In today’s blog post, we will be going over how to create honey folders with no additional tooling.

Cyber Deception allows for the placement of traps with no business value, “normal” is defined as no interaction.

Its value lies in being probed, attacked, or compromised.

Any interaction is abnormal and thus actionable.

We will be leveraging a Desktop.ini file, which provides us with the ability to load icons from a remote location.

NOTE: To enable this feature, you have to create the value `”EnableShellShortcutIconRemotePath”=dword:00000001`

in the registry key `[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Explorer]`

 

STEPS:

1. Create the Desktop.ini file with the following content:

NOTE: Adjust the domain name to your use case; the domain does not have to exist.

You can encode information in the domain name such as an ID for the honey folder and client information using environment variables.

 

2. Give the folder and the Desktop.ini file the system attribute:

You might also want to make the Desktop.ini file hidden. In this case you would use the following command:

After completing these steps, every time someone opens the folder that contains the honey folder, a DNS request will be made.

To have the DNS request logged, you should include the following in your Sysmon configuration under Event ID 22.

After ingesting the Sysmon logs into your SIEM you have a high-fidelity detection mechanism, if implemented correctly, with almost zero false positives.

 

 

 

 

 

 

 

 

 

 

 

 

 

Employees 85% more likely to leak files today vs pre-COVID

Employees 85% more likely to leak files today vs pre-COVID

Employees are 85 percent more likely today to leak files than they were before the COVID-19 pandemic, according to research released Thursday by Code42. Joe Payne, Code42’s president and CEO, said the vast majority of that 85 percent are malicious insiders and the rest are caused by employee carelessness.

This Bluetooth Attack Can Steal a Tesla Model X in Minutes

This Bluetooth Attack Can Steal a Tesla Model X in Minutes

Tesla has always prided itself on its so-called over-the-air updates, pushing out new code automatically to fix bugs and add features. But one security researcher has shown how vulnerabilities in the Tesla Model X’s keyless entry system allow a different sort of update: A hacker could rewrite the firmware of a key fob via Bluetooth connection, lift an unlock code from the fob, and use it to steal a Model X in just a matter of minutes.

Pin It on Pinterest