-
Part 1 explained how ClickFix and TerminalFix work from the attacker’s perspective. In Part 2, we recreate the complete attack chain in a controlled environment, following the stages described in the BSI paper. For each stage, we also look at which security controls could have prevented or stopped the attack. Part 3 focuses on detection:…
-
ClickFix Did It Again We’ve been tracking ClickFix and its growing family of variants in our SOC for about two years now. At some point last year, our SOC colleagues were already wondering if ClickFix was still worth talking about. By now, you might expect both security teams and users to know one simple rule:…
-
The security of HTTPS rests on the trustworthiness of certificate authorities (CAs). While it is highly unlikely that cyber criminals breach a public CA and issue a certificate without being detected, internal CAs are a different story. In fact, Active Directory Certificate Services (ADCS) is well-known for its misconfigurations.Most prior research targeted client authentication certificates,…
-
Scalable Forensics for Business Email Compromise in Microsoft 365 with MAGIC, Timesketch and Jupyter
·
How to use MAGIC, Timesketch, and Jupyter for scalable Business Email Compromise investigations in Microsoft 365.