❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayBlack Hills Information Security

Swapper – A Pure Regex Match/Replace Burp Extension

By: BHIS
6 May 2026 at 10:00

To get a valid session token to use with Burp Suite tools, I ended up writing a small Python extension (110 lines of code, but who’s counting?) that obtained a new session token for each request, allowing items like Intruder to work as intended. Cool, I was able to use it during the test, but I would like this to be repeatable. So, this blog is releasing Swapper, a regex pattern-based match/replace Burp Suite extension.

The post Swapper – A Pure Regex Match/Replace Burp Extension appeared first on Black Hills Information Security, Inc..

Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2)

By: BHIS
1 October 2025 at 10:00

But what if we need to wrangle Windows Event Logs for more than one system? In part 2, we’ll wrangle EVTX logs at scale by incorporating Hayabusa and SOF-ELK into my rapid endpoint investigation workflow (β€œREIW”)!Β 

The post Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2) appeared first on Black Hills Information Security, Inc..

Wrangling Windows Event Logs with Hayabusa & SOF-ELKΒ (Part 1)

By: BHIS
17 September 2025 at 10:09

In part 1 of this post, we’ll discuss how Hayabusa and β€œSecurity Operations and Forensics ELK” (SOF-ELK) can help us wrangle EVTX files (Windows Event Log files) for maximum effect during a Windows endpoint investigation!

The post Wrangling Windows Event Logs with Hayabusa & SOF-ELKΒ (Part 1) appeared first on Black Hills Information Security, Inc..

Stop Spoofing Yourself! Disabling M365 Direct Send

By: BHIS
20 August 2025 at 10:00

Remember the good β€˜ol days of Zip drives, Winamp, the advent of β€œOffice 365,” and copy machines that didn’t understand email authentication? Okay, maybe they weren’t so good! For a […]

The post Stop Spoofing Yourself! Disabling M365 Direct Send appeared first on Black Hills Information Security, Inc..

GRC for Security Managers: From Checklists to Influence

By: BHIS
27 January 2025 at 11:00

This webcast was originally aired on January 16, 2025. In this video, Kelli K. Tarala and CJ Cox discuss the challenges and strategies for improving governance, risk, and compliance (GRC) […]

The post GRC for Security Managers: From Checklists to Influence appeared first on Black Hills Information Security, Inc..

Auditd Field Spoofing: Now You Auditd Me, Now You Auditdon’t

By: BHIS
11 May 2023 at 10:30

moth // IntroductionΒ  One fateful night in June of 2022, Ethan sent a message to the crew: β€œAnyone know ways to foolΒ AuditdΒ on Linux?Β I’mΒ trying to figure out how to change theΒ auidΒ (audit […]

The post Auditd Field Spoofing: Now You Auditd Me, Now You Auditdon’t appeared first on Black Hills Information Security, Inc..

Linux System Call MonitoringΒ 

13 September 2022 at 12:37

moth // I’ve been diving deep into Linux lately, with my latest kick being exploring the Linux kernel. I’ve found β€œThe Linux Programming Interface” (TLPI) by Michael Kerrisk, among others, […]

The post Linux System Call MonitoringΒ  appeared first on Black Hills Information Security, Inc..

Webcast: What to Expect When You’re Expecting a Penetration Test

By: BHIS
21 August 2020 at 10:17

CJ and Bryan will share the knowledge they’ve accumulated, by helping 1,000’s of organizations determine what they need and don’t need when it comes to penetration tests and security assessments, […]

The post Webcast: What to Expect When You’re Expecting a Penetration Test appeared first on Black Hills Information Security, Inc..

πŸ’Ύ

Webcast: Linux Forensics Magical Mystery Tour With Hal Pomeranz

By: BHIS
17 June 2020 at 08:16

One of our favorite BHIS guest presenters, Hal Pomeranz, returns for more of the Linux goodness. Roll up for a magical tour through the mysteries of Linux file systems! Relative […]

The post Webcast: Linux Forensics Magical Mystery Tour With Hal Pomeranz appeared first on Black Hills Information Security, Inc..

Webcast: Linux Command Line Dojo with Hal Pomeranz

By: BHIS
17 February 2020 at 08:05

In this webcast, we have our friend Hal Pomeranz sharing his massive knowledge on Linux. If you’re new to Linux, or if you know it and just want to hear […]

The post Webcast: Linux Command Line Dojo with Hal Pomeranz appeared first on Black Hills Information Security, Inc..

πŸ’Ύ

Fixing EyeWitness Install Errors on Kali Linux

By: BHIS
24 September 2019 at 11:04

Darin Roberts // I recently had to install a new gold image as my Kali Linux testing virtual machine.Β  Almost on every test I do, I clone the gold image […]

The post Fixing EyeWitness Install Errors on Kali Linux appeared first on Black Hills Information Security, Inc..

Pentesting Dropbox on Steroids

By: BHIS
20 November 2018 at 10:34

Joff Thyer// Many of you have probably already looked at Beau Bullock’s fine blog entry on a penetration testing dropbox. Beau has some excellent guidance on how to build the […]

The post Pentesting Dropbox on Steroids appeared first on Black Hills Information Security, Inc..

WEBCAST: GDPR – Spring Storm Warning

By: BHIS
30 April 2018 at 11:05

CJ Cox// Spring storms are often more dangerous and unpredictable than winter storms. The GDPR looks to be no exception. The General Data Protection Regulation is a universal law brought […]

The post WEBCAST: GDPR – Spring Storm Warning appeared first on Black Hills Information Security, Inc..

Deploy REMnux to the Cloud, Reverse Engineering Malware in the Cloud

By: BHIS
1 February 2018 at 10:48

Carrie Roberts //* REMnuxΒ is a free virtual machine image with Reverse Engineering Malware tools preinstalled.Β REMnux is maintained byΒ Lenny ZeltserΒ with extensive help fromΒ David Westcott and is available from https://remnux.org. I have […]

The post Deploy REMnux to the Cloud, Reverse Engineering Malware in the Cloud appeared first on Black Hills Information Security, Inc..

❌
❌