Sign in

Toby Lewis

@tobaslouis.co.uk
630 followers 1K following 72 posts

Global Head of Threat Analysis at @Darktrace.com All things Cyber Security Ops, Threat Hunting, Threat Intel and Incident Mgmt.

PostsRepliesMedia
Toby Lewis @tobaslouis.co.uk · 30/12/2025
Two birds. One proverbial stone.
010
Toby Lewis @tobaslouis.co.uk · 30/12/2025
I find the need to use up the festive leftovers, means double cream as a substitute for milk at every opportunity. Some very indulgent cornflakes this morning…
110
Toby Lewis @tobaslouis.co.uk · 28/12/2025
If I did one of those Ancestry DNA tests right now, a significantly high proportion would come back as Stilton Cheese
020
Toby Lewis @tobaslouis.co.uk · 01/05/2025
However, we can see two other likely scenarios: Either a common supplier or technology used by all three retailers has been breached; or the scale of the M&S incident has prompted security teams to relook at their logs and act on activity they wouldn’t have previously judged a risk. 2/2
030
Toby Lewis @tobaslouis.co.uk · 01/05/2025
Details of the cyber attack at Harrods (as they are with Co-op & M&S) are still low and we shouldn’t rule out that the three incidents impacting the retailers are simply coincidence. .... 1/2
news.sky.com
Luxury store Harrods is latest retail victim of cyber attackers
Harrods has "restricted internet access" after an attempt to gain access to its systems left some customers struggling to pay for purchases, Sky News can reveal.
151
Toby Lewis @tobaslouis.co.uk · 07/04/2025
Why is @microsoft.com "Teams" plural, when "Word" is not? Surely a singular Team feels more homely... maybe. Conversely, a singular "Word", feels like about as much effort as I put in my school coursework.
010
Toby Lewis @tobaslouis.co.uk · 01/04/2025
Do phishing simulations on April Fools' Day still count? 🤷‍♂️
030
Toby Lewis @tobaslouis.co.uk · 03/03/2025
Cooking top tip: quarter-pounders are not the same size as quarter-kilo’ers #ImadeBigBurgers
010
Toby Lewis @tobaslouis.co.uk · 29/01/2025
New blog post from @darktrace.com, looking at the detection of an Insider Threat in a SaaS application, with the customer supported by our amazing Analyst SOC
darktrace.com
Bytesize Security: Insider Threats in Google Workspace | Darktrace Blog
Insider threats pose significant risks due to access to internal systems. Darktrace detected a former employee attempting to steal data from the customer’s Google Workspace platform. Learn about this ...
020
Toby Lewis @tobaslouis.co.uk · 20/01/2025
In my first Executive Order, I will be renaming France as "Cheese-land" #GulfOfMexico
020
Toby Lewis @tobaslouis.co.uk · 16/01/2025
A cautionary tale: not everything suspicious is malicious. (although, I'd argue everything malicious was indeed suspicious at one point)
notalwaysright.com
So, Is Someone Getting Fired, Or…?
Two weeks before Christmas, exactly that happened. It was pandemonium in security. Someone apparently tried really hard to break into our high-sec company by sending out a "gift certificate" to every ...
110
Toby Lewis @tobaslouis.co.uk · 10/01/2025
A new blog post from analysts at @darktrace.com: The use of phishing kits as part of an AitM attack, increasing an attackers ability and proficiency in stealing legitimate credentials. ... and then simply just logging on.
darktrace.com
Detecting and mitigating adversary-in-the-middle phishing attacks with Darktrace Services | Darktrace Blog
Threat actors often use advanced phishing toolkits and Adversary-in-the-Middle (AitM) attacks in Business Email Compromise (BEC) campaigns, Discover how Darktrace detected and mitigated a sophisticate...
030
Toby Lewis @tobaslouis.co.uk · 07/01/2025
The outcome in your case is manipulated data. Cyber might provide a means, but so could send an official letter on letterheaded paper asking them to “correct a record”. Or does it still count as cyber if I used a computer to write the letter? 😉
000
Toby Lewis @tobaslouis.co.uk · 07/01/2025
Absolutely. The outcome in your case is stealing sensitive data. You can do that by paying a guy to walk out with it in a briefcase.
100
Toby Lewis @tobaslouis.co.uk · 07/01/2025
Ok Brain Trust: Prove me wrong. There is no application of cyber attack, where the intended outcome can't be achieved by non-cyber means.
300
Toby Lewis @tobaslouis.co.uk · 05/01/2025
A dog walk on the beach
030
Toby Lewis @tobaslouis.co.uk · 02/01/2025
One of my 2025 resolutions is to write more, including reinvigorating my cyber security focussed blog, which took a bit of a hiatus in the latter half of 2024. I've got a few ideas lined up already, but what would you like to see me write about?
tobylewis.substack.com
Common Sense Security | Toby Lewis | Substack
Removing the FUD from Cyber Security. Click to read Common Sense Security, by Toby Lewis, a Substack publication. Launched 2 years ago.
