top of page
Work Overview
LATEST PROJECTS
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque

Blog
Search


Phishing Attacks and Social Engineering: Recognizing the Signs and Preventing Exploitation
In today's digitally connected world, cybersecurity is no longer optional—it's a necessity. At Inception Security, we know that the only way to stay ahead of cybercriminals is to be informed and vigilant. In this blog post, we will discuss two common types of cyber attacks: phishing and social engineering, highlighting the signs to watch for and offering tips on preventing exploitation. Section 1: Understanding Phishing Attacks Phishing attacks are online scams in which cyber
2 min read


Understanding the Dark Web: What Every Business Owner Needs to Know
The Dark Web can be daunting and mysterious, often associated with criminal activity and hidden dangers. As a business owner, it's essential to understand the Dark Web, its potential impact on your organization, and how to protect your company from hidden cyber threats. This comprehensive guide will explore the Dark Web's intricacies, common risks, and actionable steps to safeguard your business. 1. What is the Dark Web, and Why Should Business Owners Care? The Dark Web is a
3 min read


Play Ransomware Group
The Play ransomware group has been making headlines recently due to its use of a new method to exploit vulnerabilities in Microsoft Exchange. Dubbed the ProxyNotShell vulnerabilities (CVE-2022-41080 and CVE-2022-41082), this method exploits the Outlook Web Application frontend to reach the Powershell remoting service in Exchange. Researchers at CrowdStrike discovered this method while investigating recent Play ransomware incidents and dubbed it OWASSRF. The Play group is a ne
3 min read


Forensic Friday - Jump Lists
What are Jump Lists? Jump Lists are windows features introduced with Windows 7, and they contain information about recently accessed applications and files. They allow files and applications to be pinned to the taskbar. There are two forms of jump list that can be created in windows. The first form is called AUTOMATICDESTINATIONS-MS. Like its name, these jump lists are created automatically when the users open a file or an application. This jump list is located in the followi
2 min read


Cyber Insurance Benefits
What is Cyber Insurance? A cyber insurance policy is commonly called "cyber risk insurance" or "cyber liability insurance" coverage. It is a product that allows businesses to transfer the costs involved with cyber recovery from a cyber incident or similar event. Typically, the critical aspect of cyber insurance will be network security coverage. This coverage is leveraged in a network security failure, such as data breaches, malware, ransomware attacks, business accounts, an
3 min read


Forensic Friday - Profile Lists
What are Profile Lists? Windows keeps track of user-profiles and their locations in the registry. The profile location is stored under the key below: HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList This registry key contains one subkey for each user profile on a Windows machine. Inside of each of these subkeys is a registry value called ProfileImagePath that includes the profile path for all users. You can obtain information on user profiles such as profile las
3 min read


Business Continuity and Disaster Recovery
Business continuity and disaster recovery (BCDR or BC/DR) is a collection of processes and procedures that assist a company in recovering from a disaster and returning to normal business operations. It is a broad approach that encompasses both IT and commercial operations and tasks in the aftermath of a disaster. BCDR frequently integrates business operations and information technology to decrease catastrophic risks and support organizations in swiftly resuming normal operati
4 min read


Forensic Friday - Prefetch
What is Windows Prefetch? Windows Prefetch creates files when a user opens an application on a Windows host. The Windows Operating system will make a prefetch record when an application is run from a specific area for the absolute time. Microsoft introduced prefetch with the Windows XP operating system. The idea behind the prefetch is that it would accelerate the boot process and start-up process. In older versions of Windows, prefetch files were limited to 128 files. With ne
4 min read


Emotet Changing Techniques
Phishing attacks remain the number one technique used in cyberattacks. Some of the most common phishing attacks leveraged attachments to facilitate the initial infection chain. We disproportionally see Microsoft Office documents and PDF files used to embed the malicious code as far as the attachments themselves go. When we say Microsoft Office documents, we refer to files created by the Microsoft Office suite such as Microsoft Word, Excel, PowerPoint, etc. Historically we wou
3 min read


Spring4Shell
A critical vulnerability CVE-2022-22965 (Spring4Shell or SpringShell) was found on March 29, 2022, in an open-source Java framework while testing named Spring. This vulnerability allows the attacker to execute arbitrary code on a web server. Spring is a widely used framework, so this vulnerability can be highly lethal. The data binding feature of Spring Framework was used to bind data in an HTTP request to some of the objects being used in an application. The vulnerability ex
3 min read


