Out walking the dog and had a mild heart attack with this @ThinkstCanary alert popup on my phone.
"ipconfig ran on Glenn's desktop"
Seems M$ uploaded the token and analysed it (I created it about four hours ago).
"ipconfig ran on Glenn's desktop"
Seems M$ uploaded the token and analysed it (I created it about four hours ago).
Makes me think of this slide from one of @haroonmeer 's talks.
Basically, you can detect when folks are RE'ing your stuff by hiding various levels of Tokens. e.g one Token that `strings` would find, a deeper one inside a loop that would need to be unpacked, another xor'd one.
Basically, you can detect when folks are RE'ing your stuff by hiding various levels of Tokens. e.g one Token that `strings` would find, a deeper one inside a loop that would need to be unpacked, another xor'd one.
And by 'token' here I guess mostly DNS tokens that call home when resolved - best used with a custom Canary token domain.
…http://23b4222d2613a2765d4d432d2d65e88e.topsecret.glenn.com
(did you know you can use custom domains? I learned that this week)
…http://23b4222d2613a2765d4d432d2d65e88e.topsecret.glenn.com
(did you know you can use custom domains? I learned that this week)