CVE-2021-31166: RCE in Microsoft HTTP.sys

Network Detection for ZeroLogon CVE-2020-1472

ZeroLogon has quickly become popular and well known because of multiple proofs of concept and ...

Read More

Citrix ADC/Netscaler - CVE-2019-19781

The Citrix vulnerability (CVE-2019-19781) was first identified in December of 2019. This ...

Read More

Detecting Malicious Behavior by Unmasking WebSockets

WebSockets allow a single TCP connection to have full duplexing communications. This type of ...

Read More

Decoding Hancitor Malware with Suricata and Lua

Many types of malware send and receive data via HTTP. They may either be sending updates back to ...

Read More

Inspecting Encrypted Network Traffic with JA3

Part of our job as security researchers is keeping up with new tools and techniques used to monitor ...

Read More

Petya From The Wire: Detection using IDPS

Most malware that traverses a network do so with specific indicators, some of which look like ...

Read More

Advanced Malware Detection with Suricata Lua Scripting

Normal IDPS signatures using either Snort or Suricata have quite a few options and, if regex is ...

Read More

Google Summer of Code (GSoC) + OWASP + ModSecurity = Awesome

OWASP is again participating in the Google Summer of Code (GSoC) Program for 2014 by acting as a ...

Read More