View Topics

Incident Response
5 minutes
4 Top Cyber Threats to the Finance and Insurance Industries
Cyberattackers follow the money. Read on to discover the top cyber threats for financial and insurance services seen in 2021.

Incident Response
8 minutes
3 Ways to Save Incident Response Time
Save time during incident response with these tips and tools to help your team accelerate HD, memory, and live forensics.

Cloud Security
10 minutes
Make your First Malware Honeypot in Under 20 Minutes
A honeypot is a powerful tool for threat intelligence. Collecting malware from attackers in a controlled environment helps stay one step ahead of stopping real attacks.

Threat Hunting
7 minutes
Detection Rules for Sysjoker (and How to Make Them With Osquery)
Using osquery to create detection rules for SysJoker can help you determine whether any of your systems are affected. SysJoker is otherwise undetected as Linux and macOS variants by any scanning engines on VirusTotal as of this publication.

Research
9 minutes
New SysJoker Backdoor Targets Windows, Linux, and macOS
In December 2021, we discovered a new multi-platform backdoor that targets Windows, Mac, and Linux that we have named SysJoker.

Malware Analysis
11 minutes
Malware Reverse Engineering for Beginners - Part 1: From 0x0
Reverse engineering is an integral part of malware analysis and research - get started learning this advanced skill to investigate malware.

Malware Analysis
8 minutes
The Role of Malware Analysis in Cybersecurity
Security analysts use a variety of methods and tools to analyze suspicious files and endpoints in search of malware.

Malware Analysis
16 minutes
All Your Go Binaries are Belong to Us
Extract hidden metadata in binaries produced by the Go compiler and learn how it can be used to determine if an application uses a vulnerable dependency.

Malware Analysis
9 minutes
The State of Malware Analysis
Learn about malware analysis tools, their challenges, and what to look for when choosing the right solution.

Incident Response
10 minutes
New Type of Supply Chain Attack Could Put Popular Admin Tools at Risk
Registered retired usernames in GitHub could allow attackers to inject code into popular Golang projects and infect a large number of users.

Cloud Security
4 minutes
Conducting Digital Forensics Incident Response (DFIR) on an Infected GitLab Server
GitLab servers are under attack with a now-patched critical vulnerability.

Cloud Security
3 minutes
Exposed Prefect Workflows Could Lead to Disruptive Attacks
Hundreds of misconfigured Prefect instances could be the target of cyber attacks. Verify your instances are not exposed to the internet and enable MFA.

Cloud Security
11 minutes
Misconfigured Airflows Leak Thousands of Credentials from Popular Services
Misconfigured Apache Airflows expose credentials for popular services including Slack, PayPal and AWS. Airflow is the #1 rated open-source workflow project.




