Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Ahead With Linux Security Features

Filter%20icon Refine features
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security features

We found 2 articles for you...
102

LinuxSecurity.com Major Update for Improved Threat Discovery and Research

LinuxSecurity.com has been part of the Linux and open-source security community since the late 1990s. Over the years, the platform has evolved alongside the Linux threat landscape itself — from the early days of mailing lists and isolated vulnerability disclosures to today’s nonstop cycle of advisories, exploit research, malware reporting, supply chain attacks, and infrastructure-focused threat intelligence. . For many readers, LinuxSecurity.com became more than just a news site. It became a long-running research archive used to track vulnerabilities, investigate Linux threats, review hardening guidance, and stay current on operational security risks affecting enterprise systems, cloud environments, and open-source infrastructure. But the way security professionals research information has changed dramatically. Modern Linux security investigations rarely happen inside a single article or isolated advisory feed. Security teams move rapidly between vulnerability disclosures, mitigation guidance, malware analysis, hardening documentation, threat reporting, and historical research while trying to understand exposure and respond quickly. The previous platform no longer reflected that workflow. So we rebuilt LinuxSecurity.com from the ground up with a stronger focus on discoverability, connected research, faster navigation, and operational threat visibility. The new platform was designed to help Linux administrators, security teams, researchers, and open-source professionals move naturally between advisories, HOWTOs, feature analysis, archived research, and emerging threat coverage without constantly fighting disconnected archives or fragmented navigation. The mission itself has not changed. LinuxSecurity.com remains focused on delivering Linux security news, open-source threat intelligence, vulnerability awareness, practical hardening guidance, and security education for the Linux community. The difference is that the platform is now built to support the way modern Linux securityresearch actually happens. A Better Way to Explore Linux Security Topics The updated LinuxSecurity.com platform was redesigned around the realities of modern Linux security research workflows. Instead of forcing readers to manually navigate disconnected archives, static categories, or isolated article feeds, the new structure organizes content around related security topics, operational workflows, and active threat intelligence. Whether readers are researching SSH hardening, privilege escalation, Linux malware, OpenSSL vulnerabilities, cloud exposure, container security, or supply chain threats, the platform now helps surface connected advisories, tutorials, feature analysis, and historical research within a unified experience. The goal is not simply faster navigation. It is to create a faster understanding. Readers can now move more naturally between vulnerability disclosures, mitigation strategies, hardening guidance, malware reporting, and related Linux security coverage during active investigations without losing research continuity or context. The updated structure also improves visibility into ongoing Linux security activity by making advisories, trending topics, distribution-specific vulnerability reporting, featured analyses, and archived research easier to discover directly on the homepage and in topic hubs. LinuxSecurity Features The Features section was redesigned to highlight deeper Linux security analysis, investigative reporting, and long-form technical coverage focused on real-world operational risk. Readers can explore in-depth articles examining vulnerability trends, malware activity, supply chain threats, Linux hardening strategies, cloud security exposure, infrastructure attacks, and broader developments affecting the Linux and open-source security landscape. Rather than focusing solely on breaking disclosures, Features provide additional context on how vulnerabilities are exploited, why operational failures persist, and how organizations can strengthentheir defensive posture across Linux environments. The updated structure also improves discovery of related research, helping readers move between advisories, technical guidance, historical analysis, and current threat reporting during ongoing investigations. LinuxSecurity Advisories Streamlined access to vulnerability reports and security updates. The redesigned Advisories section gives readers direct access to Linux vulnerability disclosures and distribution-specific security updates without forcing them to dig through fragmented archives or disconnected feeds. Advisories are now easier to browse by distribution, topic, and publication date, helping administrators quickly identify patches and exposure affecting their environments. Readers can move between current vulnerability activity, related advisories, and connected Linux security coverage more naturally while tracking emerging threats across Debian, Ubuntu, Fedora, openSUSE, Rocky Linux, Slackware, Gentoo, Oracle Linux, and additional distributions. The updated interface also improves visibility into ongoing advisory activity by surfacing recent searches, trending topics, and newly published security updates directly from the main advisory hub. LinuxSecurity HOWTOs Practical, step-by-step hardening and configuration guidance. The LinuxSecurity HOWTOs section was redesigned to make technical hardening guidance easier to discover and apply during active security investigations. Readers can quickly access step-by-step walkthroughs covering Linux hardening, access control, file integrity monitoring, container security, SSH configuration, CI/CD security, and cloud infrastructure protection. Rather than existing as isolated tutorials, HOWTOs are now more tightly connected to related advisories, malware reporting, and feature analysis, allowing readers to move directly from vulnerability awareness into actionable remediation and defensive implementation guidance. LinuxSecurity News The LinuxSecurity News section wasredesigned to provide faster visibility into ongoing Linux security developments, vulnerability disclosures, malware activity, and emerging open-source threats affecting enterprise and infrastructure environments. Readers can now more quickly monitor active Linux security discussions, follow evolving attack trends, and explore timely reporting covering cloud security, supply chain risk, privilege escalation, ransomware activity, infrastructure compromise, and operational security issues impacting Linux systems. The updated layout also improves access to trending stories, featured reporting, and related security coverage, helping readers stay informed without constantly sorting through fragmented security feeds or disconnected news archives. By surfacing current Linux security developments more effectively, the platform helps administrators, researchers, and security professionals maintain stronger awareness of rapidly evolving threats across the open-source ecosystem. LinuxSecurity Newsletters LinuxSecurity.com newsletters were redesigned to help readers stay informed on meaningful Linux security developments without needing to constantly monitor dozens of separate advisory feeds, threat intelligence sources, and open-source security discussions throughout the week. Subscribers receive curated coverage focused on Linux vulnerability advisories, malware reporting, open-source threat intelligence, hardening guidance, cloud security risks, infrastructure attacks, and newly published HOWTOs and feature analysis. Some weeks focus heavily on patching activity, disclosure tracking, and active vulnerabilities. Other weeks center around operational failures, evolving attacker techniques, Linux malware trends, or recurring security mistakes that continue to expose enterprise infrastructure and cloud environments. The goal is simple: surface the Linux security developments that matter most and make them easier to review quickly during busy operational workflows. For administrators,researchers, and security professionals already using LinuxSecurity.com during vulnerability response and ongoing research, the newsletters provide a steady stream of connected security intelligence tied directly to the platform’s broader advisory and threat coverage. LinuxSecurity Security Dictionary The LinuxSecurity Security Dictionary was expanded to serve as a practical reference resource for Linux administrators, researchers, and security professionals navigating complex security