user avatar
Curated Intelligence
@CuratedIntel
Bringing together intelligence researchers and incident responders. #TrackThePlanet
Joined September 2020
Posts
  • Pinned
    user avatar
    ICYMI: In October 2024, we released the CTI Research Guide. It aims to help practitioners learn more about how to effectively perform the collection, processing, analysis, and production stages of the CTI lifecycle. 🔗curatedintel.org/2024/10/the-ct…
  • user avatar
    Members of Curated Intel have compiled a public list of IOC feeds and threat reports focused on the recent Log4Shell exploit targeting CVE-2021-44228 in Log4j.
  • user avatar
    ⚠ A well-known Initial Access Broker (IAB) on a cybercriminal underground forum has reappeared after a several month hiatus, now offering a 0day RCE vulnerability, as well as domain admin access, and network hacking services #cti #cybercrime #threaintel
  • user avatar
    🇷🇺 OSINT on REvil In this feature, @SttyK shares geolocation reports related to the #REvil ransomware gang. In January, Russia's #FSB announced the arrest of some REvil ransomware gang members; the raid videos reveal some of their home addresses. 🔗 curatedintel.org/2022/01/osint-…
  • user avatar
    Curated Intel is working with analysts from around the world to provide useful information to organisations in #Ukraine looking for additional free threat intelligence feeds. The CI community will update this repository as the situation progresses.
  • user avatar
    ⚠️PSA: Curated Intel DFIR teams noticed a severe uptick in Akira Ransomware cases in Jan 2024. Same repeated TTPs: - Dwell times of < 4 hours on average - Cisco ASA VPN for Access - WinSCP for exfil / WinRAR for compression - AnyDesk RMM for persistence - 'w.exe' Akira payload
  • user avatar
    Learn about the Initial Access Broker (IAB) space with this new visual! Created by @TrevorGiffen with notable peer review from the @CuratedIntel community🌀 🔗Blog: curatedintel.org/2021/10/initia… 🔗PNG: github.com/curated-intel/… 🔗SVG: github.com/curated-intel/… #CTI #IAB #AccessBrokers
  • user avatar
    🇺🇦 Curated Intel now tracks Ukrainian personal data shared on underground forums. We added a 'data brokers' table to our Repo. We have documented ~89 instances of Ukrainian data being shared/discussed on underground forums since December 1, 2021. 🔗 github.com/curated-intel/…
  • user avatar
    🌐 Curated Intel is tracking hacktivist, cybercriminal, and regional APT groups surrounding the war in Israel. We describe the types of campaigns and attacks we've observed so far and have also provided recommendations for CTI analysts monitoring the war. curatedintel.org/2023/10/tracki…
  • user avatar
    We centralized most #Log4Shell IOCs in one place! CSV #1 — 11 feeds (MISP): github.com/curated-intel/… CSV #2 — AV OTX pulses (MISP): github.com/curated-intel/… CSV #3 — validated IOCs (ETAC): github.com/curated-intel/… Curated by: @TrevorGiffen @0xDISREL @BushidoToken @MISPProject
  • user avatar
    🌐 Curated Intelligence is sharing a new resource we created for those of you looking to learn more about #CyberThreatIntelligence. This includes a collection of essential reading material & helpful projects created by other #CTI professionals github.com/curated-intel/…
  • user avatar
    Grief ransomware group has ransomed the National Rifle Association (NRA).
  • user avatar
    📣 With the help of Equinix Threat Analysis Center (ETAC)™️ team and the Curated Intel community we have created a GitHub repository to assist with tracking the MOVEit Transfer Hacking Campaign
  • user avatar
    🇧🇾 Curated Intel member, @SttyK, asked Cyber-Partisans to share a malware sample from the ransom of Belarusian Railway; they sent an incident response report revealing a past compromise of Belarus' Academy of Public Administration. We investigated. 🔗 curatedintel.org/2022/01/hackti…