HowTo

Analyzing an active vishing campaign using a Teams and email-bombing combination

I should be driving to Vegas but instead I am sitting here fucking around with some asshole’s C2 infrastructure.

An e-mail bomb was launched against LA County users together with a coordinated vishing attempt via Teams. The intent was to execute the malware package described here.

Exhaustive report below including the IOCs. Reach out if you want access to the full malware and investigation package but since this is currently active you should be able to fully reproduce everything based on the report below.

Setting up a tiny honeypot on a tiny Oracle Always Free VM

What better way to spend a lovely Saturday afternoon than building a honeypot.

HOWTO: Teach users to correctly pick a Sensitivity Label

Teaching users how to correctly choose a sensitivity label is one of the most critical parts of any Microsoft Purview implementation.

The labels themselves may be technically configured correctly, but the deployment will still fail if users do not understand how to apply them. First impressions matter. The process needs to feel simple, predictable, and easy to explain, even when the underlying classification model is not always intuitive.

I have always used what I call the Sensitivity/Audience Rule.

HOWTO: Use WinSCP to move files to and from your cloud VM

Could you have googled this or asked Claude? Yes. But you didn’t and they don’t have nice screenshots.