terminology during active investigations and ongoing research. The dictionary provides organized definitions and contextual references covering vulnerability terminology, malware concepts, encryption methods, access control models, authentication technologies, attack techniques, and broader cybersecurity terminology frequently encountered throughout Linux security operations. Rather than functioning as a simple glossary, the Security Dictionary helps readers better understand the technical language surrounding advisories, hardening guidance, threat reporting, and feature analysis published across the platform. The updated structure also improves navigation and discoverability, making it easier to quickly reference unfamiliar terms while researching vulnerabilities, reviewing threat intelligence, or investigating operational security issues. LinuxSecurity Polls LinuxSecurity Polls were redesigned to encourage greater community participation while helping surface real-world perspectives from Linux administrators, security professionals, researchers, and open-source users across the broader Linux ecosystem. Poll topics focus on operational security priorities, Linux adoption, hardening practices, infrastructure management challenges, defensive tooling, and evolving security concerns affecting modern Linux environments. Beyond simple engagement, polling data provides additional visibility into how security professionals are approaching ongoing operational risks, vulnerability management, cloudsecurity, and system hardening across real-world deployments. The updated polling experience also creates more opportunities for readers to participate in broader Linux security discussions happening throughout the platform. About Us The About Us section was redesigned to provide additional context around LinuxSecurity.com’s long-standing role within the Linux and open-source security community. Readers can learn more about the platform’s history, editorial mission, research focus, and ongoing commitment to delivering practical Linux security guidance, vulnerability awareness, open-source threat intelligence, and educational security coverage for the broader Linux ecosystem. The updated section also highlights LinuxSecurity.com’s relationship with Guardian Digital and its continued focus on supporting Linux administrators, developers, researchers, and enterprise security teams with reliable security-focused reporting and operational guidance. As Linux threats continue evolving across enterprise infrastructure, cloud environments, and open-source software ecosystems, the platform remains committed to helping readers stay informed on the vulnerabilities, hardening practices, malware activity, and defensive strategies shaping Linux security today. Distribution-Specific Advisories LinuxSecurity.com now organizes advisories by Linux distribution to help administrators and security teams identify relevant vulnerability disclosures and patch activity faster during active operational workflows. Readers can quickly review advisories affecting Debian, Debian LTS, Fedora, Gentoo, Mageia, Oracle Linux, openSUSE, Rocky Linux, Slackware, SuSE, Ubuntu, and additional Linux distributions without manually filtering through unrelated security updates. This structure improves visibility into distribution-specific exposure while helping organizations track vulnerabilities, package updates, and patching activity affecting their environments more efficiently. By separating advisory coverageby distribution, the platform also makes it easier to monitor recurring vulnerability trends, identify software components that are actively targeted, and track ongoing Linux security developments across the broader open-source ecosystem. AI-Powered Search and Topic Discovery The new AI-powered search and topic discovery system was designed to reduce the amount of manual research required during active Linux security investigations. Instead of forcing readers to navigate disconnected archives, isolated advisories, or fragmented category structures, the updated platform connects related content dynamically across advisories, HOWTOs, feature analysis, malware reporting, historical research, and broader threat intelligence coverage. Readers researching topics such as SSH hardening, OpenSSL vulnerabilities, Linux privilege escalation, systemd abuse, container security, ransomware activity, supply chain attacks, or cloud exposure can now uncover connected tutorials, advisories, and threat analysis within a unified research experience. The updated search experience also includes refined filtering and discovery tools that allow readers to narrow results by: Topics and categories Authors Publication dates HOWTO-specific criteria Related Linux security subjects This connected discovery model helps security professionals move more naturally between vulnerability intelligence, defensive guidance, operational hardening, and historical Linux security research during active investigations. The result is a more continuous research workflow that surfaces both current threat activity and foundational Linux security knowledge that may still remain operationally relevant today. Faster Visibility Into Emerging Linux Threats Our homepage was redesigned to provide faster visibility into ongoing Linux security activity while making active threat coverage easier to follow throughout the platform. Readers can now quickly explore: Weekly vulnerability activity Trending securitytopics Featured Author’s Choice coverage Recent advisories Active Linux security discussions Current threat reporting The previous homepage often made important information difficult to surface consistently, especially during busy vulnerability cycles where new advisories and threat coverage were published rapidly throughout the week. The updated experience makes it easier to identify active security developments quickly while connecting related coverage together more naturally. Readers can now monitor vulnerability activity, malware reporting, trending Linux security discussions, and recent advisories from a single location without constantly digging through disconnected archives or categories. The updated platform was designed to support the way modern security research actually happens, moving quickly between advisories, tutorials, threat analysis, hardening guidance, and related vulnerabilities during the same investigation. Bringing Archived Security Research Back Into View LinuxSecurity.com contains decades of Linux and open-source security coverage, much of which remains highly relevant today. Older hardening guides, technical explainers, and vulnerability research can sometimes be difficult to rediscover over time, even when the information itself remains useful. The new platform structure helps reconnect archived knowledge with current advisories, modern threat reporting, and newer tutorials, making foundational security guidance easier to surface during active research. As a result, older Linux hardening articles can now appear alongside newer vulnerability coverage whenever the topics overlap, allowing readers to discover both historical context and current threat intelligence within the same research flow. Improved Mobile Navigation and Article Experience Linux security research doesn’t always happen from a desktop. The new LinuxSecurity.com experience was also designed to make long-form technical content easier to navigate on mobile devices. Articlesnow include features like “In This Article” navigation, allowing you to quickly jump between sections without scrolling through an entire page. Whether you’re looking for: mitigation steps detection guidance vulnerability details hardening recommendations command examples You can move directly to the information you need faster. We are excited to welcome readers to the new LinuxSecurity.com and look forward to continuing to deliver the Linux security news, research, tutorials, and threat coverage the community relies on every day. Thank You for Supporting LinuxSecurity.com Whether you have been using LinuxSecurity.com for years or are discovering the platform for the first time, we’re glad to have you here. The new LinuxSecurity.com was rebuilt to better support the way today’s Linux administrators, researchers, and security professionals investigate threats, track vulnerabilities, and stay informed on the rapidly evolving open-source security landscape. We look forward to continuing to provide the Linux security news, advisories, hardening guidance, and threat intelligence the community relies on every day. . For many readers, LinuxSecurity.com became more than just a news site. It became a long-running rese. linuxsecurity, linux, open-source, security, community, since, 1990s. . Dave Wreski

