Tech, tools, thoughts from the team at Lab539

Lab539::Blog

John Fitzpatrick John Fitzpatrick

Self Hosted Conditional Access Service

Creating a self hosted Azure Logic App to periodically query the Lab539 AiTM API and update a named location - allowing you to have real time updated conditional access policies.

Read More
John Fitzpatrick John Fitzpatrick

A Summary of 6 Months Tracking AiTM Campaigns

This post is a summary of 6 months tracking AiTM campaigns using a rather clever technique we have devised that allows us to identify the backend infrastructure before it is used.

Read More
John Fitzpatrick John Fitzpatrick

The Cyber Defenders Kill Chain (TCDO Part2)

The cyber defenders kill chain emphasises the different stages of an attack in a manner relevant to defenders. It’s central to how we, at Lab539, craft effective tailored cyber defences that protect critical functions.

Read More
John Fitzpatrick John Fitzpatrick

Applying Context, Controlling Adversaries (TCDO Part 1)

Adversarial tradecraft is not rigid, it can and does evolve. Spending more time studying adversaries is not unhelpful but we much prefer to keep things on our own terms, to control how adversaries must operate, and the tradecraft they must use. This is the first of a series of posts on our thinking and how we look at things a little differently in order to achieve that elusive feeling of confidence in our defences.

Read More
John Fitzpatrick John Fitzpatrick

Inside Akira Ransomware Negotiations

Lab539 delved into the negotiations which the Akira ransomware group conduct with their victims in order to provide and share some insights.

Read More