!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NSji!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png" width="960" height="670" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:960,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1168260,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NSji!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 424w, https://substackcdn.com/image/fetch/$s_!NSji!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 848w, https://substackcdn.com/image/fetch/$s_!NSji!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 1272w, https://substackcdn.com/image/fetch/$s_!NSji!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81bda609-7507-4b30-8d4e-c21f11c39390_960x670.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Luckily, years ago as part of my job, I had experience terminating RJ-45 cables, so I was able to slot in relatively easily to the operation. Interacting with people wanting to learn how to create a cable from scratch but starting from zero was pretty cool to experience. I had a great time getting to tell stories about my experiences with making cables, some of the history of cabling standards that I knew, and getting a surprise visit from my wife while doing so. It all made for an absolutely amazing experience for DC.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PaYL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PaYL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 424w, https://substackcdn.com/image/fetch/$s_!PaYL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 848w, https://substackcdn.com/image/fetch/$s_!PaYL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 1272w, https://substackcdn.com/image/fetch/$s_!PaYL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PaYL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png" width="1448" height="1526" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1526,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3424219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PaYL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 424w, https://substackcdn.com/image/fetch/$s_!PaYL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 848w, https://substackcdn.com/image/fetch/$s_!PaYL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 1272w, https://substackcdn.com/image/fetch/$s_!PaYL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74d1a464-6412-424f-bb02-91dda97b434e_1448x1526.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h1>I Didn't F It Up</h1><p>Another part of DC that I absolutely love are the evening events. For at least the past six years, Hacker Jeopardy has been a staple of my DC experience. I made Whose Slide Is It Anyways a new annual staple moving forward. What an amazing evening of fun - even if it was invaded by those who attempted to strip away the joy.</p><h1>But They Did</h1><p>It goes without saying that one apple can spoil the whole bunch. That's very much the truth. Many attendees are gracious, caring, kind. There are others who attend who perhaps should be better aware of how they treat others. Be better. Treat others with respect. Be Kind. It's honestly not that hard to be a good person.</p><h1>Luck?</h1><p>In the midst of everything going on, I managed to obtain what appears to have been a card from the famed &#8220;Black Badge Raffle&#8221; card game at DEF CON that was super unique. Here it is:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cZoR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cZoR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cZoR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cZoR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cZoR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cZoR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg" width="746" height="1054" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1054,&quot;width&quot;:746,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:277999,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cZoR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cZoR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cZoR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cZoR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d9d1fad-12b0-4861-8978-1a75787908d5_746x1054.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Thankfulness</h1><p>It goes without saying that all this isn&#8217;t possible without sacrifice. I am lucky beyond words to have someone in my life that encourages me and pushes me to do great things. Without her, I wouldn&#8217;t be where I&#8217;m at, nor could I be. I&#8217;m happy to have been able to share the DEF CON world with her the past five years. She&#8217;s dealt with my long nights working on something for DC and the crazy schedules while AT DC. Thank you for being there for me and keeping me focused on the bigger picture while keeping me grounded all along the way.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dDW5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dDW5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 424w, https://substackcdn.com/image/fetch/$s_!dDW5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 848w, https://substackcdn.com/image/fetch/$s_!dDW5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 1272w, https://substackcdn.com/image/fetch/$s_!dDW5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dDW5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png" width="1284" height="1054" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1054,&quot;width&quot;:1284,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2859171,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/172498473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dDW5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 424w, https://substackcdn.com/image/fetch/$s_!dDW5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 848w, https://substackcdn.com/image/fetch/$s_!dDW5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 1272w, https://substackcdn.com/image/fetch/$s_!dDW5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F210711ae-6ad6-4670-9637-a1bbefab536f_1284x1054.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Reflecting</h1><p>Overall, I think the experience was amazing. I find myself looking forward to the next DEF CON, ready to work alongside the amazing teams to build more materials to help teach/train newcomers in the field. If you've never had the opportunity to check out DEF CON, I encourage you to, should you ever have the means to. For its alleged faults, if you find the right crowd for you (and you&#8217;re not a jerkface), it can absolutely be a rewarding experience.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ilovesec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Six Tickets: The Ramblings of a Beaten Down SOC Analyst]]></title><description><![CDATA[My Journey in Security - and how life... finds a way]]></description><link>https://ilovesec.substack.com/p/six-tickets-the-ramblings-of-a-beaten</link><guid isPermaLink="false">https://ilovesec.substack.com/p/six-tickets-the-ramblings-of-a-beaten</guid><dc:creator><![CDATA[Joshua Morgan]]></dc:creator><pubDate>Mon, 26 May 2025 03:04:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YHOL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YHOL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!YHOL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!YHOL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!YHOL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YHOL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!YHOL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!YHOL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!YHOL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!YHOL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69f13c51-1d50-47bc-a452-6823800777bf_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Beginnings</h1><p>A lot can be said about first impressions, but far more can be said about perseverance. I take a great deal of pride in the type of work that I do and strive to be the best at what I do at a certain moment in time. I don&#8217;t think I&#8217;m better than anyone else - I just know I&#8217;m going to always work hard to get the best results, no matter what I&#8217;m going through. Or so I thought.</p><p>Let&#8217;s go back to 2011 - I decided to go back to school to get my Associates in IT. I&#8217;ve always been a tech guy for as long as I can remember, so it made sense. After working two jobs and attending classes, I graduated in 2014 with my shiny Associates degree. I had no clue what I wanted to be, but knew it had to be in IT/Tech. Got a job as a contract help desk employee at a large manufacturing facility in Southern California. I thought to myself: &#8220;This is my big break - to finally get a job in something that I&#8217;m good at!&#8221; Little did I realize that some events in 2014 would turn out to change the trajectory of my career path&#8230; in a big way.</p><p>In late 2013, news of the huge Target security breach came out. I had heard about this and then the Home Depot credit card breach in early 2014, but figured these were one-off situations. I started reading up more on the Target incident and became intrigued at the method of how the attack occurred. I had always considered myself to be a security-minded person, but to see how things played out with Target made me want to dive in further.</p><h1>Education</h1><p>On a whim, I decided to think about looking into further education as it became more and more apparent that an Associates degree would not get me very far without the real work experience - at least not far enough with respect to financials. I ended up starting the enrollment process for my Bachelor of Science in IT Security, aiming to start at the beginning of 2015. I was able to get about half of my program credits transferred in from my Associates degree. This would be a cakewalk.</p><p>HOLY SHIT. I hadn&#8217;t considered that an online-only school would require more from me than my experiences at the local Community College. I struggled working full-time (and often overtime) and attending school full-time. That along with being married and trying to maintain a relationship was not simple or easy. They say if you want something bad enough, you&#8217;ll make sacrifices to get it. I wanted that degree, I am going to get that degree.</p><p>By the middle of 2016, I was wrapping up my degree! I&#8217;ve done it. I got my Bachelors, finally! But part of me wondered, was there an opportunity for more? I&#8217;m still working as a Help Desk employee and while I was happy to work for the company I was contracted out to, the lack of raises or even health benefits was something that gave me pause. One benefit that I leaned on for my Bachelor program was tuition reimbursement. I was able to get a portion of my payments reimbursed by my employer - great! However, would they finance me furthering my education in obtaining a Masters in Cybersecurity? The answer, surprisingly, was &#8220;yes&#8221;.</p><p>Quite possibly easier than requesting a day off from work, my employer approved my plan to continue attending college and directly progress towards a degree in Cybersecurity.</p><p>I took the next year and a half to progress through my Masters program - I had already known the expectations and knocked the courses out. I started building an appreciation for the security world and everything in between. I always liked tinkering with things, making things do things they weren&#8217;t supposed to do, pushing boundaries.&nbsp;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new blogs and support my work. Thank you for reading!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Above and Beyond - But Ghosted</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZBus!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZBus!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 424w, https://substackcdn.com/image/fetch/$s_!ZBus!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 848w, https://substackcdn.com/image/fetch/$s_!ZBus!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBus!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZBus!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1548171,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/164450557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZBus!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 424w, https://substackcdn.com/image/fetch/$s_!ZBus!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 848w, https://substackcdn.com/image/fetch/$s_!ZBus!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBus!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa85d0360-606e-47ca-8eec-c3e1c83f4fda_1912x1274.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I graduated in 2018 - I was extremely pleased with getting the opportunity to say I had my degrees. There was just one slightly major issue: who is going to hire a guy with no security experience, no security project background, a paper-holding wanna-be hack that only has Help Desk experience? All the places I applied to either gave the &#8220;we&#8217;ve selected a candidate that better fits our needs&#8221; email or the good old ghosting.&nbsp;</p><p>I was great at what I did working for the Help Desk. People liked me because I didn&#8217;t treat them &#8220;like most IT people&#8221; - whatever that meant. I just genuinely enjoy helping teach people about technology and conveying related concepts in a way they can better understand.&nbsp;</p><p>I also enjoyed getting to do special projects for the company: I would work on their phone systems, help plan tech upgrades, refurbish equipment. Mostly things not necessarily associated with Help Desk life. One such thing was helping the network team scope out projects before they made changes. They asked me to go out to Las Vegas in August 2018 to check out a new facility they would be implementing appliances to, and I jumped at the opportunity. VEGAS! Hell yeah I&#8217;m down to go.</p><p>By this time, I am engrossed in the security world, I&#8217;m checking out subreddits, web forums, Twitter, you name it. I took the trip to Las Vegas on a Wednesday-Friday for the job. Unbeknownst to me, it just so happened that this was the week of DEF CON 26. When I realized this, I had to attend. Another request to my employer got another approval to attend this convention. It was the weekend I attended DEF CON 26 that solidified my love for the security world.</p><h1>I made it&#8230;</h1><p>Fast forward to the beginning of 2019, I landed my first security role as a SOC Analyst - someone decided to take a risk on me. For the most part, the first three quarters of 2019 were amazing. I got a job in a role that I had been trying so very hard to get. My morale did fall when the majority of my colleagues left for better opportunities, but overall I got to work in my field!