Calendar%202 May 25, 2026 User Avatar Dave Wreski
102

Exploring Open Source Intelligence (OSINT) Techniques And Tools For Cybersecurity Applications

Open Source Intelligence (OSINT) is the practice of collecting information from published or publicly available sources for intelligence purposes. . The term ‘Open Source’ within Open Source Intelligence refers to the public nature of the analyzed data; publicly available information includes blogs, forums, social media sites, traditional media (TV, radio, and publications), research papers, government records, and academic journals. The scope of this information is almost infinite, concerning various people, companies, and organizations. Individuals who leverage Open Source Intelligence can span from IT security professionals and state-sanctioned intelligence operatives with ethical intentions to malicious hackers with unethical intentions. Understanding The History of Open Source Intelligence The history of Open Source Intelligence dates back to the emergence of intelligence to support a government’s decisions and actions. However, it was not used in a systematic way until the United States established the Foreign Broadcast Monitoring Service (FBMS) in response to the Japanese attack on Pearl Harbor. In 1947, it was renamed the Foreign Broadcast Intelligence Service (FBIS) under the newly established CIA. In 2005, following the 9/11 attacks and the passage of the Intelligence Reform and Terrorism Prevention Act, FBIS - with other research elements - was transformed into the Director of National Intelligence's Open Source Center (OSC). Since its establishment, the OSINT effort has been responsible for filtering, transcribing, translating/interpreting, and archiving news items and information from many foreign media sources. What Role Does Open Source Intelligence Play in Different Industries? OSINT is essential for many fields, such as law enforcement, risk and fraud management, human resources, cybersecurity, and military operations. It can be used to identify data breaches, uncover vulnerabilities, back up decision-making processes, aid customer due diligence, or help users stayupdated. In business, OSINT can be used for penetration testing, breach detection, ethical hacking, and chatter monitoring. Using OSINT is also crucial when keeping tabs on vast amounts of information. Information technology users using OSINT often target three essential tasks: discovering public-facing assets, discovering relevant information outside the organization, and collecting and grouping discovered information into an actionable form. By finding public-facing assets using OSINT, IT professionals can find information that anyone can find on or about a company's assets without resorting to unethical means such as hijacking. Using OSINT to discover relevant information outside an organization helps IT professionals expand from exploring only tightly defined networks, thus increasing their scope of discovery. Using OSINT tools to help collect and group this discovered information helps shape this information into more valuable and actionable intelligence. Within fraud detection and prevention, OSINT can be used as manual review support for anti-fraud systems. For instance, if an anti-fraud system’s ruleset was insufficient to assess the case correctly, OSINT can be used as a backup assessment. OSINT can also search carder forums or the dark web to see what information is trending and what professionals should prepare for. What Techniques Are Used in Open Source Intelligence? OSINT reconnaissance involves using publicly available resources to gather information on a person or organization. OSINT reconnaissance techniques fall into three categories: passive, semi-passive, and active. Passive reconnaissance often involves searching the web using applications such as search engines. This reconnaissance method is hard to detect since no direct engagement is involved, and only archived information is collected. Semi-passive reconnaissance usually consists of searching the web to find data, but can also utilize software solutions to non-intrusively gather information. Active reconnaissance is when data iscollected directly from the target, offering more accurate and timely information. This type of probing can be detectable. The best reconnaissance technique is dependent on the organizational needs of a team. However, following a general process helps lay the foundations for effective intelligence gathering. The Open Web Application Security Project (OWASP) outlines this 5-step OSINT process. This process begins with source identification, where we can find the information for the specific intelligence requirement. Next comes harvesting, collecting relevant information from the identified source. Data processing deals with processing the identified source’s data and extracting meaningful insights. The analysis step combines the processed data from multiple sources. Reporting is the last step, creating a final report on the findings. Using OSINT investigative skills , such as identifying visual clues in photos (e.g., terrain, architecture, shadows, street signs) and leveraging tools like Google Earth or reverse image search, investigators can geolocate images effectively to uncover critical insights, enhancing their OSINT investigative expertise. What Types of Open Source Intelligence Tools Exist? OSINT tools can be divided into three main categories. Discovery tools are used to search for any information that might be found on the web. Good discovery tools can be as simple as search engines. Scraping tools ensure only the required information is filtered through for extraction to a database. Scraping tools are helpful in hiding the presence of bulky data transfers and preventing irrelevant information from mixing with relevant information. Aggregation tools help combine related information from scraping tools to display a clearer picture of what the data represents, all in a presentable format. These can be instances of relations and connections between datasets. There are many free and paid open source intelligence tools available for a variety of purposes, such as searching metadata andcode, researching phone numbers, investigating identities, verifying email addresses, analyzing images, detecting wireless networks, and analyzing packets. However, some of these tools are limited by a paywall. Here is a list of the latest open-source intelligence tools that are free and can be used to their full potential: Nmap Scraping Tool Nmap (Network Mapper) is a free, open-source tool for vulnerability checking , port scanning, and network mapping. It allows you to scan your network and discover everything connected to it, and a wide variety of information about what’s connected and other valuable information. At its heart lies port scanning, which is helpful for administrators. Nmap utilizes a large number of scanning techniques, such as UDP, TCP connect (), TCP SYN (half-open), and FTP. It also offers various scan types such as Proxy (bounce attack), Reverse-ident, ICMP (ping sweep), FIN, ACK sweep, Xmas, SYN sweep, IP Protocol, and Null scan. Nmap can also do limited deployments of network port scans or scheduled network port scans, which is helpful since massive port scans would likely trigger security alerts by the target. Users can control the depth of each scan with light or limited scans for information regarding the port status or more detailed scans for relaying information about the operating systems using these ports. Nmap can do operating system detection via TCP/IP fingerprinting, stealth scanning, dynamic delay and retransmission calculations, parallel scanning, detection of down hosts via parallel pings, decoy scanning, port filtering detection, direct (non-portmapper) RPC scanning, fragmentation scanning, and flexible target and port specification. These qualities make Nmap very versatile. Previously, controlling these scans used to require training in console commands. However, with the new Zenmap graphical interface , experienced admins can more easily use commands to help them identify a target. This makes Nmap a helpful tool for experts and professionals involved inpenetration testing. However, the tool is still very technical and not recommended for novice users. Use Scenario: A user wants to use Nmap to identify a host’s operating system. They want to identify the host’s operating system because they are performing an inventory sweep of their network and want to identify any older assets. The user uses the- A switch to determine the OS for a remote system. For example, running: $ nmap -A localhost. yields an output that says the host is running Linux 3.7 - 3.9. Using Nmap, the user could identify that the host was running a deprecated operating system. Wireshark Scraping Tool A packet analyzer tool, Wireshark, effectively lets users put their network traffic under a microscope, allowing them to zoom in on the root cause of a particular problem. Wireshark captures network traffic on local networks such as Ethernet, Bluetooth, Wireless (IEEE.802.11), Token Ring, etc (packet capture). It then breaks the packets of these local networks down (filtering) before storing the data from these packets for purposes such as offline analysis (visualization). Wireshark has many uses within the industry, such as network analysis and network security. For instance, network administrators may use Wireshark to troubleshoot network problems, while network security engineers may use Wireshark to examine security problems. Quality assurance engineers may use Wireshark to verify network applications, while developers may use it to debug protocol implementations. Beyond these uses in the industry, Wireshark can also be used as a learning tool. Those new to information security can use Wireshark to understand network traffic analysis, how communication occurs when particular protocols are involved, and where it goes wrong when certain issues present themselves. Wireshark can also help novice users learn more about network protocol internals, such as those concerning TCP/IP. However, to properly use Wireshark, a user should first learn exactly how a network operates,such as understanding the three-way TCP handshake and various protocols, including TCP, UDP, DHCP, and ICMP. Use Scenario: A user has an issue with their home network; their internet connection is very slow. Using Wireshark, the user drills down into a packet to identify a network problem. They discovered quickly that their router thought a common destination (Youtube) was unreachable using the Wireshark interface. The issue was easy to find since Wireshark’s interface marks any packet in black to reflect an issue. Once realizing this, the user restarts the cable modem to fix the problem. GHunt Discovery Tool This OSINT tool allows users to analyze a target’s Google history based on factors such as a Gmail address. From a Gmail address, GH unt can extract the target’s name, Google ID, Youtube account, and active Google services. GHunt can also discover a target’s phone model and make, firmware and installed software, public photos, and even the target’s physical location with the right data. Within the industry, white hat hackers and penetration testers may use Ghunt to test whether the emails they find are reasonable and whether they can leak other information. However, they can also be used for threat hunting to identify and track threats. This tool can also be used to understand the extent of a user’s or business’s internet footprint. These qualities make GHunt a great threat intelligence collection and attack simulation tool. Use Scenario: A user’s friend has been receiving strange messages from a “secret admirer” through their email. These messages contain statements that make them feel uncomfortable. The user decides to find the identity of this “secret admirer,” but cannot find their name from the Gmail address alone. The user chooses to use