How to Use Corelight and Zeek Logs to Mitigate RDS/RDP Vulnerabilities

By Richard Bejtlich, Principal Security Strategist, Corelight Introduction On May 14 Microsoft released patches for, and details about, a remote code execution vulnerability in Remote Desktop Services (RDS), the graphical interactive desktop offered with most Windows operating system platforms. This vulnerability bears the Common Vulnerabilities and exposures number CVE-2019-0708. Remote Desktop Protocol (RDP) is the […]

Network Security Monitoring, a Requirement for Managed Service Providers?

By Richard Bejtlich, Principal Security Strategist, Corelight Over the last six months, we’ve read in the security press about a variety of managed service providers (MSPs) being compromised by nation-state and criminal actors. Some examples: December 2018 – The United States Department of Justice indicted two individuals associated with APT10 for their role in compromising […]