CD

CPT Derek Ditch

Derek is a leader and educator striving to change the way the world defends against cyber threat actors. A captain in the Missouri Army National Guard on the Missouri Cyber Team (MOCYBER) and a core developer of RockNSM; he is working towards his goal to take back the home field advantage and empower cyber defenders around the globe. Derek holds a MS in Computer Science from Missouri S & T with an emphasis of research in critical infrastructure protection. He served at the NSA/CSS Threat Operations Center in Texas as a Lead Intrusion Analyst of several nation state actors targeting service members and other Federal government agencies.

S'inscrire
Articles de CPT Derek Ditch
PHOREAL Malware Targets the Southeast Asian Financial Sector
Security Labs

PHOREAL Malware Targets the Southeast Asian Financial Sector

Elastic Security discovered PHOREAL malware, which is targeting Southeast Asia financial organizations, particularly those in the Vietnamese financial sector.

Daniel Stepanic
The Elastic Container Project for Security Research
Security Labs

The Elastic Container Project for Security Research

The Elastic Container Project provides a single shell script that will allow you to stand up and manage an entire Elastic Stack using Docker. This open source project enables rapid deployment for testing use cases.

Andrew Pease
Doing time with the YIPPHB dropper
Security Labs

Doing time with the YIPPHB dropper

Elastic Security Labs outlines the steps collect and analyze the various stages of the REF4526 intrusion set. This intrusion set uses a creative approach of Unicode icons in Powershell scripts to install a loader, a dropper, and RAT implants.

Seth Goodwin
ICEDIDs network infrastructure is alive and well
Security Labs

ICEDIDs network infrastructure is alive and well

Elastic Security Labs details the use of open source data collection and the Elastic Stack to analyze the ICEDID botnet C2 infrastructure.

Daniel Stepanic
Extracting Cobalt Strike Beacon Configurations
Security Labs

Extracting Cobalt Strike Beacon Configurations

Part 2 - Extracting configurations from Cobalt Strike implant beacons.

Daniel Stepanic
CUBA Ransomware Campaign Analysis
Security Labs

CUBA Ransomware Campaign Analysis

Elastic Security observed a ransomware and extortion campaign leveraging a combination of offensive security tools, LOLBAS, and exploits to deliver the CUBA ransomware malware.

Daniel Stepanic
Going Coast to Coast - Climbing the Pyramid with the Deimos Implant
Security Labs

Going Coast to Coast - Climbing the Pyramid with the Deimos Implant

The Deimos implant was first reported in 2020 and has been in active development; employing advanced analysis countermeasures to frustrate analysis. This post details the campaign TTPs through the malware indicators.

Andrew Pease
FORMBOOK Adopts CAB-less Approach
Security Labs

FORMBOOK Adopts CAB-less Approach

Campaign research and analysis of an observed FORMBOOK intrusion attempt.

Derek Ditch
Collecting and operationalizing threat data from the Mozi botnet
Security Labs

Collecting and operationalizing threat data from the Mozi botnet

The Mozi botnet is an ongoing malware campaign targeting unsecured and vulnerable networking devices. This post will showcase the analyst journey of collecting, analyzing, and operationalizing threat data from the Mozi botnet.

Andrew Pease
Collecting Cobalt Strike Beacons with the Elastic Stack
Security Labs

Collecting Cobalt Strike Beacons with the Elastic Stack

Part 1 - Processes and technology needed to extract Cobalt Strike implant beacons

Derek Ditch