GHunt to investigate their Gmail account. By typing: $ python3 hunt.py This email address is being protected from spambots. You need JavaScript enabled to view it. Within the GHunt folder and pressing enter, the user finds the name of their friends’ “secret admirer” and, using theirname, also finds out that the “secret admirer” goes to their university. The user gives this information to university authorities. Google Dorks Discovery Tool Google Dorks is a data querying method that involves using a dvanced search arguments in a Google Search to reveal tough-to-find but public information. Its roots go back to 2002, when a man named Johnny Long started using custom queries to search for elements of certain websites that he could leverage in an attack. Since then, the role of Google Dorks has remained relatively the same. It remains a way to use the search engine to find websites with certain flaws, vulnerabilities, and sensitive information that hackers can take advantage of. However, cybersecurity professionals can also use it to protect businesses and users from attacks. Google Dorks users can prevent hackers from exploiting their targets by finding vulnerable information before hackers can leverage it for nefarious reasons. One of the most popular Google Dorks sites is Google Hacking Database on Exploit Database. The site enables users to dive deep into a server to find data on a target using an extensive list of arguments that can address queries for almost any type of data, such as usernames and passwords. This is why using Google Dorks is a must for penetration testers. Greg.app Discovery Tool Modern software development is about collaboration and leveraging the power of open source. Greg.app makes this easy, allowing users to search code from half a million public repositories on GitHub. What's cool about Greg.app is that, in addition to a repository filter and language filter, it includes a path filter that can check for similar code within particular folders. This can be useful for finding key details about code similarities and differences between various languages. If a user is interested in finding any code, regardless of punctuation, Greg.app is a great OSINT tool to use. Intel Owl Aggregation Tool Intel Owl is an OSINT solution for findingthreat intelligence data about a specific file, IP, or domain from a single API request. A scalable API, Intel Owl can gather threat intelligence data about a particular file or observable (IP, domain, URL, ha sh) by querying many different analyzers and services that are externally or internally available. Built to scale up and speed up the retrieval of cyber threat information, Intel Owl can easily be integrated into a user’s stack of security tools to automate common jobs usually performed manually by security operations center analysts. This autonomy makes Intel Owl an effective tool for any user who needs a single point to query for information about a specific file or domain, IP, URL, hash, etc. Some of Intel Owl’s main features are its built-in web interface and more than 80 available analyzers that can be used to generate or retrieve data about a suspicious file or observable. 0365 Squatting Discovery Tool A Python tool created to identify risky domains before they attack. 0365 Squatting can create a list of typo-squatted domains based on the domain provided by the user. The software can then check all the domains against the 0365 infrastructure, singling out risky domains. This makes 0365 Squatting an ideal tool for users searching for potential phishing domains before these websites attack. Use Scenario: A user has received a strange email from what seems to have been sent from a Microsoft domain. Afraid to block this domain, the user wants to check whether or not this domain is real. Using 0365 Squatting, the user types in a Python terminal: python 0365squatting.py -o micros0ft.com The user receives an output of: Checking domain micros0ft.com Micros0ft.sharepoint.com is down / not available By using 0365 Squatting, the user finds out that the domain is fake and they should block this domain. OSINT Framework Discovery Tool If a user is looking for the best OSINT tools but is unsure of the tools they should choose for their targe t, the OSINT Frameworkis a very useful resource. As its name implies, the OSINT Framework is a cybersecurity framework with a vast collection of OSINT tools within and outside Linux that can help find information that spans from telephone numbers to IP addresses and email addresses. Though mostly used by security researchers and penetration testers for digital footprinting, OSINT research, intelligence gathering, and reconnaissance, there are also uses for analyzing malicious files and exploring the Dark Web. When exploring the OSINT Framework, users are provided an easy-to-use, interactive tree graph user interface to help them find the best free tools and resources for their work objectives. Use Scenario: A user wants to do research on worldwide mobile coverage, but does not know where to look. Since they want to use the most effective free tools and resources available, they look through the OSINT Framework. First, the user clicks on Geolocation Tools / Maps. From there, they receive a massive list of map-related tools. Specifically, there is a parent node titled ‘Mobile Coverage’ that they find intriguing, as it pertains to their research topic. Clicking on the ‘Mobile Coverage’ parent node, the user discovers the resources they need for their topic. reNgine Aggregation Tool An automated reconnaissance framework, reNgine does end-to-end reconnaissance with the help of configurable scan engines. The beauty of reNgine is that users can use these configurable scan engines against multiple targets. Users can configure them to scan results, find endpoints, and quickly filter endpoints based on extension, HTTP status, page title, etc. These qualities make this tool great for penetration testing of web applications and organizations looking for asset discovery and continuous monitoring. If a user has a website that receives a large amount of web traffic, they might want to use reNgine to help protect and maintain their site. Use Scenario: A user wants to do reconnaissance on a domain that continuously receivesa lot of web traffic to check whether there are any vulnerabilities periodically. Using reNgine, the user can complete a full scan on that specific domain. A full scan includes subdomain discovery, port scan, directory and files search, fetching of endpoints (URLs), and vulnerability scan. Looking at the vulnerability scan, the user finds that no vulnerabilities were discovered for the domain. To be safe, the user sets a timer for reNgine to periodically scan the domain to ensure vulnerabilities don’t go unnoticed. Recon-ng Aggregation Tool Recon-ng is a reconnaissance framework designed to provide an environment to quickly and thoroughly conduct open-source web-based reconnaissance. Written in Python, it has many modules, features for database interaction, built-in convenience functions, interactive help, and command completion. Its primary purpose is to work and act as a web application/website scanner. Recon-ng can also be used to find the IP Addresses of a target, look for error-based SQL injections, find sensitive files such as robots.txt, and more, using built-in features such as WHOIS lookup. For users looking for a reliable information-gathering tool, Recon-ng is an excellent choice. Sublist3r Scraping Tool Sublist3r is a python tool designed to list subdomains of websites using search engines such as Google, Yahoo, Bing, Baidu, and Ask. It can help collect and gather subdomains of a target domain, making it useful for penetration testers. and bug hunters. If a user is interested in finding the subdomains of their target domain, they should use Sublist3r. ZMap Discovery Tool ZMap is a modular, open-source network scanner architected to perform Internet-wide scans. Capable of surveying the entire IPv4 space in under 45 minutes from user space on a single machine, the tool is often used to discover vulnerabilities within a network, the impact of these vulnerabilities, and to detect affected IoT devices such as connected appliances. On a single port on one gigabit persecond of network bandwidth, Zmap can scan the entire IPv4 address space in 44 minutes. However, with a ten-gigabit connection, the total time is reduced to just 5 minutes. This speed in scanning makes Zmap an effective tool for network scanning. If users want to monitor their network for vulnerabilities, Zmap is a highly recommended tool. Is Open Source Intelligence Legal? The legality of OSINT is dependent on how it is used. The U.S. Code defines the legal use of open source intelligence as “... intelligence that is produced from publicly available information and is collected, exploited, and disseminated in a timely manner to an appropriate audience for the purpose of addressing a specific intelligence requirement.” When OSINT is used for purposes such as “doxing” (unveiling publicly available information of anonymous internet users) to someone, it can be illegal. There can also be legal issues with managing vulnerable information if managed improperly. If, for example, an organization accidentally leaked an employee’s credentials on a public storage bucket, it is up to an OSINT analyst to alert the organization accordingly to ensure fast remediation. Without remediation, consequences will ensue. What is Operations Security (OPSEC), and How is it Related to Open Source Intelligence? Operations Security (OPSEC) is a process that identifies non-illicit means that a potential attacker can use to reveal critical or sensitive information and data. OPSEC uses countermeasures to reduce or eliminate an attacker’s exploitation of such information to prevent this action by a potential attacker. Just like OSINT, OPSEC can trace its origins to U.S defense and military interests. The term OPSEC was created during the Vietnam War campaign by the U.S military when unclassified information was inadvertently shared with the North Vietnamese and their allies. The relationship between OSINT and OPSEC lies in how one balances the other. OSINT is the practice of collecting information frompublished or publicly available sources for intelligence purposes. OPSEC concerns the protection of individual pieces of data that can be aggregated to form a bigger, potentially critical/sensitive picture. Without OPSEC, there is a chance for OSINT tools and techniques to be used by potential attackers for illicit reasons. Therefore, to protect the legality of using OSINT tools and techniques, OPSEC is a necessary enforcer. Closing Thoughts on the Critical Importance of Open Source Intelligence in Cybersecurity Open Source Intelligence (OSINT) is a formidable tool for finding valuable information. The information found using OSINT in the past has not only helped industries but also saved lives in military sectors and law enforcement. As the internet keeps becoming a larger part of daily human life, the need for OSINT and cybersecurity will continue to grow. We hope that the tools mentioned above will help you start using OSINT in your daily life and that you share these tools with others. Leveraging open-source OSINT tools and techniques, investigators can also refine their ability to geolocate images by employing methods such as reverse image searches and analyzing visual indicators, including shadows, terrain, architectural styles, and signage. These approaches underscore the importance of integrating diverse data sources to generate actionable intelligence, while emphasizing the need for precision and careful validation to mitigate risks of misinterpretation during complex investigations. . The term ‘Open Source’ within Open Source Intelligence refers to the public nature of the analyz. source, intelligence, (osint), practice, collecting, information, published, publicl. Hithesh Sathian. Brittany Day

