When the fuzzers come knocking on port 389: Hunting injection canaries in LDAP
Core protocols like LDAP are often left unmonitored. See how Zeek's ldap_search and DNS logs expose injection canaries and confirm whether attacks...
Core protocols like LDAP are often left unmonitored. See how Zeek's ldap_search and DNS logs expose injection canaries and confirm whether attacks...
At Black Hat Asia, everyday IoT devices exposed authentication tokens and credentials over cleartext HTTP, showing what the network sees but...
Recapping our learnings from the Black Hat NOC, using packet captures and Zeek scripting to decode threat payloads.
Recapping our learnings from the Network Operations Center (NOC) at Black Hat USA 2024. Using historical network logs to detect threats during the...
Learn how Zeek’s metadata approach can help focus patching efforts for the SSH “Terrapin” attack.
Learn how the kill web concept can be applied to cybersecurity, and how it addresses some of the concerns with the kill chain.
Take a look at an incident we detected, investigated, triaged, and closed using Corelight at Black Hat Las Vegas 2023.
Researchers at wiz.io found vulnerabilities in Windows OMI; Corelight has open-sourced a Zeek package for the most severe of these vulnerabilities.
In this blog we aim to provide a little insight into part of the lifecycle of Corelight Lab’s response to a critical HTTP vulnerability.