&nbsp;</p><p>Then it hit me - I was thrown into a role in which I had no real direction, no real experience, and no real power to make positive changes. I did get to attend DEF CON 27, which was nice, and things appeared to be going well...until they weren&#8217;t.</p><div><hr></div><h1>Recognizing where I came from</h1><p>Life is hard, finding who you are can be an absolute struggle.&nbsp;</p><p>My parents divorced when I was seven or eight, my mom remarried quickly after and sent me and my siblings on a journey through hell. I'll spare specific details, but the in the end I ended up in a temporary "orphanage" home for a week and then foster care for about nine years.</p><p>I experienced a lot, but thankfully I learned some hard lessons in making the most of what you have and being thankful you have it.</p><p>What does this have to do with security, you ask?</p><p>My goal if nothing else is to tell you that no matter what you've come from, who you were, what you've done doesn't have to define who you are now.</p><p>Many of the foster children I grew up with were extremely troubled, some ended up in prison, others homeless, struggling. I very well could have been a statistic. Plainly stated, we all have our history. What we do with our future is what matters most.</p><div><hr></div><h1>&#8230;and then the walls came tumbling down</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PAya!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PAya!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PAya!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PAya!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PAya!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PAya!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg" width="480" height="445" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:445,&quot;width&quot;:480,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26547,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/164450557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PAya!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PAya!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PAya!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PAya!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F968bed85-7e2c-4555-a3c6-b34b6df022f0_480x445.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Life fell apart quickly for me after DC27; my marriage fell apart, my mom died, then the dumpster fire of 2020 happened.</p><p>I wasn't engaged in work; I loved being in the security world. I wanted to do more, to make an impact, but at every chance I was shot down by other teams I worked with, because they didn't have time to do anything about what I detected. At one point I figured there was no point to my role - what did it matter what I did anyways. Even if I find something substantial, it's not like anyone would do anything about it anyways.</p><p>To add insult to injury, I got moved over to a team that had been known as hard nosed and blunt at the beginning of the pandemic. I was positive I was out the door. I started working with a new member of the team that pushed me to think differently and encouraged me to go against the grain. I started to get more involved, but I was still not fully there.&nbsp;</p><h1>Unexpected Support Sources</h1><p>I remember getting a call from my new manager a few weeks into being a part of the team. I expected to be berated for something I had done since the manager had a reputation of being very hardnosed, but instead the following was said "hey, I see you're struggling a bit with some of the work you've been doing - is there anything I can do to help you or assist you to get your numbers up?" I was actually taken aback by this - I had not expected support, only criticism and negativity. That's all it took for me to realize maybe there was another level I could take myself to.</p><p>That call made me realize a few things:&nbsp;</p><ol><li><p><code>People see the effort you put into your work.</code></p></li><li><p><code>Don't always allow other people's opinions to deny giving others a chance to prove to you who they are or how they operate.</code></p></li><li><p><code>I need to step up my fucking game and produce results.</code></p></li></ol><p>Truth is: it was a wake up call. Stop feeling sorry for yourself, and be the security superstar you know you can be.</p><p>I think my manager saw something that I didn't initially see in myself: I can be a leader, an influencer, and most of all&#8230; a teacher.</p><p>I would later find out that I had been negatively viewed because of my poor work ethic. I had earned the moniker of &#8220;Six Tickets&#8221; from previous management - and this wasn&#8217;t a badge of honor. To find that someone thought that I would only close six tickets <em><strong>a week</strong></em> in the SIEM absolutely crushed me. To know this originated from someone who had claimed they were on my side? Of course I'm not going to give a shit when management tells me there's nothing they can do because they don't have the manpower to further investigate an issue I found every single time I found one.</p><h1>Defining Me</h1><p>I made it my goal to persevere and prove that wasn't me, it wasn't going to define me, just like I wasn't going to let being a former foster child from a broken marriage define who I am today.</p><p>From my experience I give the following advice to managers getting handed a new team:</p><ol><li><p><code>Don't always take things at face value, you might not know history of an under-performer or the circumstances that led them there.</code></p></li><li><p><code>Don't be afraid to push for better, sometimes that's what people need to get them moving.</code></p></li><li><p><code>Do find out the strengths of the worker.</code></p></li></ol><p>Saying this, however, some workers might not be able to handle the pressure, but every now and then you'll end up with a potential gem on your hands.</p><h1>Finding a Voice</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ran4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ran4!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 424w, https://substackcdn.com/image/fetch/$s_!ran4!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 848w, https://substackcdn.com/image/fetch/$s_!ran4!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 1272w, https://substackcdn.com/image/fetch/$s_!ran4!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ran4!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif" width="500" height="260" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Life finds a way. - Reaction GIFs&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Life finds a way. - Reaction GIFs" title="Life finds a way. - Reaction GIFs" srcset="https://substackcdn.com/image/fetch/$s_!ran4!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 424w, https://substackcdn.com/image/fetch/$s_!ran4!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 848w, https://substackcdn.com/image/fetch/$s_!ran4!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 1272w, https://substackcdn.com/image/fetch/$s_!ran4!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F654c4cfd-5f4d-4ec6-8d1d-7de91626bc1a_500x260.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first few months working with the new team was brutal, in a sense. I'm not normally a vocal person, I tend to be an introvert and keep to myself. What better way to make me uncomfortable than to make me the center of attention on team calls.&nbsp;</p><p>You either sink or you swim in that sea, and I'm not going to turn down a challenge.</p><p>It was yet another time for self reflection. I realized, hey my work is being recognized, and yes we now have teeth to do the job right.</p><p>Over the next few months I learned to become more assertive, to trust my instincts, and to strive for excellence. I also learned the power of sharing your knowledge and experience with others - this is key. I've been extremely blessed to have met people in this industry that encourage and educate me constantly. I want to be able to share what I've learned with others like those before me.</p><p>To the coworker that inspired me to push through - thank you so much.</p><p>To the manager that got me outside of my comfort zone - thank you as well.</p><p>I&#8217;ll keep telling myself &#8220;Don&#8217;t be &#8216;Six Tickets&#8217;&#8221; forever.</p><h1>Final Thought</h1><p>I encourage you to share your knowledge, educate the new incoming security workers. We are such a small tight knit community, but we have room for so much more.</p><h1>Connections</h1><p>Thank you for taking the time out of your daily life to read this. If any of this resonates with you, I encourage you to reach out and connect with me:</p><ul><li><p>Website: <a href="https://www.ilovesec.com">https://www.ilovesec.com</a></p></li><li><p>BlueSky: <a href="https://bsky.app/profile/ilovesec.com">https://bsky.app/profile/ilovesec.com</a></p></li><li><p>Mastodon: <a href="https://infosec.exchange/@Samunoske">https://infosec.exchange/@Samunoske</a></p></li><li><p>Github: <a href="https://github.com/samunoske">https://github.com/samunoske</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/in/thejoshuamorgan">https://www.linkedin.com/in/thejoshuamorgan</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[nMap Explorations - A Great Time - DEF CON 31 (Blue Team Village)]]></title><description><![CDATA[My Talk from DEF CON 31 in 2023]]></description><link>https://ilovesec.substack.com/p/nmap-exploration-a-great-time-in</link><guid isPermaLink="false">https://ilovesec.substack.com/p/nmap-exploration-a-great-time-in</guid><dc:creator><![CDATA[Joshua Morgan]]></dc:creator><pubDate>Fri, 11 Aug 2023 00:21:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ESE-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ESE-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ESE-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ESE-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ESE-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ESE-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ESE-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;My Talk from DEF CON 31 in 2023&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="My Talk from DEF CON 31 in 2023" title="My Talk from DEF CON 31 in 2023" srcset="https://substackcdn.com/image/fetch/$s_!ESE-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ESE-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ESE-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ESE-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c0ace4-9e20-41af-b1f0-7da53386245d_1280x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>(n)Map Exploration: A Great Time in Remote Destinations</h2><p>Let&#8217;s take a look at activity within a corporate environment. Can we find actions that stand out or might be suspicious?</p><h1>Video Walkthrough</h1><div id="youtube2-kKeV-Es17dc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;kKeV-Es17dc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/kKeV-Es17dc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1>Overview</h1><h2>What will we learn?</h2><p>There are a number of concepts we will go over and learn in this walkthrough:</p><ul><li><p>What is reconnaissance in a security/threat hunt context?</p></li><li><p>What are some ways that adversaries can identify points of exploitation within an environment?</p></li><li><p>What are some commonly abused services that adversaries use?</p></li><li><p>How can we walk through the thought process associated with a Threat Hunt from hypothesis to tangible results?</p></li><li><p>What tools do we have at our disposal and what can we do with them?</p></li><li><p>Can we go deeper and find out more after validating our hypothesis?</p></li></ul><h1>Initial Required Concepts</h1><p>In order to dive into the hunt, we need to have some baseline information to better understand what we are seeking to find. Let us take a look at some of these now.</p><h2>What is reconnaissance?</h2><p>In a security context, reconnaissance is the process of gathering information about a particular target. It&#8217;s important to recognize that reconnaissance is <em>not</em> always malicious in nature. It is not unexpected or unheard of to see some tools in use within the organization that perform this activity. Reconnaissance is often utilized prior to potential exploitation as an adversary would build out a &#8220;map&#8221; of items that exists in a particular environment.</p><h2>What are some ways that adversaries can identify points of exploitation?</h2><p>An adversary can begin with some basic web searches to find information that is freely available on the internet to begin building a model associated with a particular &#8220;entity&#8221; - often in this context the &#8220;entity&#8221; is an organization. We call this freely-available information on the internet Open Source Intelligence, or OSINT for short. There is often a limit to the usefulness of the information provided by OSINT resources as it pertains to actively using it against an entity.</p><h2>What if the adversary is already connected to the network?</h2><p>If the adversary already has a limited foothold into the network, there are more effective things that the adversary can do:</p><ul><li><p>Build a network map of the environment - what systems are there? what operating systems are there?</p></li><li><p>Identify services that the adversary could then utilize to move deeper into systems/the network.</p></li><li><p>Exfiltrate data</p></li></ul><p>From a security point of view, we call this building a list of systems &#8220;Enumeration&#8221;</p><h2>What tools could be used to do this enumeration within the network?</h2><p>Some tools for this include:</p><ul><li><p>Network Scanning Tools: Used for building out systems associated with a particular network, including open ports, operating system type, and more. A few examples of applications in this group include the popular tool nmap and as well masscan.</p></li><li><p>Vulnerability Scanners: OpenVAS/Nessus are two vulnerability scanners that could theoretically be used to identify hosts within a network.</p></li><li><p>Built-in OS Tools: The ping tool could be used to identify available hosts within a network, though</p></li></ul><p><strong>Now that we understand more about reconnaissance, let&#8217;s put these concepts together to see if we can build a Threat Hunt with these ideas in mind!</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you&#8217;re interested in keeping in touch and following my posts, feel free to subscribe free:</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Threat Hunting</h1><h2>What is Threat Hunting?