Calendar%202 Sep 04, 2025 User Avatar Brittany Day
102

Cloud-Native Security Insights: Addressing Challenges with Uptycs

Cloud and container adoption is on the rise, as organizations are increasingly recognizing the potential for rapid growth and evolution that cloud-based infrastructure offers. That being said, along with these advantages comes significant security challenges. . The modern cloud-native attack surface is complex and difficult to secure with many “moving pieces” including endpoints, servers, containers and cloud providers. This makes integrating Threat Intelligence data gathered from all of these surfaces and evaluating potential security and compliance risks and active threats no easy task. Not only is risk harder to identify and evaluate in cloud and container environments, security vulnerabilities, malware and other threats that are also easier to inadvertently inherit from common layers and shared components frequently used in container builds. To better understand the modern cloud-native attack surface and what is required to close security and observability gaps across cloud-native infrastructure, LinuxSecurity researchers had the privilege of speaking with Ryan Mack, Director of Engineering at Uptycs, a leading open source cloud-native security analytics provider, to discuss the challenges organizations face and how to enhance and simplify cloud-native security and observability for the enterprise. LinuxSecurity: How do you feel that the extensive adoption of containerization has impacted the digital threat landscape? Ryan Mack: Containerization, like every evolution in the way software is developed and deployed, trades some conveniences and security benefits for others. On the development side, building container images speeds development by making it much easier to include common layers and shared components. This also makes it easier to inadvertently inherit security vulnerabilities or even malware - commonly coin miners - that have been included in commonly used images on public image repositories. On the deployment side, short-lived containers have dramatically improved the abilityto scale to sudden increases in load and provide security benefits by making deployments more immutable. This can present a challenge for heavy weight endpoint security software that don't scale down well into low memory micro VMs or don't make it easy to understand a complex and potentially high churn set of running containers. LS: What is the most significant challenge that Uptycs helps enterprises overcome? What differentiates your products from other security analytics platforms available for the enterprise? RM: To be honest this varies widely depending on the enterprise. This can range from just providing a tool to run queries against their corporate assets and cloud infrastructure, historic data collection for after-the-fact security analysis, to our full set of compliance monitoring, real time threat detection, remediation, and vulnerability scanning. Every security analytics vendor that ingests data from different sources needs to solve the problem of normalization and correlation to perform analysis. Uptycs tackles this problem by extending the osquery concept of SQL-driven analytics. We’ve developed open-source extensions to osquery to expand the types of telemetry gathered and normalized into SQL tables for simpler real-time event correlation and ad hoc querying. With this analysis backend, we can quickly answer different types of questions such as “Are we seeing exploit attempts for this particular CVE, and have these bad actors been doing anything else in our network?” and “What is the compliance posture of our Linux server fleet against the CIS Benchmarks?” LS: Although the platform itself is not an open-source tool, Uptycs has built on various open-source projects spearheaded by Facebook and Apache to engineer its Uptycs Security Analytics Platform. In your opinion, how does your use of Open Source benefit your engineers and your customers? More specifically, how does your use of Open Source impact the level of security that your customers experience? RM: Therapid adoption and evolution of cloud-based infrastructure requires that cloud-native Security Analytics innovate and adapt quickly. Open source software provides scalable, battle tested foundations that allow us to focus on the unique requirements of our product instead of reinventing common components. Our ability to rapidly adapt to enterprises' changing requirements and an ever-evolving threat landscape is in no small part due to being able to build on top of robust open source solutions . LS: How do you anticipate the cloud-native attack surface changing and evolving in coming years? RM: The key ongoing trend of the last couple of decades has been the shift from a few big servers, to small server scale-out, to virtual machines, containers, and now serverless computing with AWS Lambda and Fargate. Each step has shifted the operational complexity from things we are in direct control of to things we manage indirectly through the configuration of our cloud provider, container orchestration framework, or service mesh. This trend is certainly going to persist foing forward. Security professionals need to understand how dramatically their attack surfaces will change in the coming years. They need to anticipate these changes because attackers will be looking to exploit gaps in visibility and unmitigated risk in these new environments. New problems demand new solutions, and Uptycs is positioned well to help organizations tackle these emerging security challenges with scalable, integrated technology built on a secure, community-powered open-source foundation. Have a thought to share or another open-source security tool you’d like us to cover? Connect with us on Twitter and let us know! . The modern cloud-native attack surface is complex and difficult to secure with many “moving pieces. cloud, container, adoption, organizations, increasingly, recognizing, poten. . Brittany Day

Calendar%202 Oct 26, 2021 User Avatar Brittany Day
102

Harnessing Threat Intelligence For Optimal Cyber Defense Strategies

Thank you to Oyelakin Timilehin Valentina and Duane Dunston for contributing this article. Threat intelligence (or threat intell) is information used to understand past, present, and future threats targeting an organization. It is evidence-based knowledge about a previous, existing or emerging threat to organizational assets. Threat intelligence also includes settings, implications, mechanisms, context, and even action-oriented advice on the threat. Context mentioned here includes who the attackers are, what their motivation is, what their capabilities are, and what indicators of compromise are in your system. An Indicator of compromise (IOC) is forensic data in a system log file, for example, which identifies malicious activities on a system or network. . Also, threat intelligence can be defined as data analysis using tools and techniques to get information about an existing or emerging threat targeting the organization. Notice that the definitions mentioned above include using knowledge (obtained from data) to achieve a common goal of mitigating cyber threats or cyberattacks. In this series, we will define threat intelligence as collecting, processing, and analyzing data that gives us meaningful knowledge to understand the pattern of previous or present attacks and leads to the building of a stronger and better cyber defense to help mitigate or prevent future attack. Importance of Threat Intelligence Threat intelligence provides deep knowledge on the potential threats to an organization. It helps to know all that is happening outside of the network, because it helps to recognize threats and exploits that the organization is vulnerable to using data from various tools and threat event sources to build a risk management plan to prevent future threats. Cyberattacks and data breaches lead to loss of data, but it also leads to costs like damage to the organization's reputation, market position, fines, lawsuits, expenses that come from investigation, and post-incident restoration andremediation. Practical threat intelligence that comes with effective defense strategies can also save an organization by cutting down or avoiding the cost of data breaches. With vulnerabilities being actively exploited, practical threat intelligence can quickly identify and mitigate their impact and increase the security team's efficiency in handling security alerts. Also, threat intelligence helps gather IOCs like signatures of tools used by the attackers, malware characteristics, and behavior. In this series, we will explore some tools that can be used for creating a threat intelligence program for an organization. The tools will be explained along with examples of how to run it and interpreting its output. While it cannot cover all possible implications to an organization, it can help provide a starting point for interpreting the output in context to your organization. We will begin with discussing how nmap can be used as one source to gather information to add to a threat intelligence program. Stay tuned! About the Authors Oyelakin Timilehin Valentina is a self-taught cybersecurity professional. As someone who loves to contribute to social responsibility, she volunteers for Cybersafe Foundation with its initiative #NoGoFallMaga. She is also a volunteer for The Young Ciso Network and The Diana Initiative. Duane Dunston is an Associate Professor of Information Security at Champlain College. He has been in information security since 1997, starting in the education sector, then to federal, and then into academia. . Profound understanding of threat intelligence and its importance in counteracting cyber risks for enhanced organizational safeguarding.. Threat Intelligence, Cyber Defense, Risk Management, Security Strategies. . Duane Dunston

