Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

2388 total results found

Memory Modification

Cyber Crucible Training Info

What is memory modification? Memory modification, as Cyber Crucible use the term, is when the executable sections of a process' memory have been modified in abnormal ways. The normal execution of a given process, without outside tampering, does not trigger...

Microsoft SSO Integration With Cyber Crucible Dashboard

Administration

Clients can integrate their Microsoft Entra ID (Azure AD) SSO with the Cyber Crucible dashboard by following these steps below:Client updates in the Entra ID SAML configFirst, go to Enterprise applications and click the desired appIf you d...

Mitre Techniques Covered

Cyber Crucible Training Info

Mitre TechniquesSummaryTraining ScenariosT1037Malware may instruct Windows to execute malicious scripts on boot or when a user logs in.T1055Process injection, usually used to run malicious code in a target process while allowing the origin...

Partner Deal Registration

Partner Operations

How to Register a Deal Deal Length and Billing Cycle Options How to Know when a Deal is Approved How to Request a Quote for an Existing Deal How to Pay for a Deal How to Download a Signed Quote How to Edit a Deal How to Disable a Deal Ho...

Process Injection

Cyber Crucible Training Info

What are process injections?Process injections are when a (potentially malicious) process A forces process B to execute instructions that are not otherwise a part of its code. Process injection has many different techniques, the most commo...

Removing Users from a Group

Administration

Removing users from a group is easy.First, go to the Groups page found under the Administration tab in the sidebar.Then click the Manage Group icon on the group you want to remove the user from.Clicking the icon will popup the Manage Group...

Role Management

Administration

Creating a Role Assigning Roles to Users Deleting a Role from a Group Editing a Role’s Permissions By default, there are three built-in roles:Guest has no permissions.Read Only grants read only permissions to tailored behaviors, silent ...

Sales Email Notifications

Partner Operations

Introduction How to Create a Sales Notification How to Delete a Sales Notification How to Turn a Sales Notification Off Without Deleting IntroductionSales Notifications are alerts emailed out to users relating to sales activities, and t...

Script to Release Licenses for Machines Using a CSV File

Deployment & Agent Management

Script Arguments Download the Script How to Run the Script How to find Your Refresh Token Cyber Crucible has created a Powershell Script that can take in a CSV file path containing Net bios machine names to automatically release license...

Training License Management

Cyber Crucible Training Info

How to Purchase Training Licenses How to Assign Training Licenses to Users How to Release Training Licenses from Users How to Turn Training Mode On/Off How do I Reset My Training Data How to Purchase Training LicensesUsers can navigate ...

What Happens When CC Finds Memory Attacks

Architecture & Technology

First, it is very important to note that memory alterations happen for a couple different reasons:In-memory attacksInteraction between programsSoftware bugsExploitsSo, a process injection or memory altering technique used, even between pro...

4.4.0.9

Software Releases Endpoint Agent

FeaturesFor telementry-enabled groups, added Active Directory data to credential theft watch listFixesRemove duplicate local volumes and network share entries in some environments.Refined behavior for some thumbnail database rebuilds causing incidentsFixed lic...

4.4.0.9.1

Software Releases Endpoint Agent

FeaturesNone - maintenance update.FixesFixed some network shares connected by a user being initially ignored in analytics.Refined false positive behavior associated with shares appearing during user sessions, followed quickly by a Save As dialog box.WHCP/WHQL ...

4.4.1.0

Software Releases Endpoint Agent

FeaturesExpanded support for processes injection analytics, to dramatically increase the accuracy of detecting malicious vs benign intent for applications. This became especially important due to a small number (<0.02%) of machines in Cyber Crucible telemetry...

4.4.1.1

Software Releases Endpoint Agent

FeaturesImproved analytical processing for parent-child relationships, when the parent process quickly dies before Cyber Crucible completes processing (milliseconds).The extremely common scenario here is that attackers (and legitimate programs) will often open...

4.4.1.2

Software Releases Endpoint Agent

FeaturesIncreased available specificity for whitelists, such as parent process path and arguments.Expanded support for identity access analytics to more credential databases.Identity access is now also monitored for Slack, Opera, Thunderbird, Discord, and Viva...

4.4.1.3

Software Releases Endpoint Agent

FeaturesCredential/Identity Monitoring now includes various VPN, cryptocurrency wallet, and other applications.In a (this is common) chain of affected processes during an attack (attacker moves from running program A, to B, to C, and D is used for data theft),...

Training Scenario - DLL Injection

Cyber Crucible Training Info Scenarios

Group NameTraining Data - Dll Injection (Hive)ScenarioIn this training scenario, we will execute an encrypted ransomware payload via DLL injection into a signed MS Defender. A custom DLL has been created, as an attacker would create it, which decrypts a fake ....