</h2><p>Threat Hunting (TH) is a process of being proactive of unveiling unknown-knowns and unknown-unknowns to better our security posture</p><h1>Hypothesis</h1><p>In order to begin the Threat Hunt, we need to have a reason to start the hunt. To start, we will need to come up with a hypothesis.</p><h3>What is a hypothesis?</h3><p>A hypothesis can be described as something we think might be occurring or something that we think might be taking place in an environment. A hypothesis focuses on the 6 W&#8217;s:</p><ul><li><p>Who: Who is doing the activity?</p></li><li><p>What: What is happening?</p></li><li><p>Where: Where (What systems/networks) is this happening?</p></li><li><p>When: What time/time period did this happen?</p></li><li><p>Why: What is the end goal for the activity being performed?</p></li><li><p>How: How is the activity occurring in the system?</p></li></ul><h3>How do we create a hypothesis?</h3><p>For HOW to create a hypothesis for Threat Hunting, you can read an in-depth guide here: (insert link).</p><p>For now we will go over the hypothesis I have created for this scenario.</p><p>Let&#8217;s create a hypothesis to hunt for reconnaissance!</p><h3>Broad Hypothesis</h3><p>The company has reconnaissance activity within the network.</p><h3>Narrow hypothesis</h3><p>Reconnaissance activity is occurring in the Magnum Tempus environment, and some of the activity is malicious.</p><h1>Transitioning from a Hypothesis to a Query</h1><h2>How can we formulate a query based on our hypothesis?</h2><p>Our initial hypothesis presumes that there is reconnaissance activity within the environment. While this is most certainly true, we need to dig deeper. There may indeed be this ocurring, but as we noted above, not all reconnaissance activity is outright malicious.</p><p>First we need to understand what tools we have available. For this Hunt, we are using Splunk, however many of the procedures/methods we use can and should be used with other query languages/log platforms.</p><p>Since we know our log data is in Splunk, we first need to determine what log sources we have available to us.</p><p>We could modify our index to include ALL log source data using a wildcard query like this:</p><pre><code><code>index="*"
</code></code></pre><p>HOWEVER, this is considered <strong>bad practice</strong> as doing so is an expensive (resource-intensive) query and could cause undesirable effects on the Splunk (or other Log Aggregator) server and could hinder other searches being done on the system.</p><p>Thanks to our friend, <a href="https://github.com/blueteamvillage/obsidian-threat-hunting/blob/first-draft/KC3/Sniffing_Compromise_Cereal.md">Cereal Killer</a>, we can utilize the following query to find the indexes (source) of data to query against:</p><pre><code><code>| eventcount summarize=false index=* | dedup index | fields index
</code></code></pre><p>While you may not know this, when I think of nmap usage, I think of it being used on Linux distributions. As we can see above, there is an index for Linux, so let&#8217;s start there!</p><p>In Splunk queries, we start by calling the index (source) of the data we are querying against:</p><pre><code><code>index="linux"
</code></code></pre><p>We can query with just this, however we will get ALL data in the associated log:</p><blockquote><p>NOTE: We need to change the time filter to the time period we are checking against for this specific scenario because we don&#8217;t know exactly when the log data starts/stops. In your own Threat Hunting (outside of this scenario), you will want to identify a timeframe to conduct your searches. This could be 24 Hours, 1 Week, 1 Month.</p></blockquote><p>In this scenario for this hunt, we are focusing on the whole day of 2023-04-29.</p><p>In Linux, an example of a basic host nmap scan command line entry would look like this:</p><blockquote><p>nmap -sn 192.168.1.0/24</p></blockquote><p>To make it easier, we can expand on our existing query and add just the text &#8220;nmap&#8221; to it, since the nmap application is just simply <em>nmap</em>.</p><pre><code><code>index="linux" (nmap)
</code></code></pre><p>Okay, so for some reason this did not provide any results.</p><p>Did we do something wrong here? <em>Not exactly.</em> We&#8217;re conducting a threat hunt for something we THINK might be in the environment. A threat hunt will not always be successful, but sometimes it can be.</p><p>Let&#8217;s look at the index list again. So we see there are a few items that might be interesting to try. We see sysmonforlinux. Sysmon is a tool that is used to get telemetry data (information about what&#8217;s happening on the computer, even activities that the end user doesn&#8217;t ever see) and forwards this data to a log collector. This might also be a great source to query against.</p><p>We can also try adding some of the other tools we referenced above to the query as well.</p><h2>How can we refine this query?</h2><p>Let&#8217;s start with the previous query:</p><pre><code><code>index="linux" (nmap)
</code></code></pre><p>So there was no nmap activity in the linux logs in Splunk. Let&#8217;s pivot to include another potential log source as well as another command line reconnaissance tool, masscan.</p><p>Masscan might not be as commonly used as nmap and if we think like a potential adversary, we might want to use a tool that is less commonly used and therefore potentially less likely to be recognized.</p><p>An example of a masscan command line would be:</p><blockquote><p>masscan -p 80,443 192.168.1.0/24</p></blockquote><p>This scan is specifically looking for open HTTP (80) and HTTPS (443 Secure!) ports between 192.168.1.0 and 192.168.1.254.</p><p>We can modify our search as seen here:</p><pre><code><code>index IN (linux,sysmonforlinux) (masscan OR nmap)
</code></code></pre><p>This query did not net us any relevant hits, either.</p><p>Let&#8217;s pivot again - this is normal. Everything is fine.</p><h2>How can we refine this query since the previous did not get us what we expected?</h2><p>Let&#8217;s start with the initial query:</p><pre><code><code>index="linux" (nmap)
</code></code></pre><p>Our initial hypothesis presumes that we have reconnaissance activity in the environment. We started looking at Linux systems to see if there was activity there, but perhaps we made a problematic first assumption that the reconnaissance would come from a Linux system. Let&#8217;s go with the &#8220;sysmon&#8221; and &#8220;windows&#8221; index choices. Much like Sysmon for Linux, Windows Sysmon can provide telemetry from Microsoft Windows systems and there actually is a nmap version that can be used in Windows. We will not include masscan at this point because it&#8217;s less common in Windows.</p><p>Let&#8217;s go!</p><p>Here&#8217;s what we should modify our search query to:</p><pre><code><code>index IN (sysmon,windows) (nmap)
</code></code></pre><p>Let&#8217;s run this query!</p><p>We have hits!</p><p>Let&#8217;s look at the overall results:</p><p>182 events - digging through this, we could probably refine this list down. Let&#8217;s take a look at the hosts that show nmap activity. If we click on the host field on the left side, we see that 5 systems have been identified with something related to &#8220;nmap&#8221; on it:</p><p>What we also notice is that a LOT of activity related to nmap appears to be by one particular system:</p><blockquote><p>wkst16.magnumtempus.financial</p></blockquote><p>Let&#8217;s dig into this system a bit to see what&#8217;s happening.</p><p>We need to modify the query again</p><pre><code><code>index IN (windows,sysmon) (nmap) AND host="wkst16.magnumtempus.financial"
</code></code></pre><p>Running this, we see 152 events that match this query.</p><p>Looking through these entries the only directly interesting entry is one associated with Powershell, but it appears to be activity associated with installing nmap, so I don&#8217;t see this as particularly nefarious.</p><p>We also see this system is associated with Seth Morgan, an IT Engineer. Without knowing much more about what an IT Engineer is within the orgainzation, let&#8217;s take a moment to presume this is expected activity by this user.</p><p>Let&#8217;s compare with <em>Excluding</em> the host from the results:</p><pre><code><code>index IN (windows,sysmon) (nmap) AND NOT host="wkst16.magnumtempus.financial"
</code></code></pre><p>29 events!</p><p>Let&#8217;s take another look at the breakdown of the hosts associated with this query:</p><p>We see now that the top talker for this activity is:</p><blockquote><p>iot-eng-wkst.magnumtempus.financial</p></blockquote><p>Let&#8217;s refine our query and dig more into this system:</p><pre><code><code>index IN (windows,sysmon) (nmap) AND NOT host="wkst16.magnumtempus.financial" AND host="iot-eng-wkst.magnumtempus.financial"
</code></code></pre><p>So now we have found some interesting activity that seems like it would be somewhat questionable. Many of the top few events we see are from the user we saw previously, Seth Morgan, connecting over the network from the source IP Address 172.16.50.20 to the destination IP Address 172.16.50.19 via port 3389.</p><h3>What is port 3389?</h3><p>Port 3389 is commonly associated with Microsoft Windows Remote Desktop Protocol (RDP). This is a service that allows users to connect to a computer remotely via another computer.</p><blockquote><p>!!!IMPORTANT NOTE!!! Remote Desktop Protocol service should never be exposed to the public Internet. If this is required, please be sure to have this service hidden behind a secure VPN or some other access restriction.</p></blockquote><p>Moving forward with this in mind, we need to determine what the system 172.16.50.19 is. For this, we&#8217;ll need to craft another query.</p><p>Don&#8217;t worry, this one will be simple and we&#8217;ll get back to our main query shortly.</p><pre><code><code>index=* 172.16.50.19
</code></code></pre><p>When we run the query, we see can look at the hosts that are somewhat associated with this IP:</p><p>Over 40% of the traffic is associated with this asset:</p><blockquote><p>iot-jumpbox.magnumtempus.financial</p></blockquote><p>For those who may not be aware, a &#8220;jumpbox&#8221; is a system that is used as an intermediary between networks that may be highly restricted. This can be a normal practice and based on the hostname, we can presume this is an expected system on the network.</p><p>Let&#8217;s make a modification to the original query to only look for nmap activity from this system:</p><pre><code><code>index IN (windows,sysmon) (nmap) AND host="iot-jumpbox.magnumtempus.financial"
</code></code></pre><p>Running this query, we see two entries this time:</p><p>The first entry appears to be a file creation in the C:\Windows\SysWOW64 folder for nmap. Interesting, we may need to understand this more.</p><p>The next entry is very intriguing. Looking at the metadata within this, we see command line activity from this system probing the overall network using nmap:</p><blockquote><p>CommandLine: nmap 172.16.60.0/24 -p 22,5900,8080,80,443,502 -oA a -v</p></blockquote><p>Also, of note, is that this command was being run by a local user:</p><blockquote><p>IOT-JUMPBOX\iotadmin</p></blockquote><p>We know this is a local user due to the fact that the username includes the system name &#8220;IOT-JUMPBOX&#8221;. If this were a domain account, we would theoretically expect to see &#8220;MAGNUM.TEMPUS\iotadmin&#8221;</p><p>Let&#8217;s look at the command and dissect this so we understand what the command is looking for.</p><p>As we discussed previously, the command goes across a subset of the network, looking at the entry</p><blockquote><p>nmap 172.16.60.0/24</p></blockquote><p>This will cover all systems between the IP 172.16.60.1 and 172.16.60.254</p><blockquote><p>-p 22,5900,8080,80,443,502</p></blockquote><p>This is an interesting part of the command because of the wide range of open services that this is looking for. Let&#8217;s break each one down:</p><ul><li><p>22: This is for a remote service, Secure Shell, commonly called SSH. This is often used for remote access to a system, commonly over command line.</p></li><li><p>5900: This is another remote service, Virtual Network Computing, VNC. This is used for Graphical remote access to systems, similar to Windows Remote Desktop Protocol.</p></li><li><p>8080: This is looking for a web server. While this is not commonly used, 8080 is used in situations where the normally default web port 80 is unavailable.</p></li><li><p>80: See above. This is the more common port used.</p></li><li><p>443: This is for Secure HTTP, HTTPS. This adds a secure layer to regular HTTP.</p></li><li><p>502: This port is the most intriguing of all of the ports for this query. This is not a port we would expect to be queried for except in specific scenarios. It is specifically used for Modbus TCP/IP, allowing devices in industrial automation systems to communicate over TCP/IP networks. Modbus is widely used for exchanging data between devices such as PLCs, SCADA systems, and other industrial controllers.</p></li></ul><blockquote><p>-oA a -v</p></blockquote><ul><li><p>-oA a: This flag is used to specify the output format and file naming convention for the scan results. In this case, the letter &#8220;a&#8221; is used as the argument after -oA. It instructs Nmap to save the results in three different formats: normal format (a.nmap), XML format (a.xml), and grepable format (a.gnmap). This makes sense as to why we saw the file being created in the Windows SysWOW64 folder, and based on the filename, matches.</p></li><li><p>-v: The -v flag is useful for obtaining a more comprehensive view of the scanning process and gathering additional insights about the targets being scanned.</p></li></ul><h2>Where does this leave us?</h2><p>What stands out for this is that a local admin account on the jumpbox is attempting to enumerate a network, specifically looking for exposed webhosts, remote services, and curiously enough a port associated with industrial systems.</p><p>While this could be legitimate activity, I would not expect to see this type of a probe with all these seemingly unrelated ports being queried in a normal business operation. An administrator would not be looking for remote access ports, web servers, and an industrial-specific port, but instead have separate queries to do this.</p><p>What&#8217;s important to note is that our Threat Hunt focused only on computer/asset logs and we did not investigate any network traffic logs that could have provided additional context and support for our Hunt.</p><p>This activity definitely raises some red flags, so we need to provide our findings to the next team for them to dig in deeper.</p><p>Let&#8217;s build our Threat Hunter Template now!</p><h2>THREAT HUNTER TEMPLATE</h2><pre><code><code>Playbook Title: Detecting Reconnaissance in Company Environment