Calendar%202 Jun 03, 2021 User Avatar Duane Dunston
102

Using Reverse Engineering to Secure Linux Against Malware Threats

For many years, Windows users were the only ones at risk of facing malware network security threats; however, cybercriminals have come to view Linux as a viable target for their attacks due to the growing popularity of the open-source OS and the plethora of high-value devices it powers. During 2019 and 2020, dangerous Linux malware variants like CloudSnooper, EvilGnome, and HiddenWasp emerged, and the number of malware strains continued to grow over time as Linux malware operators harbored great success with their malicious malware and phishing campaigns. Thus, taking proactive measures to secure your Linux systems against attacks has never been more critical. . Reverse engineering seeks to deconstruct malware in an artificial environment, such as a Linux system, to gain insight into its design, architecture, and code. It is a highly effective method of malware detection and analysis, which we will examine in this article, highlighting how reverse engineering can be used to secure Linux systems, our favorite network security toolkits for doing so, and malware scanning available to Linux users. How Can Reverse Engineering Detect, Analyze, and Protect against Malware for Ultimate Security? Reverse engineering helps administrators identify, study, and eliminate network security issues and risks on their systems that they can use to gain knowledge on how to prevent future attacks in network security. This process involves disassembling - and sometimes decompiling - malware software programs that threaten to harm a system. By converting binary instructions to code mnemonics (shortcuts within a system) or higher-level constructs, reverse engineers (often referred to as “reversers”) can analyze the characteristics of a malicious program, including its behavior, systems it impacts, and cybersecurity vulnerabilities it exploits. These valuable details can be used to create effective solutions to mitigate the program’s intended malicious results. Dynamic analysis relies on privacy sandboxing malwaretesting to determine the speed and automation offered through reverse engineering. Privacy sandboxing is when a malicious program is intentionally launched into a secure environment so companies can find and fix the cybersecurity vulnerabilities within their system. As emerging malware strains continue to demonstrate increasingly complex techniques, reversers need more time to understand disassembled or decompiled code, which can be an opportunity for cybercriminals to compromise a network with malware. The use of dynamic analysis can make reverse engineering more efficient and effective; however, reversers should not rely solely on dynamic techniques, as sophisticated malware variants are capable of employing evasion techniques that detect whether they are in a sandbox, allowing them the chance to delay or hide malicious activities. The best approach to malware detection and analysis involves combining the previously described methods to work automatically to combat any threat heading a company’s way. Dynamic analysis can be used to automatically analyze the majority of network security threats, while reversers can dedicate their time to acquiring threat intelligence from the most sophisticated attacks. Now that we’ve explored how reverse engineering can help you secure your Linux systems against malware, we can go over the various network security toolkits and utilities that can assist in the process of reverse engineering and malware scanning. Network Security Toolkits and Utilities to Use with Linux Reverse Engineering & Malware Scanning REMnux REMnux is a free, versatile network security toolkit that conveniently allows reversers and analysts to investigate malware without having to find, install, and configure the tools needed. REMnux offers a distro that can be downloaded as a Virtual Machine (VM) in the OVO format and then imported into your hypervisor, installed from scratch on a dedicated host, added to an existing system running a compatible version of Ubuntu, or run as a Dockercontainer . Chkrootkit Chkrootkit is a widely used free rootkit detector. A rootkit is a malware program that gives cyber criminals access to a system from afar. This protection toolkit locally scans for rootkits and hidden security holes on Unix/Linux systems utilizing a shell script that checks system binaries for any rootkit modification through the use of “strings” and “grep” (Linux tool commands) to detect potential network security threats. Chkrootkit can verify an already compromised system through alternative directories or rescue discs. It can also locate deleted entries in the “wtmp” and “lastlog” files, find sniffer records or rootkit configuration files, check for hidden entries in “/proc,” and look at calls to the “readdir” program. Chkrootkit can be downloaded here. Rkhunter Rkhunter is a powerful, user-friendly tool designed to inspect and analyze Linux systems for hidden security holes and scan for rootkits, backdoors, and local exploits in cybersecurity. This tool thoroughly checks files, default directories, kernel modules, and misconfigured permissions, comparing them to the database records that can help identify suspicious programs. Rkhunter can be downloaded here. Lynis Lynis is a popular, free malware scanning and auditing tool for Unix/Linux OSes used to detect security holes and configuration flaws, which could be cybersecurity vulnerabilities. It performs firewall auditing, checks file/directory permissions and integrity, and verifies installed software. Lynis exposes network security threats but provides mitigation suggestions to assist you in taking care of your system. Lynis can be downloaded here. LMD Linux Malware Detect (LMD) is a full-featured malware and cloud security scanner explicitly designed for hosted environments; however, LMD can be used to detect network security threats on any Linux system. The renowned program uses a signature database to identify and rapidly terminate malicious code running on a system. Topopulate its database, LMD captures threat intelligence data from network edge Intrusion Detection Systems (IDS), enabling programs to generate new signatures for malware actively being used in attacks. LMD includes a complete reporting system where administrators can view current and past scan results and receive email alerts after each scan. To improve LMD’s performance, you can integrate it alongside the virus scanner, ClamAV . Keep Learning about Mitigating Network Security Threats Malware is a growing concern for administrators as the prevalence and sophistication of variants targeting Linux systems continue to increase. However, this tends to result from misconfigured servers and poor administration, demonstrating that this rise in attacks is not a result of defective data and network security on Linux’s part. Testing and verifying server cybersecurity projects on an ongoing basis is crucial to preventing attacks. Reverse engineering is an excellent method of detecting and analyzing malware on Linux systems and gathering threat intelligence that can be used to prevent future network security issues. There are various services for reverse engineering and malware scanning available to Linux users that are powerful, user-friendly, and free to download. Have questions about reverse engineering? Currently, are you using one or more of the network security toolkits that we’ve highlighted in this article? We'd love to hear about your experience and/or answer your questions! Please do not hesitate to contact us on social media: Twitter | Facebook . Reverse engineering seeks to deconstruct malware in an artificial environment, such as a Linux syste. years, windows, users, facing, malware, network, security, threats. . Brittany Day

