Author's Posts

Hello All. I wanted to thank the organizer for having me at the 2025 Atlantic Security Conference in Halifax, NS this past week. I would also like to thank all the attendees who came to hear me speak.

For those who are looking for the slides, they can be downloaded from the link below:

https://www.petermorin.com/wp-content/uploads/2025/04/AtlSecCon-Top-AD-Attacks-2025.pdf

Please fee free to contact me if you have any questions. See you at the next con!

Read more

Reposting a post from Manjunath Hiregange from GE Vernova (thanks Manjunath!).

Are you interested in learning more about industrial control system (ICS) security, but struggling to find practical training opportunities?

Look no further than GRFICS (Graphical Realism Framework for Industrial Control Simulations) – free and open-source framework.

๐–๐ข๐ญ๐ก ๐†๐‘๐…๐ˆ๐‚๐’, ๐ฒ๐จ๐ฎ ๐œ๐š๐ง ๐ฏ๐ข๐ซ๐ญ๐ฎ๐š๐ฅ๐ข๐ณ๐ž ๐ž๐ง๐ญ๐ข๐ซ๐ž ๐ˆ๐‚๐’ ๐ง๐ž๐ญ๐ฐ๐จ๐ซ๐ค๐ฌ ๐š๐ง๐ ๐ฉ๐ซ๐š๐œ๐ญ๐ข๐œ๐ž ๐ž๐ฑ๐ฉ๐ฅ๐จ๐ข๐ญ๐ข๐ง๐  ๐ฏ๐ฎ๐ฅ๐ง๐ž๐ซ๐š๐›๐ข๐ฅ๐ข๐ญ๐ข๐ž๐ฌ ๐ฐ๐ก๐ข๐ฅ๐ž ๐ฌ๐ž๐ž๐ข๐ง๐  ๐ญ๐ก๐ž ๐ฉ๐ก๐ฒ๐ฌ๐ข๐œ๐š๐ฅ ๐ข๐ฆ๐ฉ๐š๐œ๐ญ ๐ข๐ง ๐š 3๐ƒ ๐ ๐š๐ฆ๐ž ๐ž๐ง๐ ๐ข๐ง๐ž.

The GRFICS framework is designed to virtualize entire ICS networks, including realistic ๐ฉ๐ก๐ฒ๐ฌ๐ข๐œ๐š๐ฅ ๐ฉ๐ซ๐จ๐œ๐ž๐ฌ๐ฌ ๐ฌ๐ข๐ฆ๐ฎ๐ฅ๐š๐ญ๐ข๐จ๐ง๐ฌ. While the initial version of GRFICS virtualizes a chemical process control network with a flat, un-segmented network architecture, the framework is modular and can be customized and expanded to include other types of ICS networks.

Here is a link to the 5 VMs: https://github.com/Fortiphyd/GRFICSv2
5 VirtualBox VMs (๐š 3๐ƒ ๐ฌ๐ข๐ฆ๐ฎ๐ฅ๐š๐ญ๐ข๐จ๐ง, ๐š ๐ฌ๐จ๐Ÿ๐ญ ๐๐‹๐‚, ๐š๐ง ๐‡๐Œ๐ˆ, ๐š ๐ฉ๐Ÿ๐ฌ๐ž๐ง๐ฌ๐ž ๐Ÿ๐ข๐ซ๐ž๐ฐ๐š๐ฅ๐ฅ, ๐š๐ง๐ ๐š ๐ฐ๐จ๐ซ๐ค๐ฌ๐ญ๐š๐ญ๐ข๐จ๐ง) communicating with each other on host-only virtual networks.

A video series walking through VM setup and example attacks is available on the Fortiphyd YouTube channel at https://www.youtube.com/playlist?list=PL2RSrzaDx0R670yPlYPqM51guk3bQjFG5

Read more

No one wants to see a blue screen on a Friday morning!

Not sure if folks are following the news, but a major bug has been identified with CrowdStrike Falcon stemming from a bad update. It is causing blue screens in Windows. Here is a statement from George Kurtz, CEO:

CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed. We refer customers to the support portal for the latest updates and will continue to provide complete and continuous updates on our website. We further recommend organizations ensure theyโ€™re communicating with CrowdStrike representatives through official channels. Our team is fully mobilized to ensure the security and stability of CrowdStrike customers.

There is a manual workaround, which is scriptable:

  • Boot Windows into Safe Mode or the Windows Recovery Environment
  • Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
  • Locate the file matching ‘C-0000029*.sys’, and delete it.
  • Boot the system normally.

Just when we thought this was bad enough… Microsoft had an Azure outage. Looks like Azure Central US was down for hours. But had global impacts. Airlines and other major customers all over the world we impacted. some in India reverted to checking in passengers manually in excel spreadsheets. Also affected M365.

“We experienced a Storage incident in Central US which had downstream impact to a number of Azure services. This is currently mitigated; however, we are still in the process of validating recovery to a small percentage of those downstream services. This was communicated to affected customers via the Service Health dashboard in the Azure portal. We are also aware of an issue impacting Virtual Machines running Windows, running the CrowdStrike Falcon agent, which may encounter a bug check (BSOD) and get stuck in a restarting state. While this is an external dependency, we are currently investigating potential options for Azure customers to mitigate and will be providing updates via the status page here: https://azure.status.microsoft/en-gb/status/ as well as our Azure portal, where possible.”

Good luck everyone!

Read more