Mitre Tactic: T1046 - Network Service Discovery

Mitre Sub Technique: N/A

Hypothesis: Reconnaissance activity is occurring in the Magnum Tempus environment, and some of the activity is malicious.

Proposed Detection Query: index IN (windows,sysmon) (nmap) AND host="iot-jumpbox.magnumtempus.financial"

Simulation Details: NONE

Hunter Limitations/Observation Notes: Network traffic flow logs were not available during this hunt. Having access to these logs could add additional context for the search. Also of note, all of the fields were not parsed within the logging platform, making queries slightly less efficient and not as readable.

Hunt Findings: There may be some fishy activity occurring, since we detected probing on an uncommon port associated with PLC/SCADA</code></code></pre><h1>Connections</h1><p>Thank you for taking the time out of your daily life to read this. If any of this resonates with you, I encourage you to reach out and connect with me:</p><ul><li><p>Website: <a href="https://www.ilovesec.com">https://www.ilovesec.com</a></p></li><li><p>BlueSky: <a href="https://bsky.app/profile/ilovesec.com">https://bsky.app/profile/ilovesec.com</a></p></li><li><p>Mastodon: <a href="https://infosec.exchange/@Samunoske">https://infosec.exchange/@Samunoske</a></p></li><li><p>Github: <a href="https://github.com/samunoske">https://github.com/samunoske</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/in/thejoshuamorgan">https://www.linkedin.com/in/thejoshuamorgan</a></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ilovesec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Go Phish! Visualizing Basic Malice - DEF CON 30 (Blue Team Village)]]></title><description><![CDATA[My Talk from DEF CON 30 in 2022]]></description><link>https://ilovesec.substack.com/p/go-phish-visualizing-basic-malice</link><guid isPermaLink="false">https://ilovesec.substack.com/p/go-phish-visualizing-basic-malice</guid><dc:creator><![CDATA[Joshua Morgan]]></dc:creator><pubDate>Sat, 13 Aug 2022 00:30:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lUku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lUku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lUku!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lUku!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lUku!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lUku!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lUku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;My Talk from DEF CON 30 in 2022&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="My Talk from DEF CON 30 in 2022" title="My Talk from DEF CON 30 in 2022" srcset="https://substackcdn.com/image/fetch/$s_!lUku!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lUku!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lUku!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lUku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f77b69d-8bf2-427b-96b1-02fddadd5336_1280x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Go Phish: Visualizing Basic Malice</h1><p>Come take a dive into the data lake and cast some queries to find proof that users have run files from malicious actors. How can we prove the existence of troublesome activity in the environment? We will take a journey as if we are a new member of the Magnum Tempus Financial Security Team and proceed through a Threat Hunt through the eyes of a newbie in the field of Threat Hunting.</p><h1>Video Walkthrough</h1><div id="youtube2-oXlCyvFed6Q" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;oXlCyvFed6Q&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/oXlCyvFed6Q?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1>Overview</h1><h2>What will we learn?</h2><p>There are a number of concepts we will go over and learn in this walkthrough:</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ilovesec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ul><li><p>What is phishing and what is a phishing payload?</p></li><li><p>What is Visual Basic for Applications?</p></li><li><p>What are Macros and what does this have to do with phishing and Threat Hunting?</p></li><li><p>How can we walk through the thought process associated with a Threat Hunt from hypothesis to tangible results?</p></li><li><p>What tools do we have at our disposal and what can we do with them?</p></li><li><p>Can we go deeper and find out more after validating our hypothesis?</p></li></ul><h1>Initial Required Concepts</h1><p>In order to dive into the hunt, we need to have some baseline information to better understand what we are seeking to find. Let us take a look at some of these now.</p><h2>What is phishing?</h2><p>In simple terms, phishing in this context is an attempt by an adversary to use methods to obtain credentials in an illicit manner using email communications.</p><h2>What is a phishing payload?</h2><p>A phishing payload is the means in which an adversary attempts to obtain the credentials of a target. The payload could be a link that sends an unsuspecting victim to a webpage that emulates a known website (like Microsoft Office 365 portal or Banking logon page) to collect usernames and passwords. Here are a few examples of malicious emails I have seen in my information security experiences:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bhCD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bhCD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 424w, https://substackcdn.com/image/fetch/$s_!bhCD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 848w, https://substackcdn.com/image/fetch/$s_!bhCD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 1272w, https://substackcdn.com/image/fetch/$s_!bhCD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bhCD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png" width="1025" height="734" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:734,&quot;width&quot;:1025,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!bhCD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 424w, https://substackcdn.com/image/fetch/$s_!bhCD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 848w, https://substackcdn.com/image/fetch/$s_!bhCD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 1272w, https://substackcdn.com/image/fetch/$s_!bhCD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5185f6bb-2568-4df5-aa8f-6cf3bb1a0f30_1025x734.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Another type of payload can be a document or file specially crafted to behave in a certain manner or take specific actions to attempt to collect credentials from a user&#8217;s system:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jlgc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jlgc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 424w, https://substackcdn.com/image/fetch/$s_!Jlgc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 848w, https://substackcdn.com/image/fetch/$s_!Jlgc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 1272w, https://substackcdn.com/image/fetch/$s_!Jlgc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jlgc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png" width="727" height="353" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a34cce26-6efc-4b9d-b190-108691ca6899_727x353.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:353,&quot;width&quot;:727,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!Jlgc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 424w, https://substackcdn.com/image/fetch/$s_!Jlgc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 848w, https://substackcdn.com/image/fetch/$s_!Jlgc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 1272w, https://substackcdn.com/image/fetch/$s_!Jlgc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa34cce26-6efc-4b9d-b190-108691ca6899_727x353.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s look at what we see in the above screenshot:</p><blockquote><ol><li><p>The company email is mycoinsnow.com but the email sender is mycolnsnow.com - this is a typosquat of the domain.</p></li><li><p>Misspelling &#8216;document&#8217; in the text. Additionally, creating a sense of urgency on the recipient that action is required by a specified date.</p></li><li><p>Document attached is a .docx file that simply says &#8220;invoice&#8221; with no other indication on what it is for.</p></li></ol></blockquote><p>Attacks using the above type of email often utilize the Visual Basic for Applications (VBA) coding present in Microsoft Office Suite, primarily in Microsoft Word, Excel, and PowerPoint.</p><h2>What is Visual Basic for Applications?</h2><p>Visual Basic for Applications (VBA) is a slightly stripped down/limited version of Visual Basic coding language that can be used in Microsoft applications to add functionality and extensibility not natively available in the applications themselves. This can be useful in helping automate repetitive actions or automate retrieval of data when certain options are chosen in a document. VBA allows system-level access to perform actions and can act outside of the Microsoft Office Applications as well. We commonly call these &#8220;Macros&#8221;.</p><h2>What are the issues with Macros?</h2><p>Due to how the functionality works in allowing access outside of the walled garden of Microsoft Office Suite, macros can allow an adversary the ability to make system changes or download additional malicious code via these macros with little interaction from the victim.</p><p>An example of how the VBA Macro document could appear in a Microsoft Word document can be see here:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WGgt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WGgt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 424w, https://substackcdn.com/image/fetch/$s_!WGgt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 848w, https://substackcdn.com/image/fetch/$s_!WGgt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 1272w, https://substackcdn.com/image/fetch/$s_!WGgt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WGgt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png" width="1456" height="854" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:854,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!WGgt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 424w, https://substackcdn.com/image/fetch/$s_!WGgt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 848w, https://substackcdn.com/image/fetch/$s_!WGgt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 1272w, https://substackcdn.com/image/fetch/$s_!WGgt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb2fb3fd-36ec-4012-9ff8-2422ae3e5a3a_2660x1560.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Now that we understand what phishing, phishing payloads, VBA, and macros are, let&#8217;s put these concepts together to see if we can build a Threat Hunt with these ideas in mind!</strong></p><h1>Threat Hunting</h1><h2>What is Threat Hunting?</h2><p>Threat Hunting (TH) is a process of being proactive of unveiling unknown-knowns and unknown-unknowns to better our security posture</p><h1>Hypothesis</h1><p>In order to begin the Threat Hunt, we need to have a reason to start the hunt. To start, we will need to come up with a hypothesis.</p><h3>What is a hypothesis?</h3><p>A hypothesis can be described as something we think might be occurring or something that we think might be taking place in an environment. A hypothesis focuses on the 6 W&#8217;s:</p><ul><li><p>Who: Who is doing the activity?</p></li><li><p>What: What is happening?</p></li><li><p>Where: Where (What systems/networks) is this happening?</p></li><li><p>When: What time/time period did this happen?</p></li><li><p>Why: What is the end goal for the activity being performed?</p></li><li><p>How: How is the activity occurring in the system?</p></li></ul><h3>How do we create a hypothesis?</h3><p>For HOW to create a hypothesis for Threat Hunting, you can read an in-depth guide here: (insert link).</p><p>For now we will go over the hypothesis I have created for this scenario.</p><p>Let&#8217;s create a hypothesis to hunt for potential phishing activity!</p><h3>Broad Hypothesis</h3><p>Magnum Tempus employees receive malicious phishing emails.</p><h3>Narrow hypothesis</h3><p>MT Employees are targeted with Malicious Microsoft Documents containing VBA macros via phishing email. Some employees will click and open malicious documents.</p><h1>Transitioning from a Hypothesis to a Query</h1><h2>How can we formulate a query based on our hypothesis?</h2><p>Our initial hypothesis presumes Magnum Tempus employees receive emails with malicious documents and opens those documents.</p><p>First we need to understand what tools we have available. For this Hunt, we are using Splunk, however many of the procedures/methods we use can and should be used with other query languages/log platforms.</p><p>Since we know our log data is in Splunk, we first need to determine what log sources we have available to us.</p><p>We could modify our index to include ALL log source data using a wildcard query like this:</p><pre><code><code>index="*"
</code></code></pre><p>HOWEVER, this is considered <strong>bad practice</strong> as doing so is an expensive (resource-intensive) query and could cause undesirable effects on the Splunk (or other Log Aggregator) server and could hinder other searches being done on the system.</p><p>Thanks to our friend, <a href="https://github.com/blueteamvillage/obsidian-threat-hunting/blob/first-draft/KC3/Sniffing_Compromise_Cereal.md">Cereal Killer</a>, we can utilize the following query to find the indexes (source) of data to query against:</p><pre><code><code>| eventcount summarize=false index=* | dedup index | fields index
</code></code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xgs3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xgs3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 424w, https://substackcdn.com/image/fetch/$s_!xgs3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 848w, https://substackcdn.com/image/fetch/$s_!xgs3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 1272w, https://substackcdn.com/image/fetch/$s_!xgs3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xgs3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png" width="523" height="636" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:636,&quot;width&quot;:523,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!xgs3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 424w, https://substackcdn.com/image/fetch/$s_!xgs3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 848w, https://substackcdn.com/image/fetch/$s_!xgs3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 1272w, https://substackcdn.com/image/fetch/$s_!xgs3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd67d9c-4aeb-4b73-b485-5f31b27b06b9_523x636.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We will start with Zeek logs in Splunk because we can find documents transmitted over network traffic if they are downloaded from a company email on a company asset. Zeek is used to collect telemetry data and traffic flowing through an organization&#8217;s network.</p><p>In Splunk queries, we start by calling the index (source) of the data we are querying against:</p><pre><code><code>index="zeek"