Calendar%202 Dec 28, 2020 User Avatar Brittany Day
102

Exploring Open Source Intelligence Insights Provided by Dancho Danchev

Open Source Intelligence (OSINT) is a tactic used to learn about information relevant to protecting an organization from external and internal threats using publically accessible data. Identifying information that could be used against an organization provides actionable insight that could reduce the risk that an organization may face. It’s an early warning system used to forecast and signal a potential threat. . LinuxSecurity editors thought it would be interesting to discuss the topic of open source intelligence, threat intelligence, and how to get started with OSINT with our audience, as well as to speak with Dancho Danchev, an acclaimed ex-hacker and security intelligence researcher from Bulgaria. Dancho is a leader in the field of current and emerging cybercrime research and threat intelligence and a prolific blogger on the subject. Dancho Danchev, Bulgarian Hacker, Security Researcher We thought it would be interesting to ask Dancho a few questions about his background, open source intelligence, current trends in the cybersecurity community, the Dark Web, government security, zero-day threats, and his efforts that resulted in the take-down Koobface, the world’s largest botnet at the time. Formerly a ZDNet Zero Day blogger for more than four years, Dancho also worked as a security blogger for Webroot. In 2011, he was selected by SCMagazine for their Social Media award as a finalist for his twitter account at the time. Dancho also presented at UKs GCHQ including Canadian Intelligence Service’s HQ, and a Keynote presentation on “Exposing Koobface - The World’s Largest Botnet” . In 2016, Dancho presented at CyberCamp RSA Europe and InfoSec Europe on current cybercrime trends and cyber jihad. Prior to this, he also was one of the primary developers of the underground network known as Astalavisita . Dancho is often cited and frequently referenced cybercrime researcher, security blogger and threat intelligence analyst with over a decade in fightingcybercrime and actively responding to current and emerging cybercrime threats. Dancho also worked as a Technical Collector for the infamous LockDown2000 anti-trojan software solution, including working as a Trojan Database Manager for the market-leading Trojan Defense Suite anti-trojan vendor. His research blog, Mind Streams of Information Security Knowledge , reportedly has over 5.6M active pageviews and visitors since it was started in 2005. Dancho got started with computer security in the 90s, researching trojans and hacking tools and writing about them for a software company that developed anti-trojan solutions. Threat Intelligence and Why It’s Important Threat intelligence is the study and research of who may be attacking you, what their motivation and capabilities are, and what indicators of compromise in your systems to look for to help make informed decisions about your security. The skilled threat intelligence researcher should be able to strip out the extraneous information and false alarms and only focus on the actionable intelligence that directly affects her interests. Dancho told us that “threat Intelligence has been an inseparable part of my career and it’s something that I do and practice on a daily basis. My earliest experience with Threat Intelligence is as a Technical Collector of trojan horses/viruses/worms and VBS scripts for LockDownCorp throughout the 90’s which in combination with my experience in OSINT let me to produce some of the industry’s most recognized research articles. I’m also researching Eastern European cybercriminals as well as international and global spam phishing and malware campaigns and information on the actors behind them.” Threat intelligence and OSINT is the research and analysis of only public data. LinuxSecurity was curious if Dancho had ever been a blackhat hacker. “In my entire teenage ex-hacker enthusiast experience I've only compromised one Website which was my town's official Website,” writes Dancho. Hemanaged to obtain the accounting data for the site by socially engineering tripod.com at the time into going through the System Administrator's ICQ profile to gain access to the site for the purpose of changing the homepage to spread a message and actually say "hi" and greet local friends. What is Open Source Intelligence (OSINT)? Open-source Intelligence, or OSINT, is data collected from publicly available sources to be used in an intelligence context. While it doesn’t necessarily refer to open-source software, OSINT instead refers more to information that is open and available to everyone, such as that which is available publically on the Internet. An OSINT researcher is a skilled technician, capable of analyzing large amounts of data quickly, using sophisticated tools and knowledge of how the underground networks on the Internet work in order to understand the cyber criminals and how they operate. OSINT can also be used to track a potential attacker prior to that attack occurring, as well as to analyze raw data to determine who may be impacted by an attack. In the US Government, the CIA is responsible for collecting, producing, and promoting open source intelligence through its management of the DNI Open Source Center (OSC). In the intelligence community, the term "open" refers to freely available information, usually in its raw form, such as in a database. OSINT data is useful for gaining intelligence as part of an investigation - using OSINT doesn’t necessarily mean that data is also easily accessible. It doesn’t necessarily refer to information that can be found using regular search engines - a huge portion of the Internet cannot be found using major search engines. Instead, the “deep web” refers to a mass of pages or paywalls that cannot be indexed by Google, but is publically available nevertheless. For example, tools like Shodan and Censys can be used to find IP addresses, networks, open ports, webcams, printers, and pretty much anything elsethat’s connected to the internet. These individual pieces of information can be combined with other publically-accessible bits of information to develop a profile about a particular topic of interest by the skilled analyst. There’s also a dark side to OSINT - anything which can be found by security researchers can also be found by threat actors. In fact, late last year Dancho identified hundreds of gigabytes of raw OSINT information in underground cybercrime forum communities from more than a million websites and scoured them for fraudulent activity in an effort to shut down the community. Getting Started with OSINT LinuxSecurity asked Danchev how he got started with OSINT. Writes Danchev, “In 2008 I earned the privilege of getting invited to an invite-only conference event at the GCHQ which I attended with the Honeynet Project. Since that time, I’ve made numerous valuable contributions to the U.S Intelligence Community as an independent contractor and through the research which I've been publishing at my personal blog in terms of high-quality and never-published before OSINT analysis as an independent contractor.” Dancho tells us of a time when he was going through FOIA requests and in particular publicly released and classified information, visiting and browsing the CIA's official Website, and came across the following quote courtesy of President Nixon at the time - “What use are they? They’ve got over 40,000 people over there reading newspapers.” He says this got him interested in OSINT and helped him shape the future of his career as an Intelligence Analyst and OSINT analyst working under NDA as an independent contractor. For this project, Dancho attempted to collect as much personal information as possible, including IoCs (Indicators of Compromise) websites including personal account information and email addresses. His research resulted in publishing a list of thousands of email addresses and ICQ numbers of cybercriminals responsible for stealing creditcard and CVV numbers, among other personally identifiable information (PII). Danchev said he learned early on in my career that the best way to learn in the security intelligence world is to join a local hacking and security community. The security community rewards hard work and diligence. Prove that you can speak authoritatively on a security topic, manage a project, and build a community around it, and you will be recognized for your efforts. Anonymous Communication Using Tor One of the most useful tools in the arsenal of the security intelligence hacker is Tor, the free and open-source software for enabling anonymous communication. The name is derived from the acronym for the original software project name, " The Onion Router ". Tor was initially a worldwide network of servers built for the US Navy that enabled people to browse the Internet anonymously. Tor disguises your identity by transferring your traffic between different Tor servers, encrypting that traffic so it isn’t tracked back to you. Accessing the Tor network requires using the Tor browser . It’s typically used in environments where you’re concerned about being tracked, such as if you live under a dictatorship or a hacker looking to stay hidden from the government. “I believe it was around 2006 when I was busy researching several U.S Government programs including SPAWAR. I then decided to use it including several other covert communication tools for the purpose of preventing my local ISP from intercepting what I was doing online,” writes Dancho. He continues, “At the time in particular the 90’s many Eastern European countries part of the Soviet Union at the time were under technology embargo which was known as COCOM with personal computers at the time being something in the lines of a luxury and only organizations and companies could really afford them.” Dancho also talks about the Space and Naval Warfare Systems Command, known as SPAWAR, and the research they produced for foreignintelligence and other US Government programs as a valuable resource. Zero-day Threats and Security Blogging Dancho used to be a security blogger at ZDNet’s Zero-Day blog for four years, covering topics including the latest cyber threats, cybercrime, malware and botnets, as well as operating system vulnerabilities and exploits. Danchev writes, “During this period I covered hundreds of high-profile security events, including vulnerabilities affecting Adobe, Apple, Google, and Facebook, as well as botnets and malware affecting hundreds of millions of users. I also was awarded the prestigious Jesse H. Neal award for best blog quite some time ago. In one post, Dancho discussed how the process of developing and managing such a botnet is entirely automated, efficient, and most importantly - available as a service through a malicious underground Cybercrime-as-a-Service provider. I’m sure we’ll learn more about how that works in a future report. Astalavisita, Baby Throughout 2003-2006 Dancho was the site operator for astalavista.box.sk - the underground hacking website while acting as a Managing Director where he was responsible for managing the portal’s content and the production of a security newsletter where he interviewed people from the security industry. Back in the early 2000s, the Astalavista portal was one of the world’s most widely known and visited Websites used to search for hacking and security resources with thousands of users visiting it on a daily basis. Although it originally was created as a resource for security researchers, it also became a popular search engine for security exploits, software for hacking, cracking and different keygenerators and software cracks. In present day - he currently runs a high-profile project on the original Astalavista.box.sk domain, still one of the world’s most highly-visited websites for hackers and security experts including a popular security forum. Koobface Botnet and Compromising SocialNetworking Sites The Koobface botnet (an anagram for Facebook) propagated exclusively across Facebook and managed to infect hundreds of thousands of users globally using social engineering campaigns to trick them into revealing personal details about themselves and their friends. “Over a period of two and a half years I actively monitored the botnet’s activities and published the details on my personal blog. Eventually I learned of a single mistake made by one of the botnet masters behind the campaign, which eventually led me to actually find personally identifiable information on him, ultimately leading to the shutdown of the entire Koobface botnet at the time,” writes Dancho on his botnet takedown assist with the US government. Dancho worked full days to provide actionable intelligence on the way the Koobface botnet worked including actual information on some of the current and latest campaigns launched by the Koobface operators at that time. He then made this information available to the broader security industry, including law enforcement, so they would be able to actually track down and prosecute some of the botnet masters behind it. Bill Brenner from CSO Online reported in his article, “ Dancho Danchev unmasks man behind the Koobface Botnet ” at the time that Koobface “prompted friends to download an update to their Flash player in order to view a video. The update is a copy of the virus.” Pretty amazing stuff. Launching an actual take-down effort against the botnet’s infrastructure, including the primary Command and Control (C&C) servers led to a personal message being distributed to all the infected hosts internationally which greeted me personally and included a reference to my personal blog followed by another message during the Christmas season including an actual point-by-point answers to my “ Top 10 Things You Didn’t Know About the Koobface Botnet ” which I published at ZDNet’s Zero Day blog at the time embedded on every malware-infected hostpart of the botnet. It was an incredible success, and extremely rewarding for the intelligence community. The Evolution of Intelligence Gathering The US military first coined the term OSINT in the late 1980s as a way of providing timely, objective intelligence, free of bias, based upon all sources available to the US Intelligence Community, public and non-public. When 9/11 occurred, government agencies were formed to ensure OSINT was a major source in merging and consolidating relevant intelligence into actionable products. The government learned to collaborate with academia - universities are the perfect place for capturing the expertise needed to do the analysis. OSINT analysts are now processing immense amounts of public data, such as that on social networks, to discover emerging trends and identify valuable information. The tools being used for OSINT have also evolved greatly. On the evolution of the tools used, Danchev writes that the “majority of tools that I'm aware of rely on APIs including the active use of public sources. Users who use these tools should definitely take basic precautions to protect their own privacy, such as through the use of VPNs and secure tunnels.” “I'd rather say people should look for what information they publicly provide including social media as people including spies and bad guys often tend to do their homework before and prior to launching cyber attacks that also includes espionage campaigns.” Sage advice from an experienced OSINT researcher. Are you a security blogger or researcher and would like to be profiled here? Share your story with us and we’d be happy to discuss it with you. Connect with Dancho on social media: Twitter - https://twitter.com/dancho_danchev LinkedIn - Medium - https://medium.com/@danchodanchev . LinuxSecurity editors thought it would be interesting to discuss the topic of open source intelligen. source, intelligence, (osint), tactic, learn, about,information, relevant, protecting. . Brittany Day

