Year: 2017

Fileless Attacks are on the Rise

London, UK ā€“ June 23, 2017 ā€“ This year, the number of sophisticated attacks that use fileless malware increased by 33%. Such attacks become more popular among cybercriminals due to the fact that they easily bypass antivirus systems and application whitelisting, and it is harder to investigate them by usual methods. One of the latest […]

Read More
QakBot Trojan Detector for ArcSight is released

London, UK ā€“ June 20, 2017 ā€“ Our team created a threat-centric turn-key SIEM use case for QakBot / Pinkslipbot Trojan detection. It is one of SOC Primeā€™s free use cases targeted at immediately uncovering the most recent threats, such as Industroyer, EternalRocks or WannaCry. You can download QakBot Trojan Detector after logging or registering […]

Read More
New QakBot Modification

London, UK ā€“ June 15, 2017 ā€“ A wave of Active Directory (AD) lockouts due to malware activity occurred in June. Researchers from IBM X-Force determined during the investigation that the culprit is the famous banking trojan QakBot (aka PinkSlip). Due to actions of this malware, hundreds of thousands of Active Directory users were suddenly […]

Read More
SIEM Use case for Industroyer detection

London, UK ā€“ June 13, 2017 ā€“ Researchers at ESET have discovered and analyzed samples of malware Win32 / Industroyer. Industroyer seems to be designed to attacks power grids. It is very dangerous, because this malware is able to control circuit breakers directly via industrial communication protocols used throughout the world in critical infrastructures (such […]

Read More
Ransomware Now

London, UK ā€“ June 9, 2017 ā€“ Infosecurity Europe 2017, the largest event in the Eastern Hemisphere, finished yesterday. This year it was the 21st exhibition. A lot of excellent solutions were demonstrated there; and well-known IS experts presented plenty of reports. It was great to spend three days in a good company among thousands […]

Read More
SOC Prime at Infosecurity Europe 2017

London, UK ā€“ June 6, 2017 ā€“ SOC Prime, Inc. is participating in Infosecurity Europe 2017! Andrii Bezverkhyi and Ruslan Mikhalev are waiting for you at Satisnet’s stand and they are ready to communicate with you and show the most current versions of our products.

Read More
Visit us at the Satisnet booth (D245) at Infosecurity Europe on 06-08 June 2017!

London, UK – May 30, 2017 – SOC Prime, Inc. reports that you can find us and our partner, Satisnet, at Infosecurity Europe at booth D245. Visit us and talk with our ArcSight and QRadar experts to learn how to increase the efficiency of your SOC. Ask any questions and get acquainted with our products. […]

Read More
EternalRocks Worm Detector SIEM Use Case

London, UK ā€“ May 25, 2017 ā€“ SOC Prime, Inc. reports on public availability of SIEM use cases for EternalRocks detection. Based on the information gathered by Miroslav Stampar, expert of the Croatian Government CERT, we created EternalRocks Worm Detector for HPE ArcSight, IBM QRadar and Splunk. EternalRocks is the more sophisticated successor to the […]

Read More
WannaCry no more: ransomware worm IOC’s, Tor C2 and technical analysis + SIEM rules

Good news everyone! After a rather long day, night and morning of studying the news, researching and hunting the #WannaCryĀ ransomwarewormĀ there are some discoveries to be shared.. This includesĀ HostĀ andĀ NetworkĀ IOCs, their analysis obtained with help of fellowĀ security researchersĀ and practitioners, review of C2 infrastructure and its interactions with Tor. Last but not least are some freeĀ SIEM use casesĀ that […]

Read More
Predictive Maintenance 3.4.1 is released!

London, UK ā€“ May 11, 2017 ā€“ SOC Prime, Inc. announces a release of the new version of Predictive Maintenance (https://socprime.com/en/predictive-maintenance/) platform for HPE ArcSight. We are constantly working on making our platform as functional as possible and providing information security experts with all the necessary tools. In Predictive Maintenance 3.4.1, we have added the […]

Read More