2 min read

Sources & Methods Newsletter #14 - November 2023

Have questions or suggestions? Send them my way at sources.methods@protonmail.com.

Thanks for reading,

Matthew Conway (@mattreduce)

πŸ“ Sources

Breach Report Collection - A collection public breach reports from companies that shared the TTPs they observed.

πŸ“° Information

Mandiant - The CTI Process Hyperloop: A Practical Implementation of the CTI Process Lifecycle #intelligence #process

US CISA - Scattered Spider advisory #ScatteredSpider #0ktapus

Embee Research - Combining Pivot Points to Identify Malware Infrastructure - Redline, Smokeloader and Cobalt Strike #infrastructure #analysis #tradecraft

Brian Warehime - Collection Maturity Model Framework #collection #maturitymodels #metrics

Vertex Project - Using Spotlight Extractors for Arbitrary Data #tooling #synapse

TrendMicro - How Kopeechka, an Automated Social Media Accounts Creation Service, Can Facilitate Cybercrime #cybercrime #infrastructure

MITRE - ATT&CK v14 Unleashes Detection Enhancements, ICS Assets, and Mobile Structured Detections #frameworks #ATTCK

Bellingcat - Following the Money: A Beginner’s Guide to Using the OpenCorporates API #OSINT #sources

Filigran - Optimize Incident Response and Investigations with OpenCTI Case Management #investigation #tooling

πŸ›  Tools



A command-line DNS client that's nice to use, with colorized output and convenient flags for DNS-over-HTTPS and DNS-over-TLS.



Browser extension for quick access to search or scan email addresses, URLs, CVEs, wallet addresses and more across many services including VirusTotal and BlockChair.



A particularly powerful and feature-rich Telegram collection tool. For gathering an user's activity, understanding their network and associates, detecting identifiers such as email addresses and phone numbers (configurable via regex), and even extracting GPS coordinates from EXIF metadata for visualization.



A collection of tools and detections for the Sliver C2 Framework, popular with red teams and real threats alike.



Pandas enhancements for working with geographic data, "enables you to easily do operations in python that would otherwise require a spatial database such as PostGIS."

πŸ“† Events

Coming up in 2024:


πŸ“ Washington, DC, US and online
πŸ“Š Summit: Jan 29-30
πŸ“Š Training: Jan 31 - Feb 5
πŸ”— https://www.sans.org/cyber-security-training-events/cyber-threat-intelligence-summit-2024/


πŸ“ San Francisco, CA, US
πŸ“Š Conference May 4-5
πŸ”— https://bsidessf.org/cfp