</code></code></pre><p>We can query with just this, however we will get ALL data in the associated log:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UP7T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UP7T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 424w, https://substackcdn.com/image/fetch/$s_!UP7T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 848w, https://substackcdn.com/image/fetch/$s_!UP7T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 1272w, https://substackcdn.com/image/fetch/$s_!UP7T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UP7T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png" width="1026" height="641" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:641,&quot;width&quot;:1026,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!UP7T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 424w, https://substackcdn.com/image/fetch/$s_!UP7T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 848w, https://substackcdn.com/image/fetch/$s_!UP7T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 1272w, https://substackcdn.com/image/fetch/$s_!UP7T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff72181bb-24d5-4841-a890-0acca2bd4c81_1026x641.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>NOTE: We need to change the time filter to the time period we are checking against for this specific scenario because we don&#8217;t know exactly when the log data starts/stops. In your own Threat Hunting (outside of this scenario), you will want to identify a timeframe to conduct your searches. This could be 24 Hours, 1 Week, 1 Month.</p></blockquote><p>In this scenario for Magnum Tempus, we are focusing on 2022-02-11 through 2022-02-13</p><p>Let&#8217;s focus on document file types that are often sent as potential phishing attachments.</p><p>Some of the more common formats include Microsoft Word formats (<strong>.doc, .docx</strong>) and Microsoft Excel Spreadsheets (<strong>.xls, .xlsx</strong>). Splunk allows us to query for multiple file types at once. Note we are not necessarily looking for an <strong>official filetype designation</strong> because we may not know exactly if this is indexed in Splunk. Let&#8217;s check for the filetypes specifically as shown here:</p><pre><code><code>index="zeek" (.doc OR .xls OR .docx OR .xlsx)
</code></code></pre><p>We get lots of hits (863!) because a lot of documents will be sent as part of normal business:</p><p>Let&#8217;s try to pare down the total number to a more manageable number using some common phishing terms.</p><h2>How can we refine this query?</h2><p>Let&#8217;s start with the previous query:</p><pre><code><code>index="zeek" (.doc OR .xls OR .docx OR .xlsx)
</code></code></pre><p>This gave us way too many results. We want to reduce the number of files, but need to find files that could indicate potential phishing activity. Occasionally we see common terms/names in documents related to phishing activity as seen here at <a href="https://isc.sans.edu/forums/diary/Common+Patterns+Used+in+Phishing+Campaigns+Files/23403/">SANS Common Patterns Used in Phishing Campaign Files</a>:</p><p>Let&#8217;s pick a few and run another search, this time expanding our search to other log sources within Splunk (using index IN):</p><p>Let&#8217;s try including a different log source with our zeek query.</p><p>Looking at our index from before, let&#8217;s go with sysmon, as we might be able to see files accessed on endpoints (Much like how Zeek is used for network telemetry, Sysmon is used to generate telemetry data from endpoint devices in an organization.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x1CQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x1CQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 424w, https://substackcdn.com/image/fetch/$s_!x1CQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 848w, https://substackcdn.com/image/fetch/$s_!x1CQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 1272w, https://substackcdn.com/image/fetch/$s_!x1CQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x1CQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png" width="549" height="650" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:650,&quot;width&quot;:549,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!x1CQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 424w, https://substackcdn.com/image/fetch/$s_!x1CQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 848w, https://substackcdn.com/image/fetch/$s_!x1CQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 1272w, https://substackcdn.com/image/fetch/$s_!x1CQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa9f1c55-db97-4fa9-8112-1be79f81a9a0_549x650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We can modify our search as seen here:</p><pre><code><code>index IN (zeek,sysmon) (.doc OR .xls OR .docx OR .xlsx) (invoice OR remit OR payment OR order)
</code></code></pre><p>This query did not net us any relevant hits:</p><p>We should probably try a different approach.</p><h2>How can we refine this query since the previous did not get us what we expected?</h2><p>Let&#8217;s start with the initial query:</p><pre><code><code>index="zeek" (.doc OR .xls OR .docx OR .xlsx)
</code></code></pre><p>Our initial hypothesis presumes that users executed malicious VBA macro code. Is there a way for us to determine based on log data that such a document was executed?</p><p>In a word: yes.</p><p>Reviewing <a href="https://isc.sans.edu/diary/Office+macro+execution+evidence/27244">SANS Office macro execution evidence</a> we see that we can check logs for &#8220;TrustRecords&#8221; to see if there were Windows Registry modifications:</p><blockquote><p>One of the few places where macro execution leaves traces is in the &#8220;TrustRecords&#8221; entry in the registry: HKCU:\SOFTWARE\Microsoft\Office\16.0\Word\Security\Trusted Documents\TrustRecords HKCU:\SOFTWARE\Microsoft\Office\16.0\Excel\Security\Trusted Documents\TrustRecords HKCU:\SOFTWARE\Microsoft\Office\16.0\PowerPoint\Security\Trusted Documents\TrustRecords</p><p>-From <a href="https://isc.sans.edu/diary/Office+macro+execution+evidence/27244">https://isc.sans.edu/diary/Office+macro+execution+evidence/27244</a></p></blockquote><p>Let&#8217;s take a look at what we should modify our search query to:</p><pre><code><code>index IN (zeek,sysmon) (.doc OR .xls OR .docx OR .xlsx) (TrustRecords)
</code></code></pre><p>Let&#8217;s run this query!</p><p>We have hits!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2LvE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2LvE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 424w, https://substackcdn.com/image/fetch/$s_!2LvE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 848w, https://substackcdn.com/image/fetch/$s_!2LvE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 1272w, https://substackcdn.com/image/fetch/$s_!2LvE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2LvE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png" width="1275" height="840" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:840,&quot;width&quot;:1275,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!2LvE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 424w, https://substackcdn.com/image/fetch/$s_!2LvE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 848w, https://substackcdn.com/image/fetch/$s_!2LvE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 1272w, https://substackcdn.com/image/fetch/$s_!2LvE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9c94d7-e59f-4e6f-a8fe-298a3330cbd6_1275x840.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s look at the overall results:</p><p>62 events - this should be easier to parse. Looking at one of the first hits we see there is what appears to be an internal fileshare:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WaBZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WaBZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 424w, https://substackcdn.com/image/fetch/$s_!WaBZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 848w, https://substackcdn.com/image/fetch/$s_!WaBZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 1272w, https://substackcdn.com/image/fetch/$s_!WaBZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WaBZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png" width="1318" height="821" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/febfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:821,&quot;width&quot;:1318,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!WaBZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 424w, https://substackcdn.com/image/fetch/$s_!WaBZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 848w, https://substackcdn.com/image/fetch/$s_!WaBZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 1272w, https://substackcdn.com/image/fetch/$s_!WaBZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffebfa1e6-dc23-4787-b7d2-8cbb7c3171d0_1318x821.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><pre><code><code>files.magnumtempusfinancial.com
</code></code></pre><p>For purposes of this TH, let&#8217;s exclude this in the query. Since our initial hypothesis indicated that users would download and execute malicious documents downloaded from a malicious sender, we might not expect to see these files in an internal file share at first. It is possible, however, that files could be malicious and saved to the fileshare. Let&#8217;s take a look to see how many of our documents that use macros are on the internal fileshare:</p><pre><code><code>index IN (zeek,sysmon) (.doc OR .xls OR .docx OR .xlsx) (TrustRecords) AND (files.magnumtempusfinancial.com)
</code></code></pre><p>Running this, we see 26 events that match this query:</p><p>Let&#8217;s compare with <em>Excluding</em> the fileshare from the results:</p><pre><code><code>index IN (zeek,sysmon) (.doc OR .xls OR .docx OR .xlsx) (TrustRecords) AND NOT (files.magnumtempusfinancial.com)
</code></code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cvxt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cvxt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 424w, https://substackcdn.com/image/fetch/$s_!cvxt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 848w, https://substackcdn.com/image/fetch/$s_!cvxt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 1272w, https://substackcdn.com/image/fetch/$s_!cvxt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cvxt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png" width="1105" height="853" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:853,&quot;width&quot;:1105,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!cvxt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 424w, https://substackcdn.com/image/fetch/$s_!cvxt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 848w, https://substackcdn.com/image/fetch/$s_!cvxt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 1272w, https://substackcdn.com/image/fetch/$s_!cvxt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe84114c7-507c-4171-9716-ae2fb6689de6_1105x853.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>22 events!</p><p>Here&#8217;s the first event that shows up:</p><blockquote><p>Registry value set: RuleName: - EventType: SetValue UtcTime: 2022-02-12 21:12:25.454 ProcessGuid: 0522759F-229C-6208-B002-000000001002 ProcessId: 972 Image: C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE TargetObject: HKU\S-1-5-21-2370586174-1517003462-1142029260-1129\SOFTWARE\Microsoft\Office\16.0\Word\Security\TrustedDocuments\TrustRecords%USERPROFILE%/Downloads/MagnumTempus-<a href="mailto:Policy-Violation-matt.tristique@magnumtempusfinancial.com.doc">Policy-Violation-matt.tristique@magnumtempusfinancial.com.doc</a> Details: Binary Data User: MAGNUMTEMPUS\matt.tristique</p></blockquote><p>Based on the above we can see that a file was indeed executed according to the &#8220;Trusted Documents\TrustRecords&#8221; we saw in the SANS example of macro activity. This is a step in the right direction.</p><p>There were other users with similar activity, let&#8217;s take a look:</p><blockquote><p>TargetObject: HKU\S-1-5-21-2370586174-1517003462-1142029260-1128\SOFTWARE\Microsoft\Office\16.0\Word\Security\Trusted Documents\TrustRecords %USERPROFILE%/Desktop/MagnumTempus-<a href="mailto:Policy-Violation-karen.metuens@magnumtempusfinancial.com.doc">Policy-Violation-karen.metuens@magnumtempusfinancial.com.doc</a> TargetObject: HKU\S-1-5-21-2370586174-1517003462-1142029260-1126\SOFTWARE\Microsoft\Office\16.0\Word\Security\Trusted Documents\TrustRecords %USERPROFILE%/Desktop/MagnumTempus-<a href="mailto:Policy-Violation-amanda.nuensis@magnumtempusfinancial.com.doc">Policy-Violation-amanda.nuensis@magnumtempusfinancial.com.doc</a></p></blockquote><p>All of the filetypes appear to be .doc and the filenames appear to be extremely formulaic and similar:</p><blockquote><p><a href="mailto:MagnumTempus-Policy-Violation-karen.metuens3@magnumtempusfinancial.com.doc">MagnumTempus-Policy-Violation-karen.metuens3@magnumtempusfinancial.com.doc</a></p></blockquote><p>This is an interesting filename because it appears to include an email in the filename, which is NOT normal and could be a sign of a malicious file.</p><p>If we look at the bottom of the first entry, we see a workstation name (agent.hostname):</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SEne!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SEne!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 424w, https://substackcdn.com/image/fetch/$s_!SEne!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 848w, https://substackcdn.com/image/fetch/$s_!SEne!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 1272w, https://substackcdn.com/image/fetch/$s_!SEne!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SEne!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png" width="471" height="361" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:361,&quot;width&quot;:471,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!SEne!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 424w, https://substackcdn.com/image/fetch/$s_!SEne!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 848w, https://substackcdn.com/image/fetch/$s_!SEne!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 1272w, https://substackcdn.com/image/fetch/$s_!SEne!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6aaa861-1e95-4ec5-a5b2-be04e1f1f30f_471x361.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s see if Splunk can show us more data. On the left side of the page, go to the &#8220;SELECTED FIELDS&#8221; section, then click on &#8220;agent.hostname&#8221;:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w85v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w85v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 424w, https://substackcdn.com/image/fetch/$s_!w85v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 848w, https://substackcdn.com/image/fetch/$s_!w85v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 1272w, https://substackcdn.com/image/fetch/$s_!w85v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w85v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png" width="885" height="350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:350,&quot;width&quot;:885,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!w85v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 424w, https://substackcdn.com/image/fetch/$s_!w85v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 848w, https://substackcdn.com/image/fetch/$s_!w85v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 1272w, https://substackcdn.com/image/fetch/$s_!w85v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2081eebb-219c-435c-b6bf-78048c4153ad_885x350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Matt&#8217;s hostname appears to be wkst03 - not many hits. wkst01 and wkst02 have a significantly higher number of entries, and this could signify additional activity.</p><h2>Can we find the source of the files?</h2><p>Let&#8217;s try to see what we can find with this filename in the logs. We have to create a new query:</p><pre><code><code>index IN (zeek,sysmon) (MagnumTempus-Policy-Violation-)