000
Toby Lewis @tobaslouis.co.uk · 31/12/2024
In the end, nothing too revealing, but a nice exercise in understanding some of the behind the scenes of how these analysis tools work, and how you *could* get caught out. Fin.
010
Toby Lewis @tobaslouis.co.uk · 31/12/2024
By default, and unless you have a premium subscription, Graphs made in VirusTotal are public and form part of their community engagement. Want to know if anybody is researching an IOC? Want to know what other steps they've made in the investigation? VirusTotal public graphs will tell you.
Screenshot of VirusTotal Graphs
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
There's a feature in VirusTotal called "Graphs". It's a way of visualising your investigation in a graph format, with your IOCs as nodes. Much like the classic Always Sunny in Philadelphia / Pepe Silvia meme:
media.tenor.com
a man standing in front of a bulletin board that says " pepe silvia "
Alt: Always Sunny in Philadelphia/Pepe Silvia Meme
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
But wait, there's more (again)
media.tenor.com
a man standing in front of a shelf of oxi clean
Alt: But wait, there's more meme
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
Some of that research doesn't seem to have survived the passing of time (it was 10 years ago!), but the principles of his work survive in this Google Doc:
docs.google.com
VT Research
Purpose Research Foundation VT-MIS and Private API Metadata Results Structure Collection Process Derived Hash Values and Account Types Identifying Interesting Activity Actor Account Characteristics Up...
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
The submitter hash itself is not queryable in VirusTotal, but I remember some research by @9bplus.bsky.social back in 2014, that showed it was possible to track what files a specific submitter had uploaded, and with it, track threat actors testing their malware.
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
I've come across this before, with an organisation I was working with, who had integrated a mail scanning appliance with VirusTotal, which meant it was automatically uploading EVERY email attachment to VirusTotal for analysis. Probably not a great approach in hindsight.
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
We can also use VirusTotal to tell us how many times this file has been uploaded, and a little bit of information about them. In this case, by a single user based in the US (by IP-GEO) and uploaded via API. This means that it either formed part of a script, or via an integration with another tool.
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
But wait, there's more...
media.tenor.com
a man standing in front of a shelf of oxi clean
Alt: But wait, there's more meme gif
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
What else was in that "sharedStrings.xml" file - VirusTotal gives you the ability to view the contents of files. In this case, the only unique strings in the parent XLSX files are the IOCs we already know about. Maybe not the most exciting in this case, but worth a check!
XML blob of text showing all of the unique strings
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
In other words, somebody uploaded an XLSX of IOCs to VirusTotal, which then broke apart the constituent components as separate files. Then, realising that they made a mistake, requested that VirusTotal take down the original XLSX file. Unfortunately, that still left behind the constituent files
Screenshot from VirusTotal showing the process for requesting file deletion
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
So what Excel file was this "sharedStrings.xml" file originally part of? VirusTotal's "Compressed Parents" field reveals a SHA256 hash of a file.... which doesn't exist on VirusTotal. Or at least, it doesn't any more.
Screenshot from VirusTotal showing the hash of the compressed parentSearch results in VirusTotal showing zero results
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
A modern day Excel file (xlsx), is actually just a compressed file (zip), containing lots of individual components, such as fonts, graphics and other rich text content. This blog is a good breakdown if you're interested in diving in more: henrikmassow.medium.com/hacking-exce...
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
But what is sharedStrings.xml? Or more specifically "xl/sharedStrings.xml"?
Screenshot from VirusTotal showing the full filename of sharedStrings.xml
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
Interesting OpSec aspect with regards to the BeyondTrust compromise. (H/T to @GossiTheDog.cyberplace.social.ap.brid.gy for first spotting this) Having a search for some of the IOCs from the BeyondTrust blog, reveals that they appear in a file uploaded to VirusTotal on the 19th December
Screenshot from VirusTotal showing file uploaded on 19th December
120
Toby Lewis @tobaslouis.co.uk · 31/12/2024
6) A couple of questions for me still remain: - who were the other affected customers? Are they other US Federal orgs as US Treasury? - how was the API key compromised? Was BeyondTrust’s IT estate itself more broadly compromised, or was it obtained directly through the exploits already disclosed
010
Toby Lewis @tobaslouis.co.uk · 31/12/2024
5) BeyondTrust have shared the following IOCs, presumably IP addresses used by attackers to access BeyondTrusts infrastructure and to pivot into customers: 24.144.114[.]85 142.93.119[.]175 157.230.183[.]1 192.81.209[.]168 As well as some additional IPv6 addresses:
Screenshot of IOCs from BeyondTrust
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
4) During their investigation, BeyondTrust identified and disclosed at least one vulnerability that has confirmed exploited in the wild: CVE-2024-12356 It is unclear how this was used in the wider breach, when they also reference a compromised API key elsewhere. www.beyondtrust.com/remote-suppo...
beyondtrust.com
BeyondTrust Remote Support SaaS Service Security… | BeyondTrust
BeyondTrust’s Privileged Access Management platform protects your organization from unwanted remote access, stolen credentials, and misused privileges
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
3) The potential timeline from BeyondTrusts investigation above states that their first inkling that something was up, was when anomalous behaviour was spotted on one customer’s deployment on 2nd December. A limited number of other “customer instances” were confirmed by 5th December.
