Endpoint Security Platform Updates 5 Open Source Malware Tools You Should Have in Your Arsenal November 28, 2016 / July 6, 2026 by arpit Analysts use open source malware analysis tools to protect from and predict future attacks and to share knowledge among each other. It’s no secret that distributing malware is a big business and the rapidly rising malware epidemic is only going to grow in ability and efficiency in the coming years. As malware trading forums proliferate […] Read more » Malware
Platform Updates Security Operations SOC automation: Can incident response live without it? November 3, 2016 / July 6, 2026 by arpit The SOC – a New Vision with New Challenges The concept of a security operations center (SOC) is increasing in popularity. Many large enterprises have established SOCs, and others are in the planning process. SOCs maximize enterprise security impact by consolidating and centralizing cyber security incident prevention, detection and response across the entire organization. They also […] Read more » SOC Automation
Cybersecurity Training Platform Updates The Cyber Range – Addressing the “Security Tools Fatigue” September 21, 2016 / July 6, 2026 by arpit Seems like the IT security industry is booming. Enterprises are continuously increasing their IT security budgets and Gartner estimates that IT security spending will rise from $75 billion-plus in 2015 to $101 billion in 2018. Organizations have established their security operation centers (SOCs) and ramped up their security teams and the CISO has become an […] Read more » Cyber Simulation Cyber Training Range
Endpoint Security Platform Updates Anti-VM and Anti-Sandbox Explained August 5, 2016 / July 6, 2026 by arpit | 99 Comments on Anti-VM and Anti-Sandbox Explained This article is intended for malware analysts, investigators, and security system developers, and explains the key tactics used by malware authors to detect and evade virtual environments often used in the security analysis process. The article will detail the key anti-VM tactics we’ve encountered during our research activity and will provide information allowing you to: […] Read more » Sandbox
Endpoint Security Platform Updates Locky Ransomware: New Evasion Techniques Discovered June 30, 2016 / July 6, 2026 by arpit | 95 Comments on Locky Ransomware: New Evasion Techniques Discovered Cyberbit’s Advanced Malware Research Group has recently discovered new evasion techniques used in the new Locky ransomware campaign. Locky, one of the most dominant ransomware, has recently reappeared in the wild after a pause of several weeks. The new campaign introduces new techniques for evading automatic analysis systems, such as virtualized sandboxes. FireEye analyzed one […] Read more » Locky Ransomware
OT Security Platform Updates How this Attack on a German SCADA Network Could Have Been Prevented June 23, 2016 / July 6, 2026 by arpit | 110 Comments on How this Attack on a German SCADA Network Could Have Been Prevented In December, 2014 the German Federal Office for Information Security notified about a malicious attack on a steel mill operated by a German based company. The attack was initiated using spear phishing. Attackers gained access to the corporate network and moved into the plant network. According to the report, the adversary, showing extensive knowledge of […] Read more »
Endpoint Security Platform Updates Serialization Vulnerabilities Explained June 6, 2016 / July 6, 2026 by arpit | 90 Comments on Serialization Vulnerabilities Explained Remote code execution Overview Serialization is a useful and widely supported feature. However, it also provides an easy target for hackers to try and execute malicious commands using the external shell. This article will demonstrate, by using code samples, how serialization vulnerabilities can be exploited to execute commands remotely, and how, by implementing secure coding […] Read more »
Endpoint Security Platform Updates Unpacking Dyre Part I May 29, 2016 / July 6, 2026 by arpit | 97 Comments on Unpacking Dyre Part I Edited by Alon Slotky Dyre had become one of the most dangerous financial Trojans, targeting login credentials for banks accounts and other online services via Man-in-the-Browser exploits. In this post we will look into the mechanism of Dyre unpacking its own code. Dyre executes an obfuscated shellcode from its own .text section. In the flow […] Read more »