</code></code></pre><p>When we run the query, we see additional users were targeted:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0gK-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0gK-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 424w, https://substackcdn.com/image/fetch/$s_!0gK-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 848w, https://substackcdn.com/image/fetch/$s_!0gK-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 1272w, https://substackcdn.com/image/fetch/$s_!0gK-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0gK-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png" width="1314" height="829" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:829,&quot;width&quot;:1314,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!0gK-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 424w, https://substackcdn.com/image/fetch/$s_!0gK-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 848w, https://substackcdn.com/image/fetch/$s_!0gK-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 1272w, https://substackcdn.com/image/fetch/$s_!0gK-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19c851cf-2d72-454e-97d9-1fe7be12d206_1314x829.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><a href="mailto:MagnumTempus-Policy-Violation-domi.nusvir@magnumtempusfinancial.com.doc">MagnumTempus-Policy-Violation-domi.nusvir@magnumtempusfinancial.com.doc</a> <a href="mailto:MagnumTempus-Policy-Violation-celiste.pecunia@magnumtempusfinancial.com.doc">MagnumTempus-Policy-Violation-celiste.pecunia@magnumtempusfinancial.com.doc</a></p></blockquote><p>We also see where the file was downloaded from for one user, Matt Tristique:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5SpG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5SpG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 424w, https://substackcdn.com/image/fetch/$s_!5SpG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 848w, https://substackcdn.com/image/fetch/$s_!5SpG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 1272w, https://substackcdn.com/image/fetch/$s_!5SpG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5SpG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png" width="1214" height="634" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:634,&quot;width&quot;:1214,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!5SpG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 424w, https://substackcdn.com/image/fetch/$s_!5SpG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 848w, https://substackcdn.com/image/fetch/$s_!5SpG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 1272w, https://substackcdn.com/image/fetch/$s_!5SpG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9bbafeb-745b-4ffe-ac79-f0de129fd345_1214x634.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>File stream created: RuleName: technique_id=T1089,technique_name=Drive-by Compromise UtcTime: 2022-02-12 21:11:41.529 ProcessGuid: 0522759F-02B6-6208-A600-000000001002 ProcessId: 5616 Image: C:\Program Files\Mozilla Thunderbird\thunderbird.exe TargetFilename: C:\Users\matt.tristique\Downloads\<a href="mailto:MagnumTempus-Policy-Violation-matt.tristique@magnumtempusfinancial.com.doc">MagnumTempus-Policy-Violation-matt.tristique@magnumtempusfinancial.com.doc</a>:Zone.Identifier CreationUtcTime: 2022-02-12 21:11:40.731 Hash: SHA1=AE356A67D337AFA5933E3E679E84854DEEACE048,MD5=DCE5191790621B5E424478CA69C47F55,SHA256=86A3E68762720ABE870D1396794850220935115D3CCC8BB134FFA521244E3EF8,IMPHASH=00000000000000000000000000000000 Contents: [ZoneTransfer] ZoneId=3 HostUrl=about:internet<br>User: MAGNUMTEMPUS\matt.tristique</p></blockquote><p>This entry is very intriguing:</p><blockquote><p>RuleName: technique_id=T1089,technique_name=Drive-by Compromise</p></blockquote><p>It appears that this file was detected as a <em><strong>Drive-by Compromise</strong></em>. This is not good. We might be able to surmise this is a malicious document based on this.</p><h2>Who else downloaded the document?</h2><p>Let&#8217;s see if any other users downloaded this file with ThunderBird:</p><pre><code><code>index IN (zeek,sysmon) (MagnumTempus-Policy-Violation-) (thunderbird.exe)
</code></code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xoPj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xoPj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 424w, https://substackcdn.com/image/fetch/$s_!xoPj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 848w, https://substackcdn.com/image/fetch/$s_!xoPj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 1272w, https://substackcdn.com/image/fetch/$s_!xoPj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xoPj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png" width="1456" height="825" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:825,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!xoPj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 424w, https://substackcdn.com/image/fetch/$s_!xoPj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 848w, https://substackcdn.com/image/fetch/$s_!xoPj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 1272w, https://substackcdn.com/image/fetch/$s_!xoPj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a294-c8ba-4ac2-83a2-71a47f012389_1471x833.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>From our search, it appears both Amanda and Karen downloaded the file via ThunderBird.</p><p>Interestingly enough, neither Amanda&#8217;s nor Karen&#8217;s entries signify that the file was detected as a <em><strong>Drive-by Compromise</strong></em>:</p><blockquote><p>File created: RuleName: - UtcTime: 2022-02-12 21:11:24.552 ProcessGuid: 29C462BB-0EC0-6208-D000-000000001202 ProcessId: 3184 Image: C:\Program Files\Mozilla Thunderbird\thunderbird.exe TargetFilename: C:\Users\amanda.nuensis\Desktop\<a href="mailto:MagnumTempus-Policy-Violation-amanda.nuensis@magnumtempusfinancial.com.doc">MagnumTempus-Policy-Violation-amanda.nuensis@magnumtempusfinancial.com.doc</a> CreationUtcTime: 2022-02-12 21:11:24.552 User: MAGNUMTEMPUS\amanda.nuensis</p><p>File created: RuleName: - UtcTime: 2022-02-11 04:51:45.698 ProcessGuid: 444CBE19-EAF9-6205-E600-000000001302 ProcessId: 5552 Image: C:\Program Files\Mozilla Thunderbird\thunderbird.exe TargetFilename: C:\Users\karen.metuens\Desktop\<a href="mailto:MagnumTempus-Policy-Violation-karen.metuens@magnumtempusfinancial.com.doc">MagnumTempus-Policy-Violation-karen.metuens@magnumtempusfinancial.com.doc</a> CreationUtcTime: 2022-02-11 04:51:45.572 User: MAGNUMTEMPUS\karen.metuens</p></blockquote><h2>What does this mean?</h2><p>Unfortunately, at least three of Magnum Tempus employees downloaded (and based on what we know about the registry changes involving &#8220;Trust Records&#8221; - successfully ran the malicious code) a malicious document laden with VBA Macro documents. At this point, it might be worth it to investigate further what has happened as a result of detonation of the intial malicious payload.</p><h2>Are we done?</h2><p>In theory, at this point we are done as we have fulfilled the initial hypothesis of determining that a user downloaded and executed the VBA Macro. While we have not necessarily confirmed that the macro code is indeed malicious, we would need to take additional steps to do this.</p><h2>Can we find the initial email that contained the malicious document - and possibly the document itself and inspect the code?</h2><p>Yes! However, we will need to use another tool, WireShark in order to extract information from the captured network traffic (PCAP File).</p><h1>Threat Hunting and Investigation with WireShark</h1><h2>What is WireShark?</h2><p>WireShark is a specialized tool for analyzing network data. We can review data flowing through the network in real-time, however in this specific case we will be reviewing a point-in-time capture of Magnum Tempus network traffic.</p><h3>Locating the offending email in WireShark</h3><p>Since we know what the filename, based on our searches above:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZzRr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZzRr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 424w, https://substackcdn.com/image/fetch/$s_!ZzRr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 848w, https://substackcdn.com/image/fetch/$s_!ZzRr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 1272w, https://substackcdn.com/image/fetch/$s_!ZzRr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZzRr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png" width="982" height="149" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:149,&quot;width&quot;:982,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!ZzRr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 424w, https://substackcdn.com/image/fetch/$s_!ZzRr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 848w, https://substackcdn.com/image/fetch/$s_!ZzRr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 1272w, https://substackcdn.com/image/fetch/$s_!ZzRr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9555bebe-8780-44ef-9dd3-df23d3b9575e_982x149.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s look at the filename:</p><blockquote><p><a href="mailto:MagnumTempus-Policy-Violation-karen.metuens@magnumtempusfinancial.com.doc">MagnumTempus-Policy-Violation-karen.metuens@magnumtempusfinancial.com.doc</a></p></blockquote><p>Since MagnumTempus is something that we might expect to see in other documents, let&#8217;s disregard this for the moment. The term &#8220;Policy-Violation-&#8221; stands out as something that might be unique in an organization. Taking this mindset, let&#8217;s use the following for our further search:</p><blockquote><p>Policy-Violation-</p></blockquote><p>Now let&#8217;s check to see if we can find this in WireShark:</p><p>Press control and F to bring up the search tool.</p><p>Change the first dropdown to &#8220;Packet Details&#8221; (1).<br>In the third dropdown change to &#8220;String&#8221; (2) In the text box, type the following (3):</p><blockquote><p>Policy-Violation-</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ADC1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ADC1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 424w, https://substackcdn.com/image/fetch/$s_!ADC1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 848w, https://substackcdn.com/image/fetch/$s_!ADC1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 1272w, https://substackcdn.com/image/fetch/$s_!ADC1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ADC1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png" width="1456" height="338" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:338,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!ADC1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 424w, https://substackcdn.com/image/fetch/$s_!ADC1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 848w, https://substackcdn.com/image/fetch/$s_!ADC1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 1272w, https://substackcdn.com/image/fetch/$s_!ADC1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab5630b-382e-4728-98f2-4154cce79cc1_3300x766.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Press &#8220;Find&#8221;:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!acup!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!acup!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 424w, https://substackcdn.com/image/fetch/$s_!acup!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 848w, https://substackcdn.com/image/fetch/$s_!acup!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 1272w, https://substackcdn.com/image/fetch/$s_!acup!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!acup!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png" width="1456" height="295" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:295,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!acup!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 424w, https://substackcdn.com/image/fetch/$s_!acup!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 848w, https://substackcdn.com/image/fetch/$s_!acup!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 1272w, https://substackcdn.com/image/fetch/$s_!acup!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62fafcb7-7cc4-46a8-8ec0-76bc03beb829_2938x596.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s review what we see here:</p><blockquote><ol><li><p>Subject: [ACTION REQUIRED] INTERNAL IT POLICY VIOLATION</p></li><li><p>From: <a href="mailto:legal-internal@magnumtempus.financial">legal-internal@magnumtempus.financial</a></p></li></ol></blockquote><p>Time to dig deeper! Right click on this entry and go to &#8220;Follow&#8221; then click on &#8220;TCP Stream&#8221;:</p><p>A window will pop up with the network stream for this activity:</p><p>Scrolling down further we get to the content of the email itself. What makes this interesting is that perhaps the mail server was not properly configured, because we are able to see in clear-text over the network contents of an email. This has other security implications that we will not discuss here, but is important to note for future investigations.</p><p>We can see the content here:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IOHw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IOHw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 424w, https://substackcdn.com/image/fetch/$s_!IOHw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 848w, https://substackcdn.com/image/fetch/$s_!IOHw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 1272w, https://substackcdn.com/image/fetch/$s_!IOHw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IOHw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png" width="1456" height="560" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:560,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!IOHw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 424w, https://substackcdn.com/image/fetch/$s_!IOHw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 848w, https://substackcdn.com/image/fetch/$s_!IOHw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 1272w, https://substackcdn.com/image/fetch/$s_!IOHw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bcb768f-5d64-4dae-88c2-e32934e2bb8d_1658x638.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><pre><code><code>The MagnumTempus Financial CERT and CyberSecurity team have noticed that you are one of the users - "karen.metuens@magnumtempus.financial", "amanda.nuensis@magnumtempus.financial", who have violated the company policy CCG-IV:5-8 on 2/7/2022, 8:48pm - EDT.