RPC Vulnerability (CVE-2022-26809)
On patch Tuesday, April 12, 2022, Microsoft released patches for CVE-2022-26809. A vulnerability that is a zero-click exploit targeting Microsoft RPC services. As of right now, there is not a PoC out in the wild. However, the scanning for the vulnerability has increased. Based on the impact of this vulnerability, it is likely that there will be a PoC in the wild soon. Patch your servers now before the PoC come out. What is RPC? The Remote Procedure Call (RPC) service is used
2 min read


Cyberattacks On The Rise
As we look across the landscape, we see that cyberattacks continue to succeed in all business sectors. In the cases we have observed, the cyberattack leveraged weak security controls and, as a result, could have been prevented by organizations adopting security best practices. A new study shows that ransomware, phishing, social engineering, denial of service (DoS) attacks, and the business fallout of a data breach rank as the top concerns of global organizations. The recently
1 min read


Importance of EDR
Endpoint Detection & Response (EDR) A critical task for most organizations has become setting up advanced threat protection as cyberattacks have skyrocketed and become more sophisticated. Starting with a robust endpoint detection and response system is the first step in this process. Detecting and responding to endpoint threats, also known as EDR, is a cybersecurity process that gathers and analyses data collected by endpoints, usually workstations and servers. As a result, s
3 min read


What is Qbot / Qakbot
QBot, also known as Qakbot or pinkslipbot, is an information stealer that has been active since 2007. It is malware software that can monitor the browser's activities and lots of information on the victim's computer. It is also known as a banking trojan capable of stealing finance-related data from the infected device and loader by using c2 servers to target payload and downloads. Other important information that QBot can steal from a system are: Name of the account City Coun
3 min read


An Encounter with Pandora
Pandora ransomware came into the spotlight in March of 2022 after posting some high-profile victims on its leak site. The ransomware group announced its first victim on Feb 21st, 2022. Their biggest victim was Denso, a car parts manufacturer. After an attack on one of its offices in Germany, Denso confirmed that cybercriminals leaked stolen, classified information from the Japan-based car-components manufacturer. Pandora claims to have exfiltrated 1TB of data from Denso. So w
4 min read


How are your Backups?
Producing and preserving copies of data to safeguard businesses against data loss is referred to as backup and recovery. The data from backups are usually restored to its previous location or to a different place where it will be used to substitute the lost or damaged data. Companies of all sizes need to protect themselves against ransomware, phishing scams, malware, and other cyberattacks. These attacks can often completely devastate your company in the blink of an eye. Howe
3 min read


Lessons Learned from Conti leaks
A Russian-based Conti Ransomware gang chat leak has started a new debate. The massive chat leak from inside has provided a clearer picture of cybercriminal motives to the cyber researchers. Furthermore, it has made it evident that the Russian Ukraine war has divided the criminals who work for ransomware. Some of the lessons that cyber researchers can learn are: Hacking computers for ransomware groups is a boring job One of the most prevalent comments about chat leaks is that
3 min read


5 Reasons you should not pay ransomware attackers
Ransomware is the type of suspicious software Cybercriminals use to encrypt your data, rendering it unusable. As a result, the attackers demand the ransom money to release the victim's data. Once the attack is successfully executed, the victim has to pay money to access their data, but paying to the attacker is not a good decision because once they produce, the attacker knows they can get money from the victim, so they attack again and again. If you don't pay, you'll lose mo
3 min read


What is Incident Response?
Incident response is a method for dealing with various forms of security events, cyber threats, and data breaches in an organized manner. The goal of the incident response approach is to identify, contain, eradicate, and reduce the cost of a cyberattack or live event. To be prepared for a future attack, a well-built incident response (IR) plan will be essential in limiting the potential business impacts of an incident. It is critical to address security breaches quickly and e
3 min read


Proxyshell Vulnerabilities
In Microsoft Exchange, the three known vulnerabilities that threat actors use to get initial access are often referred to collectively as Proxyshells. These three known vulnerabilities are CVE-2021-34473, CVE-2021-34523, and CVE-2021- 31207. The attackers use these three vulnerabilities by bypassing the authentication and running a remote code as a privileged user. Microsoft has classified the Proxyshell vulnerabilities as critical. However, the proxyshell vulnerability is re
4 min read
bottom of page
