I was recently asked to write a brief guest blog entry on Recorded Future about some of the work I've done with Threat Watch, as well as present on the topic at the Recorded Future Users Network (RFUN2013) conference.
For those interested, the blog entry has been posted on Recorded Future's blog. Also, the slides for my RFUN2013 presentation are now available here.
This Blog has Moved!
This blog is moving to
Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label OSINT. Show all posts
Showing posts with label OSINT. Show all posts
Using Shodan to Measure The Security of the Internet
Shodan is a search engine for potentially vulnerable computer systems, based upon header information.
It allows you to perform a lot of neat tricks, such as see what your organization's public footprint looks like, as well as your competitors. You can use it to find interesting devices such as routers, webcams, printers, etc.
I performed the following searches to see just how many glaringly obvious vulnerable systems are exposed to the internet.
First search: "IIS/5.0". This search will produce systems which are running Windows 2000 with an IIS web server. Of course Windows 2000 and IIS 5.0 are no longer supported by Microsoft, and multiple vulnerabilities are publicly known.
So needless to say, I was quite disturbed when I found half a million exposed IIS/5.0 webservers.
Surely no one would be running a version of Windows older than Win 2000, and connect it to the Internet, right?
It allows you to perform a lot of neat tricks, such as see what your organization's public footprint looks like, as well as your competitors. You can use it to find interesting devices such as routers, webcams, printers, etc.
I performed the following searches to see just how many glaringly obvious vulnerable systems are exposed to the internet.
First search: "IIS/5.0". This search will produce systems which are running Windows 2000 with an IIS web server. Of course Windows 2000 and IIS 5.0 are no longer supported by Microsoft, and multiple vulnerabilities are publicly known.
So needless to say, I was quite disturbed when I found half a million exposed IIS/5.0 webservers.
![]() |
| IIS 5.0 on Windows 2000 |
Identifying Hacker Group Locations Based Upon Temporal Signatures
What day and time an event occurs can sometimes be very helpful in determining the origin of that event.
Analysis Intelligence just posted an excellent article titled "Pattern of Life and Temporal Signatures of Hacker Organizations".
This article explores the possibilities of using the day/time of hacking activity to determine not only what part of the world the activity originated from, but also if they're a state sponsored group or not.
I highly encourage you to check out the article, and if applicable, apply it to your own research.
Analysis Intelligence just posted an excellent article titled "Pattern of Life and Temporal Signatures of Hacker Organizations".
This article explores the possibilities of using the day/time of hacking activity to determine not only what part of the world the activity originated from, but also if they're a state sponsored group or not.
I highly encourage you to check out the article, and if applicable, apply it to your own research.
The NSA's Guide to Internet Research
The NSA recently released on their Declassification and Transparency page "Untangling The Web - A Guide to Internet Research".
This 642 page document contains search techniques and tips for everything from basic search fundamentals to "Google Hacking" and even how to find information on the "Invisible" internet.
This 642 page document contains search techniques and tips for everything from basic search fundamentals to "Google Hacking" and even how to find information on the "Invisible" internet.
Guest Post: I Can Have Most of My Threat Research Tools in a Single Interface?
The following is a guest post submitted to Caffeine Security. The owner of Caffeine Security is not responsible for its content. This post is being shared because I feel this has the potential to be a very informative webinar. I previously attended a TrainACE "Hacker's Breakfast" which you can read about in a previous post.
The answer is “Yes”! Join Advanced Security by TrainACE in this FREE, hour long webinar covering a few aspects of Advanced Threat Intelligence. During this webinar, you’ll be part of a live demo analysis of suspected malicious URL. Each malicious URL has the potential to completely cripple a company’s network infrastructure and it’s important that any string which looks suspicious be fully analyzed before it falls into the hands of an unsuspecting victim. Attendees will also be shown how to effectively complete the majority of threat research from a single interface. Compiling all data into one spot will make it more manageable and make analysis much more effective. REGISTER HERE NOW; space is limited!
TrainACE is an IT Certification and cyber security training company. This is only one of many free hacking tutorials they provide to the public. They also host regular meet-ups and events to discuss the latest and greatest topics in cyber security.