As mentioned in the yearly cybersecurity training and your employment agreement with MagnumTempus, the violation of IT policy may terminate your employment. 

Please review the attachment which includes the decision made by the MagnumTempus Legal team. Make sure to reply to this email within 72 hours of opening the document. 

Thank you, 
MagnumTempus Internal Legal Department 
(+1)969-555-5984
legal-internal@magnumtempus.financial 
</code></code></pre><p>Scrolling down further, we see there is an attachment:</p><p>A few notes about this screenshot:</p><blockquote><ol><li><p>The attachment is encoded, this one in Base64. Base64 is a common encoding algorythm that can be used to &#8216;encrypt&#8217; documents to transmit.</p></li><li><p>The filename for the attachment matches what we expect to see, based on our findings in our Splunk investigations</p></li><li><p>This is the Base64 encoded data for the document.</p></li></ol></blockquote><p>This matches what we saw in our earlier Splunk queries. We might be able to extract the file data from WireShark to analyze further - an important thing to note from above is that the data is encoded in Base64:</p><pre><code><code>NOTE: The below is a truncated version of the actual payload data for brevity purposes:

0M8R4KGxGuEAAAAAAAAAAAAAAAAAAAAAPgADAP7/CQAGAAAAAAAAAAAAAAABAAAAJwAAAAAAAAAA
EAAAKQAAAAEAAAD+////AAAAACYAAAD/////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
///////////////////////////////////////////////////////////////////////////s
pcEAWeAJBAAA8BK/AAAAAAAAEAAAAAAACAAAAQgAAA4AYmpiapDKkMoAAAAAAAAAAAAAAAAAAAAA
AAAJBBYALg4AAPKgDFzyoAxcAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD//w8AAAAA
AAAAAAD//w8AAAAAAAAAAAD//w8AAAAAAAAAAAAAAAAAAAAAALcAAAAAADIHAAAAAAAAMgcAAKoU
AAAAAAAAqhQAAAAAAACqFAAAAAAAAKoUAAAAAAAAqhQAABQAAAAAAAAAAAAAAP////8AAAAAvhQA
AAAAAAC+FAAAAAAAAL4UAAAAAAAAvhQAAAwAAADKFAAADAAAAL4UAAAAAAAAtRcAADABAADWFAAA
AAAAAAAAAAAAAAAAAAAAAABFeHRlbmRlciBJbmZvXQ0KJkgwMDAwMDAwMT17MzgzMkQ2NDAtQ0Y5
MC0xMUNGLThFNDMtMDBBMEM5MTEwMDVBfTtWQkU7JkgwMDAwMDAwMA0KDQpbV29ya3NwYWNlXQ0K
VGhpc0RvY3VtZW50PTAsIDAsIDAsIDAsIEMNCk5ld01hY3Jvcz0tMTYsIDY0LCAxNDI5LCA1ODgs
IA0KAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAP7/AwoAAP////8GCQIAAAAA
AMAAAAAAAABGIAAAAE1pY3Jvc29mdCBXb3JkIDk3LTIwMDMgRG9jdW1lbnQACgAAAE1TV29yZERv
YwAQAAAAV29yZC5Eb2N1bWVudC44APQ5snEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAA==
</code></code></pre><p>We can then take the data we&#8217;ve copied and then use a tool like <a href="https://gchq.github.io/CyberChef/">CyberChef</a> to convert from Base64 to somewhat human-readable text:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hmoF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hmoF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 424w, https://substackcdn.com/image/fetch/$s_!hmoF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 848w, https://substackcdn.com/image/fetch/$s_!hmoF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!hmoF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hmoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png" width="1456" height="1323" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1323,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!hmoF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 424w, https://substackcdn.com/image/fetch/$s_!hmoF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 848w, https://substackcdn.com/image/fetch/$s_!hmoF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!hmoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f56790-9634-4551-8131-4ee8e34601e2_1726x1568.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Scrolling down, we can see data inside the converted code that indicates it&#8217;s a Microsoft Document:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IHOT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IHOT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 424w, https://substackcdn.com/image/fetch/$s_!IHOT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 848w, https://substackcdn.com/image/fetch/$s_!IHOT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 1272w, https://substackcdn.com/image/fetch/$s_!IHOT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IHOT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png" width="1456" height="591" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:591,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!IHOT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 424w, https://substackcdn.com/image/fetch/$s_!IHOT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 848w, https://substackcdn.com/image/fetch/$s_!IHOT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 1272w, https://substackcdn.com/image/fetch/$s_!IHOT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51303549-53c1-4a3e-8380-c61bf64496b8_1586x644.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Further down the code, we see proof of Visual Basic for Application Macros:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y9SB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y9SB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 424w, https://substackcdn.com/image/fetch/$s_!Y9SB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 848w, https://substackcdn.com/image/fetch/$s_!Y9SB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 1272w, https://substackcdn.com/image/fetch/$s_!Y9SB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y9SB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png" width="1456" height="604" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:604,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!Y9SB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 424w, https://substackcdn.com/image/fetch/$s_!Y9SB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 848w, https://substackcdn.com/image/fetch/$s_!Y9SB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 1272w, https://substackcdn.com/image/fetch/$s_!Y9SB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dfb62ce-29ad-4ccf-96fd-18b2f0c01b47_1696x704.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Then, with the assistance of MOVIE MAGIC (I made that up), we are able to reassemble the malicious document to see there are macros with obfuscation:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JMcW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JMcW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 424w, https://substackcdn.com/image/fetch/$s_!JMcW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 848w, https://substackcdn.com/image/fetch/$s_!JMcW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 1272w, https://substackcdn.com/image/fetch/$s_!JMcW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JMcW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png" width="1456" height="856" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:856,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image" title="image" srcset="https://substackcdn.com/image/fetch/$s_!JMcW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 424w, https://substackcdn.com/image/fetch/$s_!JMcW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 848w, https://substackcdn.com/image/fetch/$s_!JMcW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 1272w, https://substackcdn.com/image/fetch/$s_!JMcW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd83e6ab9-517e-4d49-a9a8-9df4ac38ab1e_2976x1750.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If we look at the Macro above - there are a few important parts that stick out:</p><ol><li><p>This is set to automatically run the &#8220;test&#8221; function/macro on document open.</p></li><li><p>This is also set to automatically run the &#8220;test&#8221; function.</p></li><li><p>This macro is heavily encoded, perhaps to hide the true intent behind the function?</p></li></ol><p>This is <strong>DEFINITELY NOT GOOD</strong></p><p>There should be no reason for this level of encoding for a document of this nature.</p><p>At this point, it may be a good spot to pass this to the next team to begin their steps.</p><h2>THREAT HUNTER TEMPLATE</h2><pre><code><code>Playbook Title: Detecting Enterprise Macro Activity from Emails

