Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How We Identify Malicious Infrastructure At Hunt.io

Summary

Hunt explains how it identifies, tracks and 'burns' malicious C2 servers using TLS certificates, HTTP headers, SSH keys, JARM/JA4x hashes and TCP banners, seen in Gh0st and ShadowPad cases.
Published
Collected

original ↗