The Anatomy of the Modern Intrusion
What modern intrusions look like after the textbook timeline falls apart—and how repeatable tradecraft and peripheral telemetry make sparse evidence defensible.
10 posts tagged with this topic.
What modern intrusions look like after the textbook timeline falls apart—and how repeatable tradecraft and peripheral telemetry make sparse evidence defensible.
Exploring how agentic AI can support incident response by applying concurrent, methodical analysis across large telemetry sets. We examine where specialized agents fit into PICERL workflows, how adversarial review helps control false positives, and why orchestration matters in real-world investigative environments.
Building an entity-centric ES|QL hunting model for SSLVPN abuse by prioritizing topology over raw alert volume. We explore how infrastructure reuse, cross-organization overlap, and short authentication time deltas can separate adversarial activity from benign noise at scale.
Examining patterns observed in operating and collecting data from an SSLVPN honeypot sitting behind a Finch proxy.
Ransomware affiliates have long since abused Cloudflared tunnels to maintain persistent access to compromised environments. These tunnels can be utilized as a strong indicator of compromise when examined at-scale.
A continually evolving knowledgebase of things I've found pertinent as a threat and security operations analyst, specifically focusing on malware analysis.
Chainsaw's hunt feature, along with Chainsaw's rule engine, is an excellent way to hunt for evil at scale and create reusable, maintainable queries for rapid triage. We will apply this to both simulated red team engagements and real world compromises to detect lateral movement, Impacket, and even ASP.NET compromises.
A brief introduction to Chainsaw's search feature and the document tagging engine, Tau, that WithSecure released in the most recent major Chainsaw update. We will discuss and demystify some of the nuance of Tau's query behavior, and apply these to hands on examples of simple queries that can be utilized to detect evil across numerous event logs with high fidelity.
Discussing obfuscation and its effect on the broader open-source supply chain.
No-lone zones are ubiquitous with critical military tasks, and the scope and potential impact of the xz backdoor present an excellent opportunity to discuss how this could be applied to open source software.