Mitre Tactic: T1566, Phishing

Mitre Sub Technique: T1566.001, Spearphishing Attachment

Hypothesis: Employees are targeted with malicious documents with VBA Macro Code and 
some employees will open the documents and detonate the payload

Proposed Detection Query: index IN (zeek,sysmon) (.doc OR .xls OR .docx OR .xlsx) (TrustRecords)
AND NOT (files.magnumtempusfinancial.com)

Simulation Details: NONE

Hunter Limitations/Observation Notes: During several portions of the hunt, we discovered that there 
were log sources (sysmon) that were not properly parsed, which made finding details difficult. If we had these 
parsed properly, we may have found it easier to get some of the data.

Hunt Findings: Three users downloaded the malicious document, two users appear to have
been affected by the payload.
</code></code></pre><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ilovesec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Introspection from an Introverted Information Security Instructor]]></title><description><![CDATA[Lessons from a first-time instructor.]]></description><link>https://ilovesec.substack.com/p/introspection-from-an-introverted</link><guid isPermaLink="false">https://ilovesec.substack.com/p/introspection-from-an-introverted</guid><dc:creator><![CDATA[Joshua Morgan]]></dc:creator><pubDate>Fri, 13 May 2022 18:19:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!buUY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!buUY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!buUY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 424w, https://substackcdn.com/image/fetch/$s_!buUY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 848w, https://substackcdn.com/image/fetch/$s_!buUY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!buUY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!buUY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png" width="1456" height="865" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:865,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Lessons from a first-time instructor.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Lessons from a first-time instructor." title="Lessons from a first-time instructor." srcset="https://substackcdn.com/image/fetch/$s_!buUY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 424w, https://substackcdn.com/image/fetch/$s_!buUY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 848w, https://substackcdn.com/image/fetch/$s_!buUY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!buUY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ed7e8c9-d208-4384-a7f3-e92549d27bca_1876x1114.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the eve before I issue final exams for my students in my class, I&#8217;m taking some time to reflect on lessons learned as a first-time instructor:</p><h2>1. Some say the best way for you to learn something is to teach someone else</h2><p>This is true. There are many concepts that I might not have understood (as my normal day-to-day work does not deal directly with it) but I was able to gain insight into these topics to a degree that I feel far more comfortable discussing them.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you want to see more posts from me, feel free to sign up here or visit me at www.ilovesec.com:</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>2. You know far more than you think you know</h2><p>One of my biggest hurdles in actually accepting the opportunity to teach was being worried about the fact that I wouldn&#8217;t have enough material to cover the time allotted for the class. Fortunately/Unfortunately, I learned that this was not the case, and I ended up getting to a point to where I had too much material and not enough time to cover everything I wanted to. </p><h2>3. Students will surprise you in surprising ways</h2><p>I know I have a passion for information security, and in some sense education. Working in information security, you will learn that what you consider a priority will not always match in priority with others within the business. This is true as well when dealing with students in an academic setting. I have had students ask me about scenarios related to their employment: ways to get management to buy into implementing better security. I&#8217;ve had students give bare minimum, but far more give above and beyond.</p><h2>4. Be EXTREMELY CLEAR in your expectations of students and try to not leave too much up to interpretation.</h2><p>I&#8217;ve learned a few things this semester from students. Students will wait until the last minute to turn something in. Whether or not you accept it is another question. Students will ask what types of questions will be on exams - this one took me by surprise: I just presumed you prepared by understanding the material, not the type/method of exam.</p><h2>5. It&#8217;s easy to drone on about boring topics, so change it up!</h2><p>Yes, we need the basics before diving into deeper topics, but one key thought I now have is to incorporate demonstrations for different things I&#8217;m teaching. If I had the ability to redo this semester, I would incorporate much more of the hands-on - my students really, REALLY seemed to enjoy this aspect.</p><h2>6. You don&#8217;t have to know EVERYTHING</h2><p>One thing I know is that I don&#8217;t know everything. It&#8217;s okay to admit you don&#8217;t know something, but be willing to work to find an answer. I had several questions that stumped me, but I was able to find the answers and get the information to the students Final Notes</p><p>All in all, it was definitely an amazing experience and one that has opened my eyes to further teaching in this industry. I&#8217;m looking forward to my next opportunity to share my knowledge with others.</p><h1>Connections</h1><p>Thank you for taking the time out of your daily life to read this. If any of this resonates with you, I encourage you to reach out and connect with me:</p><ul><li><p>Website: <a href="https://www.ilovesec.com">https://www.ilovesec.com</a></p></li><li><p>BlueSky: <a href="https://bsky.app/profile/ilovesec.com">https://bsky.app/profile/ilovesec.com</a></p></li><li><p>Mastodon: <a href="https://infosec.exchange/@Samunoske">https://infosec.exchange/@Samunoske</a></p></li><li><p>Github: <a href="https://github.com/samunoske">https://github.com/samunoske</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/in/thejoshuamorgan">https://www.linkedin.com/in/thejoshuamorgan</a></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ilovesec blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is your passion?]]></title><description><![CDATA[What is your TRUE passion?]]></description><link>https://ilovesec.substack.com/p/what-is-your-passion</link><guid isPermaLink="false">https://ilovesec.substack.com/p/what-is-your-passion</guid><dc:creator><![CDATA[Joshua Morgan]]></dc:creator><pubDate>Sun, 01 Jul 2018 18:42:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hZ7G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hZ7G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hZ7G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 424w, https://substackcdn.com/image/fetch/$s_!hZ7G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 848w, https://substackcdn.com/image/fetch/$s_!hZ7G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 1272w, https://substackcdn.com/image/fetch/$s_!hZ7G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hZ7G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png" width="1456" height="796" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:796,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2221682,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ilovesec.substack.com/i/164428196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hZ7G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 424w, https://substackcdn.com/image/fetch/$s_!hZ7G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 848w, https://substackcdn.com/image/fetch/$s_!hZ7G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 1272w, https://substackcdn.com/image/fetch/$s_!hZ7G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e75d53-185f-4ed5-b683-aabaf3634b03_1722x942.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>What is your passion? I have been asked this question so many times. So many times I&#8217;ve replied with the most obvious choice for me - technology. While this is somewhat true, it doesn&#8217;t tell the whole story. Well, at least my whole story.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ilovesec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>My first passion that I can remember was writing. When I was younger, I had planned to become a writer. I wrote all the time: poetry, short stories, fiction. I was certain I would become a professional writer sometime. Along the way through my life the plans shifted and took me down another path towards the technology world and another passion.</p><p>Computers made complete sense to me. I could figure things out quickly and help others to be better with computers. Could this be my calling? I loved working with computers and from Middle School through High School, I found myself as the go-to for all problems computer or tech related. I loved it. I get to mess with computers all the time and help others - what an awesome thing. Teachers would ask me for help with new gadgets and computer programs. What I didn&#8217;t realize is that while cultivating my love for technology, I was cultivating my ultimate passion: helping others.</p><p>It is important to realize that being able to pursue your passion can help to make your life more fulfilling. Easier said than done, I know. Find a way to incorporate your passion into what you do day-to-day. If it&#8217;s writing, write a little bit each day. If it&#8217;s gardening, plant a garden. If it&#8217;s photography, go take awesome photos. Hiking? Go hike. I&#8217;m lucky that I get to work in some capacity every day to help at least one person. I get to think outside the box to get something accomplished. At the end of the day, I get to teach others about my passions: helping others and technology.</p><p>Now that I&#8217;ve finished my Degree path, I can now try to combine the two passions with my original passion, writing and my newest passion: security.</p><p>So, I ask you: What is your passion - <strong>and what can you do to cultivate it</strong>?</p><h1>Connections</h1><p>Thank you for taking the time out of your daily life to read this. If any of this resonates with you, I encourage you to reach out and connect with me:</p><ul><li><p>Website: <a href="https://www.ilovesec.com">https://www.ilovesec.com</a></p></li><li><p>BlueSky: <a href="https://bsky.app/profile/ilovesec.com">https://bsky.app/profile/ilovesec.com</a></p></li><li><p>Mastodon: <a href="https://infosec.exchange/@Samunoske">https://infosec.exchange/@Samunoske</a></p></li><li><p>Github: <a href="https://github.com/samunoske">https://github.com/samunoske</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/in/thejoshuamorgan">https://www.linkedin.com/in/thejoshuamorgan</a></p></li></ul><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ilovesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ilovesec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>