CuratedIntel Profile Banner
Curated Intelligence Profile
Curated Intelligence

@CuratedIntel

Followers
14K
Following
145
Media
37
Statuses
406

Bringing together intelligence researchers and incident responders. #TrackThePlanet

Joined September 2020
Don't wanna be here? Send us removal request.
@CuratedIntel
Curated Intelligence
5 months
ICYMI: In October 2024, we released the CTI Research Guide. It aims to help practitioners learn more about how to effectively perform the collection, processing, analysis, and production stages of the CTI lifecycle. 🔗
Tweet media one
1
21
62
@CuratedIntel
Curated Intelligence
4 months
RT @cPeterr: Reviving my blog with a complete analysis of the latest #LockBit #ransomware v4.0 Green! 🤠. h/t to @f….
0
89
0
@CuratedIntel
Curated Intelligence
5 months
⚠️PSA: VPN & RDWeb password guessing attacks have been observed originating from IP addresses consistently across the following subnets:. 85.239.59.0/24.85.239.58.0/24 .85.239.57.0/24.85.239.56.0/24. ➡️ Check for low & slow password guessing attempts and successful logins.
2
3
16
@CuratedIntel
Curated Intelligence
5 months
Related articles.1. 2. 3.
0
0
6
@CuratedIntel
Curated Intelligence
5 months
⚠️PSA: Curated Intel members in DFIR have noticed a trend in exploitation of CVE-2024-57727 in the SimpleHelp RMM tool to deploy Medusa ransomware. ➡️ This tool is often used by IT Managed Service Providers (MSPs) to remotely control customer endpoints and have been impacted.
2
20
45
@CuratedIntel
Curated Intelligence
9 months
RT @BushidoToken: Got a new project to share later this year which will be published via @CuratedIntel — a community of researchers that ar….
0
4
0
@CuratedIntel
Curated Intelligence
11 months
⚠️PSA: Curated Intel DFIR has noticed a new trend among Akira Ransomware cases in Summer 2024. For a while, Akira has been exploiting Cisco ASA devices. ➡️ They are now targeting SonicWall SSL-VPNs for access with no MFA (!) and weak passwords (!). Other TTPs remain the same 🔍.
0
26
51
@CuratedIntel
Curated Intelligence
11 months
RT @BushidoToken: PSA from the @CuratedIntel Community to the CTI industry — watch out for cybercrime groups seeking access to your vendor….
0
28
0
@CuratedIntel
Curated Intelligence
1 year
⚠️PSA: Curated Intel DFIR teams noticed a severe uptick in Akira Ransomware cases in Jan 2024. Same repeated TTPs:.- Dwell times of < 4 hours on average.- Cisco ASA VPN for Access.- WinSCP for exfil / WinRAR for compression.- AnyDesk RMM for persistence.- 'w.exe' Akira payload.
5
61
184
@CuratedIntel
Curated Intelligence
1 year
Our friends at CSIRT-CTI have published their first new blog, stay tuned for more APT research from them!.
0
18
60
@CuratedIntel
Curated Intelligence
2 years
Come along to the first ever Curated Intel workshop. There will also be prizes for the best profile! #CTI.
@BushidoToken
Will
2 years
My upcoming CTI workshop: 'Keep Your Enemies Closer: How to Profile and Track Threat Actors' at #BSidesLondon2023 is live!
Tweet media one
0
1
9
@CuratedIntel
Curated Intelligence
2 years
🌐 Curated Intel is tracking hacktivist, cybercriminal, and regional APT groups surrounding the war in Israel. We describe the types of campaigns and attacks we've observed so far and have also provided recommendations for CTI analysts monitoring the war.
Tweet media one
2
50
113
@CuratedIntel
Curated Intelligence
2 years
RT @BushidoToken: We had some good convos in the @CuratedIntel community today based on this @thecyberwire interview. Really interesting th….
0
9
0
@CuratedIntel
Curated Intelligence
2 years
RT @Kostastsale: A Day in the Life of a CISO
0
128
0
@CuratedIntel
Curated Intelligence
2 years
Pure facts #CTI.
@uuallan
Allan “Ransomware Sommelier🍷” Liska
2 years
@BushidoToken @aejleslie @Gi7w0rm @AlvieriD @AJVicens @kevincollier @ddd1ms The thing that makes this profession hard sometimes is that victims lie about attacks, the criminals are lying pieces of shit, and randos on Twitter lie about what they know. Trying to get through the lies to the truth is a big challenge.
0
0
11
@CuratedIntel
Curated Intelligence
2 years
RT @svch0st: @phillmoore and I posted a blog on a TTP observed in an #Akira Ransomware case. ➡️ Actor gains access to Hyper-V server (with….
0
43
0
@CuratedIntel
Curated Intelligence
2 years
RT @BushidoToken: TL;DR of ALPHV/BlackCat's essay on the MGM breach.- The attack began ~8 Sept. - They stole data and gained admin on their….
0
145
0
@CuratedIntel
Curated Intelligence
2 years
RT @BushidoToken: ⚠️ Use Microsoft Teams? Watch out for TeamsPhisher!. While it is not usually possible to send files to MS Teams users out….
0
145
0
@CuratedIntel
Curated Intelligence
2 years
RT @BushidoToken: 🆕 Pleased to share my latest blog for SANS FOR589: Cybercrime Intelligence 👾. We reviewed the latest cybercrime intrusion….
0
48
0
@CuratedIntel
Curated Intelligence
2 years
RT @TheDFIRReport: HTML Smuggling Leads to Domain Wide Ransomware. ➡️Initial Access: Thread-Hijacked Email > HTML Attachment.➡️Credentials:….
0
170
0