ioc.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
INDICATORS OF COMPROMISE (IOC) InfoSec Community within the Fediverse. Newbies, experts, gurus - Everyone is Welcome! Instance is supposed to be fast and secure.

Administered by:

Server stats:

1.6K
active users

#get

1 post1 participant0 posts today

10 Democrats voted with Republicans to censure Al Green:

Ami Bera of California
Ed Case of Hawaii
Jim Costa of California
Laura Gillen of New York
Jim Himes of Connecticut
Chrissy Houlahan of Pennsylvania
Marcy Kaptur of Ohio
Jared Moskowitz of Florida
Marie Gluesenkamp Perez of Washington
Tom Suozzi of New York

Bellends.

#USPol#AlGreen#Wanker

Der Streit um die potenziell schädliche Graded-Exercise-Therapie #GET bei #MECFS ist zurück - z.T. mit den Protagonisten der Vergangenheit: Die #PACE-Trial-Macher beeinflussten die @cochranecollab, die dramatisch an ihren hohen Transparenz- u. Qualitätsansprüchen scheitert: Sie etikettiert einen veralteten Pro-GET-Review als aktuell um. Wie kam es dazu? Die Hintergründe @riffreporter riffreporter.de/de/wissen/mecf

RiffReporter · ME/CFS: Neuer Streit um potenziell schädliche Aktivierungstherapie erschüttert Cochrane-NetzwerkBy Martin Rücker

They’re going to waste and destroy the lives of people with long covid by pretending that the stuff that never worked for #MECFS is the cure for #longCovid.

This way they can deny y’all disability benefits by saying if you just go to #CBT you will be cured. I mean, go to CBT therapy if you think it might help you, but it’s not going to heal your body.

I wasn’t interested in using CBT to gaslight myself into thinking I could get better when I couldn’t or that everything was fine when it wasn’t.

Fair warning, this is all y’all are gonna get for a couple decades. CBT and graded exercise therapy (#GET ) Are you sure you want to destroy your health for your boss or for brunch??

jamanetwork.com/journals/jama/

#JAMA#study#scams
Replied in thread

@Beggarmidas @Lizette603_23

I'm not one for conspiracy theories, but even I sense something doesn't quite add up.

There were too many #TechBros on team #Trump with too much to lose by publicly backing him, but they CONFIDENTLY did anyway.

Trump: #Get out and vote, just this time. You won’t have to do it any more. Four more years, you know what? It’ll be fixed, it’ll be fine, you won’t have to vote any more, my beautiful Christians.”

Something stinks! PM sent... 🙏🏾

Continued thread

Managed to create a #powershell script to disable the self-service purchases too speed it up a bit.

# This script disables self-service purchase for all Microsoft products.
# Requires Global Admin permissions to set the correct values.

try{
Get-InstalledModule MSCommerce
}catch{
Install-Module MSCommerce
}
Import-Module MSCommerce
Connect-MSCommerce

#Get all of the products that is available for self-service purchase.
$products = Get-MSCommerceProductPolicies -PolicyId AllowSelfServicePurchase

foreach ($product in $products)
{
write-Host "Disable self-service purchase on: "-NoNewline
Write-Host $product.ProductName -ForegroundColor Red -NoNewline
Update-MSCommerceProductPolicy -PolicyId AllowSelfServicePurchase -ProductId $product.ProductID -Value "Disabled"
write-host "[DONE]" -ForegroundColor Green
}

# Finds the Copilot SKU and disables self service
# Uncomment the two lines below and comment out the foreach loop if you only want to disable self-service for Copilot
#$product = Get-MSCommerceProductPolicies -PolicyId AllowSelfServicePurchase | Where-Object {$_.productname -eq "Microsoft 365 Copilot"}
#Update-MSCommerceProductPolicy -PolicyId AllowSelfServicePurchase -Value "Disabled" -ProductId $product.productID

Continued thread

Once the registry key was modified and the payload linked to in the registry data, persistence was successfully gained, which enabled the adversaries repeated access to the victim. This is a great article and just the tip of the iceberg when it comes to technical details, so check it out for yourself! Enjoy and Happy Hunting!

The Updated APT Playbook: Tales from the Kimsuky threat actor group
rapid7.com/blog/post/2024/03/2

I know I share this Cyborg Security Community hunt package a lot, but it's because this behavior is extremely commonly used! It is just one of many behaviors that we help you hunt for that stand the test of time!

Autorun or ASEP Registry Key Modification
hunter.cyborgsecurity.io/resea

hunting

Rapid7 · The Updated APT Playbook: Tales from the Kimsuky threat actor group | Rapid7 BlogWithin Rapid7 Labs we continually track and monitor threat groups. As part of this process, we routinely identify evolving tactics from threat groups in what is an unceasing game of cat and mouse.