Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, November 12, 2015

Spy Hunter Holiday Challenge 2015

This holiday season I have created another network forensics challenge for the community to try and solve. This scenario called “Spy Hunter – Operation Ares” is the second in a series that follows the questionable activities of Insider1.

All solutions should be submitted to me at Jordan 2175 with no space at Google’s mail service no later than December 20th, 2015. Winners will be announced in January. Entries will be rated based on completeness and overall explanation of what happened and how.

Please NOTE I will NOT accept any documents in PDF or Word format.  Only plain text email and documents, something readable by pine, vim or emacs, will be accepted. By submitting a solution you grant me the right to list your name on this blog.

Good Luck.

PDF: https://drive.google.com/file/d/0By0KeB0IEqeTNnd1WUFHQmt0TzQ/view?usp=sharing&resourcekey=0-B6SOqOuNK2Eh4vV7HrWp8w
MD5 (SpyHunter-Operation_Ares-ver1.pdf) = 5b428889accb3f7760c4418bb5b5b629

PCAP: https://drive.google.com/file/d/0By0KeB0IEqeTaHZDdWhMNUR2T00/view?usp=sharing&resourcekey=0-_GJ38BPGpaVsArQGJSiZ6w
MD5 (SpyHunter-Operation_Ares-ver1.pcap.zip) = 02aa6ab22bd628e819ace4d3df669caf

Official solution information will be available to full-time faculty members teaching courses in digital forensics or cyber security at accredited academic institutions.

Thursday, April 16, 2015

DHS and MITRE to Transition STIX and TAXII to OASIS

"DHS LEADS EFFORT TO TRANSITION AUTOMATED CYBERSECURITY INFORMATION SHARING SPECIFICATIONS TO INTERNATIONAL COMMUNITY

We are pleased to announce today that the US Department of Homeland Security (DHS) intends to transition the STIXTM and TAXIITM specifications for the automated exchange of cybersecurity data to the Organization for the Advancement of Structured Information Standards (OASIS), a non-profit consortium that drives the development, convergence, and adoption of open standards for the global information society.

This transition is the culmination of three years of work in collaboration with the private sector to define, develop, and implement a robust set of technical specifications to advance the state of the practice in computer network defense. From the inception of these efforts, DHS has maintained that STIX and TAXII would be transitioned to an internationally-recognized standards development organization once the specifications reached an appropriate level of maturity. That day has come, and the transition to OASIS represents an exciting next step in the continued advancement and evolution of STIX and TAXII.

OASIS has an excellent track record in successfully transitioning accepted technical specifications to voluntary consensus standards and in recognizing and building on that existing work. In addition, the global membership of OASIS mirrors the diversity of the STIX/TAXII community and includes a wide variety of government entities, technology vendors, academic institutions, and end-user organizations that have been so critical to the success of the specifications. And finally, the selection of OASIS guarantees that the entire family of STIX/TAXII specifications will always be freely available to anyone around the world.

The transition of STIX and TAXII to OASIS will provide greater transparency and stakeholder participation in the development process which will help ensure the stability and continuing viability of STIX and TAXII as true international standards. These changes have the potential to significantly increase adoption and use of STIX and TAXII and thereby strengthen global cybersecurity practices.

This transition will allow DHS to concentrate our efforts on ensuring the widest and most effective implementations of STIX and TAXII to achieve our mission. We will continue to play an active role through our participation in OASIS, and we will continue to support the development of critical documentation, tools and application programming interfaces.

The only thing that is changing is that the direction of STIX and TAXII will now be in the hands of a robust global community committed to its success. We are confident that this transition will mark the beginning of an even more vibrant and successful cybersecurity ecosystem built on STIX and TAXII that will yield significant improvements in the overall security of our cyber infrastructure."

Tuesday, April 14, 2015

JSON Support for TAXII 1.1

Today on the TAXII discussion list I released v1.00 of the JSON Message Binding Specification for TAXII 1.1.  APIs written in Go, for generating and consuming JSON based TAXII messages can be found here on Github.

Thursday, January 8, 2015

Results of the 2014 Holiday Spy Hunter Network Forensics Challenge

I hope everyone had a great holiday season and enjoyed working through the challenge. After reading through loads of really great submissions, the top 3 reports, being 90+% complete, were from:

  1. Peter VanBuskirk
  2. Matthew Edmondson
  3. Rich Cassara 

A round of virtual congratulations is in order for these three and everyone else that submitted solutions. For those of you that have been asking, the next challenge should be ready by midyear.

Wednesday, November 5, 2014

Spy Hunter Holiday Challenge 2014

This holiday season I have created a network forensics challenge for the community to try and solve. This scenario, called “Spy Hunter – Operation Hermes” is the first in a new series I am going to create and publish here at My War With Entropy.

All solutions should be submitted to me at Jordan 2175 with no space at Google’s mail service no later than December 20th, 2014. Winners will be announced in January. Entries will be rated based on completeness and overall explanation of what happened and how.

Please NOTE I will NOT accept any documents in PDF or Word format.  Only plain text email and documents, something readable by pine, vim or emacs, will be accepted. By submitting a solution you grant me the right to list your name on this blog.

Good Luck.

PDF: https://drive.google.com/file/d/0By0KeB0IEqeTX0ZYWTJqRWpXdlU/view?usp=sharing&resourcekey=0-A60aXqHU_Bml20VruR2iIg
MD5 (SpyHunter-Operation_Hermes-ver1.pdf) = 6d2bb7d0ab0d83ba2da8a1142deca758

PCAP: https://drive.google.com/file/d/0By0KeB0IEqeTVl9DRUpSU1lYclk/view?usp=sharing&resourcekey=0-YR30-ma8qjCx_2gS91rJeA
MD5 (SpyHunter-Operation_Hermes-ver1.pcap.zip) = de20687a9287dcf66ddf40d699915994

Official solution information will be available to full-time faculty members teaching courses in digital forensics or cyber security at accredited academic institutions.



Monday, October 27, 2014

A Better Hex Editor for Mac OSX

It does not take many hours of editing binary files with a basic hex editor for you to ask yourself the question, is there a better tool?  So with that question in mind, I went looking and after a few hours found a great tool for Mac OSX, it is called "Synalyze It Pro" from http://synalysis.net/

Now there are a lot of really neat features, which you can view on the App Store or at the author's web site.  But the one I will call out is the ability to write custom grammars for the binary files you work with and color code them based on what they are.

Now I work with a lot of PCAP files, and this tool has proven to be very help.  I am going to share the grammar file I wrote called libpcap.grammar with a GPLv3 license.

Here is a screen shot of my grammar file working on a PCAP file.