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
2) BeyondTrust have been openly disclosing their internal investigation, which discovered the compromise of an API key used for their Remote Support SaaS solution. They then notified “impacted customers”, of which, US Treasury is just one. www.beyondtrust.com/remote-suppo...
beyondtrust.com
BeyondTrust Remote Support SaaS Service Security… | BeyondTrust
BeyondTrust’s Privileged Access Management platform protects your organization from unwanted remote access, stolen credentials, and misused privileges
100
Toby Lewis @tobaslouis.co.uk · 31/12/2024
More information on the breach: 1) In a letter to US Senators, it is revealed that attackers were able to gain access to a service at BeyondTrust that gave them remote access to US Treasury workstations. legacy.www.documentcloud.org/documents/25...
Screenshot of letter to US Senators detailing some of the facts of the breach
110
Toby Lewis @tobaslouis.co.uk · 30/12/2024
US Treasury announce network breach by “Chinese Actors” via cybersecurity vendor BeyondTrust. BeyondTrust specialise in Privileged Access Management. In other words, they have the power to access or generate one-time-use Admin credentials for their customer networks.
bbc.com
US Treasury says it was hacked by China in 'major incident'
A Chinese state-sponsored hacker broke into the US Treasury Department's systems in what is being called a "major incident".
173
Toby Lewis @tobaslouis.co.uk · 17/12/2024
New blog post by analysts from @darktrace.com: Detecting the exploitation of internet-facing File Transfer Servers, exploiting CVE-2024-50623
darktrace.com
Cleo File Transfer Vulnerability: Patch Pitfalls and Darktrace’s Detection of Post-Exploitation Activities | Darktrace Blog
File transfer applications are prime targets for ransomware groups due to their critical role in business operations. Recent vulnerabilities in Cleo's MFT software, namely CVE-2024-50623 and CVE-2024-...
020
Toby Lewis @tobaslouis.co.uk · 10/12/2024
New blog post by analysts from @darktrace.com - a review of recent exploit campaigns against Palo Alto firewalls which are then used as a launch point into customer networks.
darktrace.com
Darktrace’s view on Operation Lunar Peek: Exploitation of Palo Alto firewall devices (CVE 2024-2012 and 2024-9474) | Darktrace Blog
Darktrace’s Threat Research team investigated a major campaign exploiting vulnerabilities in Palo Alto firewall devices (CVE 2024-2012 and 2024-9474). Learn about the spike in post-exploitation activi...
010
Toby Lewis @tobaslouis.co.uk · 05/12/2024
New blog post by analysts @darktrace.bsky.social - detecting the use of AiTM Phishing Kits, including MFA bypass, by attackers.
darktrace.com
A snake in the net: Defending against AiTM phishing threats and Mamba 2FA | Darktrace Blog
Phishing-as-a-Service (PhaaS) platforms have lowered entry barriers for cybercriminals, leading to sophisticated AiTM phishing attacks. Darktrace's AI-driven solutions, including Darktrace / EMAIL, ef...
010
Toby Lewis @tobaslouis.co.uk · 04/12/2024
I can only read this in the voice of the guy who reads out the Football results.
A cinema listing showing Gladiator 2, Paddington 3
020
Toby Lewis @tobaslouis.co.uk · 01/12/2024
‘Tis the season to… … be constantly picking up dropped pine needles off the floor
010
Reposted by Toby Lewis
TruBluFan @trublufan.bsky.social · 30/11/2024
021
Toby Lewis @tobaslouis.co.uk · 30/11/2024
England Women’s Football is more fun to watch than the men’s game
020
Toby Lewis @tobaslouis.co.uk · 30/11/2024
OSINT challenge - Easy Edition #lionesses
Wembley Stadium - I did say this was easy.
010
Toby Lewis @tobaslouis.co.uk · 27/11/2024
New blog post by analysts at @darktrace.bsky.social - detecting SaaS account compromise including the use of multiple VPN access points by threat actors.
darktrace.com
Behind the veil: Darktrace's detection of VPN exploitation in SaaS environments | Darktrace Blog
A recent phishing attack compromised an internal email account, but Darktrace’s advanced AI quickly intervened. By identifying unusual activity across email and SaaS environments, Darktrace uncovered ...
030
Toby Lewis @tobaslouis.co.uk · 27/11/2024
Yes... and no. A user clicking the link should never be "enough" to bring down your network. You will never have 0% click-through, so don't chase it, nor should you plan on that being a mitigation. It's better to try and increase the % of reports to the SOC. That will give you a chance to respond
151
Toby Lewis @tobaslouis.co.uk · 24/11/2024
In reality, this is about being prepared to quickly respond to an incident, whatever it may be. Technology can definitely help here, but so does strong Business Continuity & Disaster Recovery, that minimises business disruption.
010