<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>0xThiebaut's Blog</title><link>https://thiebaut.dev/</link><description>A dump for security-related thoughts and content.</description><webfeeds:accentColor>000000</webfeeds:accentColor><webfeeds:related layout="card" target="browser"/><webfeeds:cover image="https://thiebaut.dev/images/thumbnail.2dcf302a15c676b0673e0845fec20ccfced2e6e18033fb2f6c116ebdf507743e2be6d26ba36dcd738083f87768a1d16bea13ea437b6d6779dcaabf5d6d1ec910.png"/><language>en</language><lastBuildDate>Tue, 07 Nov 2023 00:00:00 +0100</lastBuildDate><atom:link href="https://thiebaut.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>Generating IDA Type Information Libraries from Windows Type Libraries</title><link>https://thiebaut.dev/articles/generating-ida-type-information-libraries-from-windows-type-libraries/</link><pubDate>Tue, 07 Nov 2023 00:00:00 +0100</pubDate><guid>https://thiebaut.dev/articles/generating-ida-type-information-libraries-from-windows-type-libraries/</guid><description>In this quick-post, we&amp;rsquo;ll explore how to convert Windows type libraries (TLB) into IDA type information libraries (TIL).</description></item><item><title>IcedID &amp; Qakbot's VNC Backdoors: Dark Cat, Anubis &amp; Keyhole</title><link>https://thiebaut.dev/articles/icedid-and-qakbot-vnc-backdoors-dark-cat-anubis-keyhole/</link><pubDate>Mon, 20 Mar 2023 00:00:00 +0100</pubDate><guid>https://thiebaut.dev/articles/icedid-and-qakbot-vnc-backdoors-dark-cat-anubis-keyhole/</guid><description>In this post we introduce Dark Cat, Anubis and Keyhole, three IcedID &amp;amp; Kakbot VNC backdoor variants NVISO observed. We&amp;rsquo;ll follow by exposing common TTPs before revealing information leaked through the attackers&amp;rsquo; clipboard data.</description></item><item><title>Diffing Sysmon's v14.11 ClipboardChange Event for Arbitrary Write</title><link>https://thiebaut.dev/articles/diffing-sysmon-clipboardchange-for-arbitrary-write/</link><pubDate>Mon, 14 Nov 2022 11:15:00 +0100</pubDate><guid>https://thiebaut.dev/articles/diffing-sysmon-clipboardchange-for-arbitrary-write/</guid><description>My first BinDiff: Checking the Sysmon v14.11 patch to turn a ClipboardChange event into arbitrary writing.</description></item><item><title>Enforcing a Sysmon Archive Quota</title><link>https://thiebaut.dev/articles/enforcing-a-sysmon-archive-quota/</link><pubDate>Thu, 30 Jun 2022 15:19:00 +0100</pubDate><guid>https://thiebaut.dev/articles/enforcing-a-sysmon-archive-quota/</guid><description>This blog post will create a Sysmon archive quota through WMI event consumption to avoid storage exhaustion.</description></item><item><title>Detecting &amp; Preventing Rogue Azure Subscriptions</title><link>https://thiebaut.dev/articles/detecting-and-preventing-rogue-azure-subscriptions/</link><pubDate>Wed, 18 May 2022 18:41:00 +0100</pubDate><guid>https://thiebaut.dev/articles/detecting-and-preventing-rogue-azure-subscriptions/</guid><description>In this blog post we will cover why rogue subscriptions are problematic and revisit a solution published a couple of years ago on Microsoft&amp;rsquo;s Tech Community. Finally, we will conclude with some hardening recommendations to restrict the creation and importation of Azure subscriptions.</description></item><item><title>Automated Sigma Rule Generation from MISP Threat Intelligence</title><link>https://thiebaut.dev/articles/automated-sigma-rule-generation-from-misp-threat-intelligence/</link><pubDate>Tue, 09 Jun 2020 21:00:00 +0100</pubDate><guid>https://thiebaut.dev/articles/automated-sigma-rule-generation-from-misp-threat-intelligence/</guid><description>Introducing the Sigma Importer – a way of generating thousands of qualitative vendor-agnostic Sigma rules from threat intelligence feeds such as MISP.</description></item><item><title>Automated Anomaly-Detection in DNS Records</title><link>https://thiebaut.dev/articles/automated-anomaly-detection-in-dns-records/</link><pubDate>Fri, 17 Jan 2020 14:00:00 +0100</pubDate><guid>https://thiebaut.dev/articles/automated-anomaly-detection-in-dns-records/</guid><description>Audit and monitor DNS zones using Dnsbeat. This article introduces Dnsbeat&amp;rsquo;s working and how it can be used to create a DNS honeypot.</description></item></channel></rss>