About the Author
This is a guest post from Megan Horner, Marketing Coordinator at TrainACE. TrainACE offers advanced cyber security training such as Mobile Hacking and Wireless Security. Follow TrainACE on Twitter @pentesttraining.
The answer is “Yes”! Join Advanced Security by TrainACE in this FREE, hour long webinar covering a few aspects of Advanced Threat Intelligence. During this webinar, you’ll be part of a live demo analysis of suspected malicious URL. Each malicious URL has the potential to completely cripple a company’s network infrastructure and it’s important that any string which looks suspicious be fully analyzed before it falls into the hands of an unsuspecting victim. Attendees will also be shown how to effectively complete the majority of threat research from a single interface. Compiling all data into one spot will make it more manageable and make analysis much more effective. REGISTER HERE NOW; space is limited!
TrainACE is an IT Certification and cyber security training company. This is only one of many free hacking tutorials they provide to the public. They also host regular meet-ups and events to discuss the latest and greatest topics in cyber security.
About the Author
This is a guest post from Megan Horner, Marketing Coordinator at TrainACE. TrainACE offers advanced cyber security training such as Mobile Hacking and Wireless Security. Follow TrainACE on Twitter @pentesttraining.
Ingredients:
Cyber Intelligence,
Guest Post,
OSINT,
Threat Watch
Voices in the Static: Proactive Cyber Threat Monitoring
Your network is under attack. Right now. This very moment your public facing IP address space is being scanned and probed by someone. In fact, the entire Internet is being scanned by so many malicious attackers on a 24/7 basis that the most amount of time an unprotected computer can hope to last on the Internet without being compromised is seven minutes according to SANS.
So what can you do to help determine what threats to monitor for and which ones to ignore?
Read my Guest Blog Post at Recorded Future to find out more!
So what can you do to help determine what threats to monitor for and which ones to ignore?
Read my Guest Blog Post at Recorded Future to find out more!
Ingredients:
Cyber Intelligence,
OSINT,
Security,
Threat Watch
Threat Watch Updated with Cyber Threat Forecasting
Thanks to the folks at RecordedFuture I have updated the Threat Watch page with a 90 day cyber threat forecast monitor.
The monitor is also reproduced in this post below:
Cyber Threat Forecast - Next 90 Days via Recorded Future
The monitor is also reproduced in this post below:
Cyber Threat Forecast - Next 90 Days via Recorded Future
Ingredients:
Cyber Intelligence,
OSINT,
Security,
Threat Watch
Facebook Graph Search and OSINT
Facebook Graph Search is one of the newest features of Facebook. It allows you to data-mine every person and page on the entire social network. You can get an introduction at this page.
It's not available for everyone yet...but you can sign up for early access if you'd like. It is extremely powerful as an OSINT (Open Source Intelligence) tool. A tumblr site called Acutal Facebook Graph Searches show some of the more interesting search results.
It's not available for everyone yet...but you can sign up for early access if you'd like. It is extremely powerful as an OSINT (Open Source Intelligence) tool. A tumblr site called Acutal Facebook Graph Searches show some of the more interesting search results.
Identity of @th3j35t3r Revealed
While this post is not directly related to security...I felt it was worth sharing with others.
Who is th3j35t3r? That's the million dollar question now isn't it?
For those not familiar th3j35t3r is a cyber-activist known for attacking known terrorist websites as well as Westboro Baptist Church and factions of Anonymous.
There have been many attempts to identify the true identity of th3j35t3r...but according to him none have been correct.
The endless attempts to find th3j35t3r's true identity has become a humorous game for him...to the point that he has set his Twitter background picture to supposedly contain an encrypted version of his full identity.
Who is th3j35t3r? That's the million dollar question now isn't it?
For those not familiar th3j35t3r is a cyber-activist known for attacking known terrorist websites as well as Westboro Baptist Church and factions of Anonymous.
There have been many attempts to identify the true identity of th3j35t3r...but according to him none have been correct.
The endless attempts to find th3j35t3r's true identity has become a humorous game for him...to the point that he has set his Twitter background picture to supposedly contain an encrypted version of his full identity.
Threat Watch updated to include Malware Indicator Trends
I've updated the Threat Watch page to include global home-based malware infection indicators.
Please note that this feature is still experimental.
You can also read more about how I created this map and graph.
Subscribe to:
Posts (Atom)

