Blog
Findings, advisories and field notes from Threatbear engagements.
Solving real security problems using cross-project search
If you work in complex environment, the challenges facing security operations teams are probably not simple either. Asides from the finesse required to have good governance and good opsec at the same time, the features provided by our security stack don’t always match the regulatory and compliance constraints imposed upon security teams. Ultimately the fewer silos the security team has to work across, the better. Fewer silos provide a more holistic view of the threat landscape and lower cognitive demand on the analyst.
Read moreElastic workflow for Easy Intel
Here is an Elastic workflow that can be used to seamlessly ingest threat intelligence from our easy intel product into Elastic SIEM. If you haven’t heard of Elastic workflows yet, you should certainly check it out, it provides a way to automate common security tasks using simple primitives, right within Elastic SIEM. If you’re on Elastic 9.4+, you should be able to copypasta this into a workflow (keep in mind there will be data ingest costs if you are on serverless - you use this workflow and easy intel at your own risk).
Read moreIntroducing Easy Intel
Threat Intelligence has, for a long time, only been within reach of very large organisations or security teams. Often there is a lot of waving hands and huge dollar values thrown around when talking about threat intelligence. Six month timelines for deploying some technology that is inaccessible to the seething masses or 老百姓 (Mandarin for masses). If you like LOVE the practise of Cybersecurity, you might posess a burning curiosity for details about your cyber-adversaries. You’re not content for someone else to tell you what is a threat and what isn’t. You’re curious - what if we just pay attention to information we already have, like phishing attacks and other low hanging fruit, and extract value from that?
Read moreUsing Elastic Observability as a status page app
Elastic synthetics is an observability solution that we use to measure all kinds of things that we do here at Threatbear. Specifically we use it to monitor whether a service that we provide is available, and it lets us know if it isn’t available (or down in geekspeak). If a system is available, by using Elastic observability, we can know how long a service has been available for as well as the qualitative aspects of the service we provide. For example we can get answers to questions such as “what is the 95th percentile of our latency in milliseconds” or “when does our staging certificate expire”.
Read moreUncomplicated naming convention
Naming conventions are often overcomplicated. They assume you have ten thousand sites and a hundred thousand endpoints per site. Unfortunately this additional complexity means you will probably avoid a naming convention, after all, who needs the extra hassle when there are new new critical vulnerabilities to patch every week! Enter the uncomplicated naming convention - a naming convention for the 90% that strips away the complexities and does one thing well - it answers four questions :
Read moreDetecting copyfail (CVE-2026-31431) exploitation using eBPF
For years, Linux security and observability have relied on a patchwork of tools. We scraped user-space logs, parsed Auditd events, and heavily monitored network traffic. But as adversaries have grown more sophisticated, moving deeper into the system to exploit kernel-level vulnerabilities, traditional monitoring has started to show its age. It’s often too noisy, too slow, or simply blind to exactly what is happening in the dark corners of the operating system.
Read moreHow to enable the Elastic Defend system extension in macOS Sequoia
If you’re trying to install Elastic Defend on macOS Sequoia, the system extension management screen in system preferences has been moved. Previously, as documented inElastic Defend Mac Troubleshootingit was in System Preferences under the “Privacy & Security” tab. In macOS Sequoia, they are now under the General tab. Step 1 - finding the extensions page If you’re on Sequoia, it is now under System Preferences under : General > Login Items & Extensions
Read moreAg-tech Cybersecurity Partner for Darling Downs
Threatbear is a cyber security services provider based in Dalby in the Darling Downs and can provide the following services : Cyber security awareness training Scam email reduction / Email security (80% of attacks start with a scam email - this is no exception in Toowoomba and the Darling Downs) CCTV, License plate recognition and surveillance technology. We can do Ai based object detection. Ag-tech security and security reviews for your smart farm technology (Zimmatic / FieldNet / Lindsay corporation / Lorawan)
Read moreNetwork defence using RouterOS (Part 1)
When looking for threats sometimes you know exactly what you’re looking for. Sometimes — actually often — you only have a general direction in which you wish to conduct your hunt. RouterOS has an operator for a fuzzy search ~ and an operator for an exact match = . This is extremely useful for those situations in which you only have a single clue to go on! If you’re anything like me, once you have a single “high signal” indicator, this then is all the motivation you need to continue the search no matter how arduous.
Read moreIs RouterOS vulnerable to CVE-2023-48795 ?
Is RouterOS vulnerable to CVE-2023–48795 ? Update (20/12/2023) : Terrapin scanner no longer crashes and correctly identifies RouterOS as not being vulnerable to the Terrapin attack — thanks to @TrueSkrillor It was recently discovered that the SSH protocol has a weakness that enables an attacker with the ability to perform a man in the middle to affect the negotiation of protocol security features without the client or server noticing.
Read more