With this blog post I am pleased to announce the publication of a new ERNW White Paper about our incident analysis and digital forensics framework. It is available on our website.
Due to the increasing number and impact of computer security incidents, it has become essential to develop and implement efficient measures for their investigation. However, comprehensive forensic analyses are time-consuming, and this time is often not available to security analysts during computer security incidents. As a result, automated tools are increasingly being used. These tools, however, often cover only a limited scope of the necessary analyses and typically require deep technical expertise to be used effectively.
While working on an OT project, we looked into TIA Portal1 project files to extract more information about changes, especially timestamps to be able to reconstruct a timeline. The TIA Portal (Totally Integrated Automation Portal) allows to create and upload programs for PLC (Programmable Logic Controller) devices often used in the OT (Operational Technology) landscape. Some attacks are able to find the workstation with the TIA Portal and manipulate the project to reprogram the PLCs. To be able to reconstruct the timeline of these changes we wanted to be able to read the timestamps of events from the TIA project files.
In this post I want to talk about a very essential part of my workflow when dealing with Bluetooth devices, particularly IoT devices with a corresponding mobile app: Live capture of Android Bluetooth traffic with Wireshark.
Before you stop reading because you think you know how to do this already, the method does not involve pulling bug reports off your phone, and it does not require root. And most importantly it gives you a live packet log in Wireshark.
Yesterday, the BSI (the German Federal Office for Information Security, or Bundesamt für Sicherheit in der Informationstechnik in German) published the first result document from the “Windows dissected” (ger.: “Windows seziert”) project: our analysis of Windows Hello for Business (WHfB). If you have followed this blog over the past year, you have seen the pieces. The full 170-page report has now been published. And it can be downloaded from the project page.
When looking at security measures in Microsoft Entra ID environments, a common
recommendation is to implement Conditional Access policies.
Whether Conditional Access is implemented can be quickly checked, and you can
put a check mark next to it in your best-practice compliance form. However,
simply implementing conditional access will not provide much security. A
phishing attack that we recently analyzed highlights this very well.
Kubeflow is vulnerable to the theft of authorization tokens by any user of the
Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With
this token, the attacker can take over the user’s account and the data that is
processed by that user. The attacker needs a valid user with the kubeflow-edit
or Contributor role in a random Kubeflow namespace to perform this attack. This
is given if Automatic Profile Creation is enabled. A setup based on the
official manifests prior to version 1.10, and on most other packaged Kubeflow
distributions, is vulnerable.
The Istio edit permissions were removed by Kubeflow in a timely manner. Affected
users should update to the latest version to mitigate this issue.
Hardening a Linux client system to an acceptable degree is a time-consuming
process, one that demands familiarity with a broad set of configuration
parameters, framework recommendations, and the reasoning behind each control.
This post introduces our new Linux client hardening guide
(MD,
PDF), a comprehensive, publicly
available hardening reference for Linux systems.
Motivation and Scope
The guide covers the full breadth of controls needed to significantly raise the
security posture of a modern Linux installation while preserving operational
usability (this will be very subjective, the guide reflects my opinion of
“usable”). It has been developed and validated against Ubuntu 24.04 LTS as the
primary reference platform, and cross-tested on Fedora, Debian 12, and Arch
Linux as well as on traditionally server-oriented distributions like openSUSE
Leap 15.6, Debian 12, Rocky Linux 9, and Red Hat Enterprise Linux 9 while not
focussing on those as the guide is created for Linux clients.
Over the last few weeks, I have had a very productive exchange with
Christoph Klaassen
on the impact of AI on security governance and compliance. In this post, we
summarize our thoughts.
While investigating how process mitigation settings are initialized, I
encountered the global variable PspSystemMitigationOptions. Tracing how this
value is populated led me to the CmControlVector. In this blog post, we take a
look at the Windows kernel land configuration manager, especially its global
CmControlVector variable. Quick note: the kernel’s configuration manager is
not related to Microsoft Intune’s
Configuration Manager.
In short, the configuration manager is responsible for managing and implementing
the registry. However, it is also responsible for setting up parts of the system
during early boot.