Calendar%202 Apr 27, 2020 User Avatar Brittany Day
102

Ira Winkler: Advanced Persistent Security Insights and Threat Intelligence

Brittany Day recently had a conversation with acclaimed cyber security expert Ira Winkler, author of Advanced Persistent Security: A Cyberwarfare Approach . Mr. Winkler is a security researcher and a former NSA employee who writes about cyber security and enterprise digital threat protection. . In this interview, he discusses his career, his views on computer security and his role in building effective enterprise protection systems. Mr. Winkler is also the President of Secure Mentem . As an author, his writings clearly explain the ongoing threats that businesses face and the approach they should take to effectively combat them. Understanding threat actors’ motives is extremely important in successfully fighting attacks. Winkler’s background in psychology has provided him with a unique and exceptional understanding of this aspect of cyber security threat. Exclusive Interview with Security Expert Ira Winkler Interviewed by Brittany Day Ira Winkler is a renowned security researcher and author with a background in Psychology which has enabled him to better understand threat actors’ strategies and motives. Ira, how did you get involved in security and how did your career as an author begin? My career as an author with an expertise in cybersecurity had a somewhat unusual beginning. As you mentioned, I earned my undergraduate degree in Psychology. At the time, I did not have much of an interest in computers or digital security. However, I wanted a job in the foreign service, but the career counselor also recommended I take the test for NSA. I took a test for the NSA, which showed I had an aptitude for many career fields. I took a job as an intelligence analyst, which I hated. So, I applied for the Computer Intern program, where I was retrained as a computer systems analyst. After a few years, I left the government and went to work for government contractors. They had policies that if you were accepted to a professional conference, they would have to send you, so Isubmitted conference papers and articles about security, which received a great response. I went on to write my first book Corporate Espionage. A year later, my second book Through the Eyes of the Enemy was published. Since then I have written Spies Among Us, Zen and the Art of Information Security, and Advanced Persistent Security. I am currently in the process of writing my sixth book, You Can Stop ‘Stupid’, which will be published in 2020. Ira Winkler uses the term Advanced Persistent Security to describe a proactive approach to enterprise cyber security which includes an effective protection/detection/reaction strategy. Ira, can you sum up what Advanced Persistent Security means to you? The term “Advanced Persistent Security” should be referred to as adaptive persistent security. This concept describes a comprehensive security approach that takes protection, detection and reaction into account. I think it is important to grasp that security fails when a threat actor gets out, not when he or she gets in. The problem is that the criminals go undetected. In many cases, threat actors are not outsiders. Rather, they are employees. This is something that is important to consider when creating a protection/detection/reaction strategy. Another important concept is that there is no such thing as perfect security. Threat actors are always thinking of new ways to carry out attacks, hack into networks and compromise information. They are often highly persistent and refuse to give up until they have succeeded. Thus, businesses should expect this and build failure into their security posture. A successful protection/detection/reaction strategy matches the persistence of attackers’ methods and evolves to take the latest attack variations into account. As I state in Advanced Persistent Security, “Advanced Persistent Security is Defense in Depth that is enhanced with a comprehensive methodology for integrating the appropriate and properly configured detection capability, along with proactively implementingand executing a reaction capability.” In Advanced Persistent Security, you explain the importance of designing and implementing an effective enterprise protection/detection/reaction strategy. In your opinion, what is the biggest misconception that currently exists regarding enterprise protection/detection/reaction strategies? What is a common security mistake you see many businesses making? As is true in many aspects of life, people often fail to consider the basics when thinking about enterprise protection/detection/reaction strategies. It is not uncommon for security experts to focus on addressing highly complex and somewhat obscure attack variations, and to neglect basic cyber hygiene. Basic attacks are still around because they are highly successful. For instance, the latest attacker du jour, APT 10, began their latest attacks with a classic spear phishing email. Threat intelligence is a complex concept that many people do not fully understand. Your book Advanced Persistent Security talks about building a threat intelligence program. Can you tell our readers what that means and how one would get started doing that? Threat intelligence means different things to different people. In my opinion, a true threat intelligence program stands apart from traditional security technologies and products in that it is an ecosystem that can be tuned, programmed and continually analyzed to suit the resources and threats with which they are working against on a daily basis. The first step in building a successful threat intelligence program is proactively determining the types of threats that pose a risk to your business. The more specifics the better: try to identify who would carry out these attacks and the tools and methods they would likely use to do so. This information is important in developing effective countermeasures. In general, businesses need to be better about planning and preparing for attacks, not just reacting to them. The Dark Web is a term that refers to a collection of websites thatexist only on an encrypted network and cannot be accessed using traditional search engines or browsers. Many security researchers and ethical hackers use the Dark Web as a resource for their research or their work. How can a security researcher or ethical hacker benefit from using the Dark Web? Although the Dark Web has a bad reputation, it does have some benefits for security researchers and hackers. Primarily, the Dark Web has great resources for finding and buying attacks of different types. It makes committing computer crimes easy. However, if you monitor it appropriately, you can stay abreast of the latest concerns. While the Dark Web does contain a lot of illegal material, it is interspersed with valuable resources and research material. Botnets have been a major security concern for the past 20 years. What are some current trends you have noticed related to botnets? How do you feel they should be addressed? To be honest, not much has changed regarding botnets since hackers began using them. Approaches that are currently being taken to combat botnets are generally ineffective, because they are reactive instead of proactive. In other words, people try to blacklist botnet nodes after an attack is in progress, but do not try to take down botnets as they are built. Even when you know where they are, it takes a coordination of law enforcement and vendors to take them out. The digital threat landscape is always changing and evolving and attacks are becoming increasingly advanced and dangerous. In what ways do you feel cyber security has changed/evolved over the past five years? What changes do you expect to see in the next five years? In my opinion, the same underlying problem persists: known vulnerabilities are not being patched. Companies and vendors are often careless when it comes to fixing known security bugs that exist in their products, and then it comes as no surprise when these flaws are exploited. This is essentially a cyber hygiene issue. Threat actors are succeeding due to knownweaknesses that should not exist, coupled with ineffective protection/detection/reaction strategies. Email attacks are more sophisticated and targeted than ever before. What do you feel is the single biggest email threat that businesses currently face? This is a difficult question to answer, as the email threat landscape has become very diverse and complex. I will say, however, that malware, ransomware, and phishing have always been and continue to be very successful methods of attack. Even with user education and training, user behavior is unreliable, so it is critical to create a strong environment around the user through the use of technology. Investing in a well-designed email security gateway is the single best way to mitigate email threat risk by preventing the attack from getting to the user. Social engineering plays a critical role in many email attack variations like spear phishing, whaling and BEC. In what ways do you think that social engineering has changed/impacted the email threat landscape over the past five years? This may come as a surprise, but I actually don’t think social engineering has changed much at all in recent years. Social engineering attacks have been centered around lying and manipulating from the start. Attacks vary greatly and the tactics used can be very creative and unique; however, the motives behind these attacks are the same or very similar as they were in the beginning: to deceive users into sharing confidential or personal information that can be used for fraudulent purposes. Guardian Digital is looking forward to following up with Ira in another interview once his next book, You Can Stop ‘Stupid’, is published in 2020. . In this enlightening discussion, Ira Winkler reveals thoughts on sophisticated ongoing security, malicious agents, and additional topics.. Ira Winkler, Cybersecurity Expert, Advanced Persistent Security, Threat Intelligence, Social Engineering. . Brittany Day

Calendar%202 Jul 24, 2019 User Avatar Brittany Day
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200