top of page
Work Overview
LATEST PROJECTS
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque

Blog
Search


Understanding NightEagle: An In-Depth Analysis of APT-Q-95
At Inception Security, our mission is to equip organizations with the knowledge and tools to combat advanced cyber threats. As experts in threat intelligence and incident response, we've conducted extensive research into numerous APT campaigns. This includes uncovering the NightEagle group—also tracked as APT-Q-95—for its precision and sophistication. Through our proprietary analysis and forensic investigations, we've determined that this North American-aligned APT has been l
5 min read


Understanding the Mockingjay Malware
Cybersecurity is a lot like a game of chess. You must anticipate your opponent's moves and devise strategies to stop them. But what happens when the opponent changes the rules of the game? A new threat called the Mockingjay malware shows us how crucial foresight is in cybersecurity. Recently, a new process injection technique, Mockingjay, has been discovered, making waves in cybersecurity. This malware can bypass security solutions to execute malicious code on compromised sys
3 min read


Understanding and Mitigating the MOVEit Transfer CVE-2023-34362 Vulnerability
On May 31, 2023, Progress released a security advisory for their MOVEit Transfer application detailing a SQL injection vulnerability leading to remote code execution. Customers were urged to update to the latest version. This vulnerability, CVE-2023-34362, was believed to have been exploited in the wild as a 0-day dating back at least 30 days. Threat intelligence reports suggested that exploitation activity could be traced back to 2021. The attacks were attributed to the cl0p
3 min read


7 Reasons Why Businesses Need TableTop Exercises
Top Reasons Why Incident Response Table Top Exercises Are Important In today's digital world, cyber threats are becoming more sophisticated, frequent, and disruptive than ever before. As a result, organizations must take a proactive approach to manage cyber risks, and incident response (IR) tabletop exercises are a crucial part of that approach. In this blog post, we will explore why IR tabletop exercises are essential for businesses and organizations and how Inception Securi
3 min read


5 Reasons Why Risk Assessments are Important for Businesses
In today's digital age, cybersecurity threats are on the rise, and it's more important than ever for businesses to take proactive measures to protect themselves. Cyberattacks can result in data breaches, financial losses, and reputational damage, which can be devastating for any business. One of the most effective ways to mitigate these risks is by conducting regular cybersecurity risk assessments. Here are 5 reasons why risk assessments are crucial for your business: Identif
3 min read


Understanding ManageEngine Vulnerability CVE-2022-47966
ManageEngine's CVE-2022-47966 vulnerability is a critical issue that allows an attacker to gain remote code execution on the server running the ManageEngine software. The vulnerability is caused by two main factors: the validation order of SAML and XSLT injection. Firstly, the vulnerability is caused by how the software handles SAML information validation. SAML is a standard for exchanging authentication and authorization data between systems. In ManageEngine, the software fa
2 min read


Understanding the Exchange Server Attacks: Exploiting CVE-2022-41040 and CVE-2022-41082
In recent months, we have seen a surge in attacks targeting Exchange Servers. These attacks have been made possible by exploiting the CVE-2022-41040 and CVE-2022-41082. This post will delve into the details of these vulnerabilities and how attackers exploit them to gain access to Exchange Servers. Exploiting CVE-2022-41040: The first step in this attack is exploiting CVE-2022-41040 to gain access to the PowerShell API endpoint of the Exchange Server. This vulnerability arises
2 min read


Play Ransomware Group
The Play ransomware group has been making headlines recently due to its use of a new method to exploit vulnerabilities in Microsoft Exchange. Dubbed the ProxyNotShell vulnerabilities (CVE-2022-41080 and CVE-2022-41082), this method exploits the Outlook Web Application frontend to reach the Powershell remoting service in Exchange. Researchers at CrowdStrike discovered this method while investigating recent Play ransomware incidents and dubbed it OWASSRF. The Play group is a ne
3 min read


Citrix CVE-2022-27518
Citrix is a global leader in providing digital workspace solutions, and as such, it is a popular target for cyber attackers. One such attack is the recently discovered vulnerability known as CVE-2022-27518. In this blog, we will discuss the details of this vulnerability, how it affects Citrix and the technical workings of this exploit. First, let's define what a CVE is. Common Vulnerabilities and Exposures (CVE) is a standardized way of identifying and categorizing vulnerabil
3 min read


Citrix CVE-2022-27516
CVE-2022-27516 is a severe vulnerability recently discovered in Citrix, a widely-used software program. This vulnerability has the potential to wreak havoc on Citrix users, and it is important for individuals and organizations that use the program to take steps to protect themselves against it. The vulnerability in question lies within Citrix's handling of certain types of data inputs. Specifically, the program fails to properly validate and sanitize user-supplied input, allo
2 min read


Fortinet CVE-2022-42475
CVE-2022-42475 is a recently discovered vulnerability in the software that powers Fortinet, a popular cybersecurity company. This vulnerability has the potential to be exploited by hackers to gain unauthorized access to sensitive information, making it a serious concern for both Fortinet and its customers. The vulnerability is a type of flaw known as a "buffer overflow" error. This occurs when a computer program attempts to store more data in a temporary memory buffer than it
2 min read


Forensic Friday - Jump Lists
What are Jump Lists? Jump Lists are windows features introduced with Windows 7, and they contain information about recently accessed applications and files. They allow files and applications to be pinned to the taskbar. There are two forms of jump list that can be created in windows. The first form is called AUTOMATICDESTINATIONS-MS. Like its name, these jump lists are created automatically when the users open a file or an application. This jump list is located in the followi
2 min read


Remote Assistance Tools - T1219
Let's talk about remote assistance tools! As you would expect, a remote assistance tool is used to assist end-users from a remote location. These tools are great and are widely used by helpdesk and IT support staff to help users with various workstations issues. If allowed within the settings of the host computer, the remote user can also share control of the host computer, opening files, accessing information, and inputting data by mouse and keyboard. This is extremely helpf
2 min read


Microsoft Office - Arbitrary Code Execution
We have recently observed threat actors evolving their procedures in light of Microsoft disabling macros by default in office documents. This new technique would allow threat actors to continue to bypass security controls to infect one or more hosts in an environment. In light of the latest Microsoft Office vulnerabilities, we will likely see broad adoption of macro-less infected documents that will lead to many organizations getting hacked. While Microsoft has shared mitigat
3 min read


Stale Active Directory User Accounts
A user account is created in Active Directory for each user in your environment. Over time as users leave the organization, their accounts do not always get removed from Active Directory. As a result, many organizations have an excessive amount of stale user accounts in Active Directory. You can identify a stale account using the last time the password was changed or the user's last login timestamp. Stale user accounts in Active Directory pose a significant risk to the organi
3 min read


Cyber Insurance Benefits
What is Cyber Insurance? A cyber insurance policy is commonly called "cyber risk insurance" or "cyber liability insurance" coverage. It is a product that allows businesses to transfer the costs involved with cyber recovery from a cyber incident or similar event. Typically, the critical aspect of cyber insurance will be network security coverage. This coverage is leveraged in a network security failure, such as data breaches, malware, ransomware attacks, business accounts, an
3 min read


Forensic Friday - Profile Lists
What are Profile Lists? Windows keeps track of user-profiles and their locations in the registry. The profile location is stored under the key below: HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList This registry key contains one subkey for each user profile on a Windows machine. Inside of each of these subkeys is a registry value called ProfileImagePath that includes the profile path for all users. You can obtain information on user profiles such as profile las
3 min read


CVE-2022-1388 (F5 BIG-IP)
CVE-2022-1388 is a critical CVE (CVSS 9.8) in F5 Networks’ BIG-IP solution management interface. This CVE will allow threat actors to bypass F5’s iControl REST authentication to gain remote code execution. This is not the first significant vulnerability we have seen with the BIG-IP platform. In 2021, security practitioners worldwide observed attacks against the iControl REST API as well. This was tracked as CVE-2021-22986. The vulnerability is what security researchers call a
3 min read


Business Continuity and Disaster Recovery
Business continuity and disaster recovery (BCDR or BC/DR) is a collection of processes and procedures that assist a company in recovering from a disaster and returning to normal business operations. It is a broad approach that encompasses both IT and commercial operations and tasks in the aftermath of a disaster. BCDR frequently integrates business operations and information technology to decrease catastrophic risks and support organizations in swiftly resuming normal operati
4 min read


Forensic Friday - Prefetch
What is Windows Prefetch? Windows Prefetch creates files when a user opens an application on a Windows host. The Windows Operating system will make a prefetch record when an application is run from a specific area for the absolute time. Microsoft introduced prefetch with the Windows XP operating system. The idea behind the prefetch is that it would accelerate the boot process and start-up process. In older versions of Windows, prefetch files were limited to 128 files. With ne
4 min read
bottom of page
