Meta tags:
Headings (most frequently used words):
2026, monday, january, on, saturday, windows, june, 19, 10, thursday, december, 2025, windowsir, blog, lnk, files, in, incident, response, july, 04, 27, friday, tuesday, march, february, 02, 05, 01, 29, 11, pages, subscribe, to, list, archive, finding, initial, access, cti, rigor, threat, intel, consistency, timelines, links, devices, views, ai, the, anthropic, report, what, your, clipboard, questions, ve, been, asked, defender, support, logs, grab, bag, question, open, source, tools, perspectives, cybersecurity,
Text of the page (most frequently used words):
the (609), and (328), that (248), this (125), for (113), was (97), you (91), with (80), not (77), there (72), what (71), but (66), from (64), data (58), have (57), are (55), share (54), threat (53), they (53), can (53), some (52), post (51), about (48), one (47), how (47), blog (43), time (42), when (41), been (41), files (40), windows (37), were (36), used (35), more (34), just (34), see (34), all (32), analysis (32), then (32), into (32), something (30), where (28), also (27), their (27), other (27), #january (26), may (26), way (26), had (26), lnk (25), information (25), june (24), look (24), actor (24), december (23), march (23), why (23), even (23), which (23), available (23), seen (23), now (23), file (23), clipboard (23), february (22), july (22), october (22), because (22), than (22), use (22), found (22), analysts (22), comments (21), like (21), much (21), has (21), them (21), well (21), don (21), your (21), september (20), know (20), things (20), going (20), point (20), first (20), endpoint (20), devices (20), april (19), november (19), part (19), using (19), email (19), posted (19), out (19), system (19), while (19), work (19), take (19), across (19), would (19), write (19), process (19), august (18), example (18), question (18), tools (17), most (17), over (17), incident (17), based (17), systems (17), actors (17), recently (17), access (16), ago (16), these (16), need (16), analyst (16), attack (16), logs (16), those (16), same (16), shared (16), report (16), 2026 (15), pinterest (15), facebook (15), blogthis (15), carvey (15), response (15), team (15), different (15), get (15), ransomware (15), any (15), tool (15), registry (15), back (14), will (14), during (14), run (14), saw (14), however (14), say (14), means (14), only (14), did (14), server (14), usb (14), finding (13), initial (13), running (13), lot (13), doing (13), able (13), another (13), here (13), does (13), provide (13), doesn (13), linkedin (13), very (13), someone (13), bit (13), such (13), connected (13), figure (13), login (13), find (12), defenders (12), times (12), etc (12), path (12), off (12), often (12), soc (12), could (12), our (12), via (12), regripper (12), published (12), specific (12), really (12), image (12), sources (12), application (11), engagement (11), multiple (11), got (11), engagements (11), cases (11), tooling (11), own (11), intel (10), timelines (10), many (10), years (10), before (10), simply (10), few (10), default (10), being (10), said (10), his (10), sharing (10), looking (10), web (10), attempts (10), rather (10), after (10), little (10), reading (10), successful (10), develop (10), might (10), artifacts (10), goals (10), claude (10), findings (10), metadata (10), source (9), malware (9), who (9), applications (9), installed (9), sure (9), together (9), every (9), sometimes (9), issues (9), worked (9), yes (9), started (9), less (9), nor (9), attacks (9), consulting (9), incidents (9), through (9), new (9), easy (9), timeline (9), support (9), within (9), include (9), log (9), year (8), case (8), technical (8), fact (8), understand (8), along (8), endpoints (8), two (8), event (8), working (8), good (8), infrastructure (8), seeing (8), following (8), regarding (8), various (8), great (8), article (8), down (8), aware (8), effort (8), forensics (8), parsing (8), history (8), key (8), investigation (8), provided (8), understanding (8), forensic (8), 2025 (7), months (7), command (7), posts (7), albeit (7), content (7), remember (7), received (7), detection (7), overall (7), services (7), both (7), having (7), format (7), later (7), against (7), make (7), indications (7), clear (7), answer (7), company (7), anything (7), organizations (7), igor (7), events (7), output (7), better (7), cybersecurity (7), described (7), last (7), interesting (7), previous (7), contents (7), read (7), activity (7), anthropic (7), investigations (7), provides (7), developed (7), consistency (7), failed (7), 2016 (6), 2018 (6), dfir (6), comes (6), alert (6), assumption (6), surface (6), security (6), clearly (6), isn (6), asked (6), specifically (6), drive (6), ran (6), including (6), field (6), without (6), add (6), recent (6), spent (6), let (6), yrs (6), providing (6), around (6), approach (6), limited (6), want (6), plugins (6), mean (6), aspects (6), document (6), deal (6), right (6), end (6), full (6), parse (6), triage (6), entire (6), customer (6), fig (6), thought (6), address (6), malicious (6), side (6), became (6), value (6), step (6), 2008 (5), rigor (5), cti (5), show (5), brett (5), line (5), open (5), list (5), books (5), podcast (5), context (5), organization (5), folks (5), each (5), should (5), goes (5), hard (5), again (5), aperture (5), statement (5), historically (5), best (5), call (5), role (5), copy (5), knowledge (5), others (5), perspective (5), moved (5), persistence (5), nothing (5), think (5), defender (5), level (5), career (5), start (5), vulnerability (5), next (5), link (5), workstation (5), writing (5), plugin (5), already (5), everything (5), online (5), upon (5), since (5), early (5), days (5), help (5), useful (5), memory (5), developing (5), didn (5), long (5), themselves (5), links (5), keep (5), microsoft (5), images (5), real (5), collection (5), still (5), particularly (5), given (5), disabled (5), almost (5), bad (5), whatever (5), needed (5), place (5), parsed (5), faster (5), likely (5), excerpt (5), summary (5), observed (5), aren (5), addresses (5), research (5), digital (5), try (5), affiliates (5), similar (5), written (5), steps (5), archives (5), 2022 (4), training (4), windowsir (4), home (4), basis (4), either (4), thinking (4), points (4), eco (4), environment (4), reduction (4), mssql (4), required (4), entirely (4), admin (4), asking (4), instead (4), thumb (4), complete (4), view (4), jensen (4), difficult (4), actual (4), evidence (4), corporate (4), important (4), global (4), between (4), target (4), starting (4), known (4), leave (4), tend (4), updates (4), created (4), called (4), describing (4), yara (4), topic (4), pretty (4), addition (4), monday (4), comment (4), book (4), experiences (4), true (4), pdfs (4), thoughts (4), exe (4), creating (4), user (4), valley (4), rat (4), grab (4), bag (4), dropping (4), day (4), okay (4), number (4), linux (4), encase (4), logging (4), depending (4), change (4), references (4), questions (4), social (4), media (4), consider (4), device (4), else (4), mention (4), locations (4), associated (4), clipboardhistorythief (4), dump (4), prior (4), settings (4), groups (4), pci (4), notice (4), blue (4), activities (4), state (4), reason (4), wmi (4), problem (4), prompts (4), techniques (4), result (4), left (4), intelligence (4), chain (4), learned (4), appear (4), documentation (4), depth (4), manually (4), raas (4), artifact (4), exploit (4), tag (4), done (4), automate (4), processes (4), members (4), transitioned (4), respond (4), 2006 (3), 2007 (3), 2023 (3), archive (3), names (3), private (3), sector (3), atom (3), pages (3), older (3), podcasts (3), style (3), regular (3), movie (3), cycles (3), impacted (3), generated (3), accurate (3), once (3), local (3), staff (3), consultant (3), ticket (3), text (3), went (3), addressing (3), copied (3), opened (3), three (3), evt (3), zero (3), editor (3), actively (3), makes (3), agree (3), domain (3), regularly (3), personal (3), decade (3), germany (3), concerned (3), theft (3), installations (3), appears (3), second (3), changes (3), high (3), made (3), military (3), began (3), assessments (3), haven (3), talk (3), notes (3), receive (3), came (3), capability (3), product (3), added (3), incorporate (3), keys (3), focus (3), always (3), seems (3), github (3), usually (3), articulate (3), enough (3), particular (3), changed (3), location (3), getting (3), info (3), leads (3), technique (3), reference (3), whole (3), hkcu (3), apparently (3), configuration (3), mentioned (3), actually (3), folder (3), parser (3), wondering (3), lists (3), vary (3), methodology (3), investigating (3), describes (3), searches (3), documented (3), above (3), exfiltrated (3), sync (3), enabled (3), descriptions (3), hit (3), page (3), collecting (3), weren (3), fascinating (3), saturday (3), repository (3), half (3), mechanisms (3), human (3), order (3), possible (3), sift (3), conduct (3), supported (3), logins (3), today (3), incorrect (3), chatgpt (3), hope (3), executive (3), whether (3), autonomously (3), individual (3), targeted (3), legal (3), environments (3), playbooks (3), monitoring (3), updated (3), under (3), note (3), protocols (3), presentations (3), computer (3), model (3), reporting (3), move (3), involved (3), capture (3), ways (3), issue (3), deleted (3), revision (3), led (3), indicators (3), wietze (3), detections (3), structure (3), timing (3), chris (3), week (3), enrichment (3), decoration (3), error (3), results (3), original (3), gaps (3), forget (3), common (3), consistent (3), description (3), internal (3), cross (3), pollination (3), confidence (3), iss (3), name (3), exfil (3), situational (3), awareness (3), comparison (3), timestamps (3), campaigns (3), exploited (3), sql (3), injection (3), theme (2), 2004 (2), 2005 (2), 2009 (2), 2013 (2), 2014 (2), 2020 (2), 2024 (2), evil (2), group (2), netbios (2), philosophy (2), month (2), comparing (2), subscribe (2), fan (2), mostly (2), movies (2), yeah (2), matter (2), gpu (2), receives (2), positive (2), subject (2), policy (2), terminal (2), installation (2), force (2), password (2), defend (2), presence (2), regardless (2), phone (2), direct (2), engage (2), him (2), understood (2), room (2), tried (2), bytes (2), size (2), toolset (2), transfer (2), admins (2), boots (2), ground (2), perhaps (2), civilian (2), knew (2), owner (2), servers (2), advantage (2), trying (2), mind (2), scoping (2), office (2), moving (2), deploy (2), built (2), asset (2), inventory (2), outside (2), closely (2), couldn (2), computationally (2), costly (2), respect (2), neither (2), discussion (2), task (2), protect (2), scale (2), pointing (2), current (2), beyond (2), volume (2), unique (2), challenges (2), sausage (2), making (2), familiar (2), background (2), trained (2), experience (2), war (2), dialing (2), listened (2), easily (2), accessible (2), wanted (2), views (2), stringent (2), focused (2), chatter (2), thursday (2), nuix (2), commercial (2), functionality (2), aug (2), values (2), describe (2), incorporating (2), simple (2), interest (2), especially (2), attention (2), itself (2), come (2), directed (2), beginning (2), ask (2), reg (2), update (2), mattis (2), remains (2), talked (2), thousands (2), ahead (2), campaign (2), coffee (2), saving (2), keeping (2), docs (2), wrote (2), interested (2), shellcode (2), 101 (2), authors (2), speaking (2), further (2), heard (2), account (2), paths (2), console (2), stored (2), stage (2), anyway (2), sort (2), dog (2), linking (2), mentions (2), strings (2), follow (2), disk (2), anywhere (2), live (2), put (2), noise (2), indicate (2), yesterday (2), idea (2), appeared (2), nature (2), generally (2), expanding (2), capabilities (2), alerts (2), publish (2), date (2), ups (2), cheat (2), cyber (2), brian (2), somewhat (2), moment (2), setting (2), auditing (2), item (2), gets (2), automated (2), code (2), paste (2), window (2), tracking (2), works (2), combo (2), hadn (2), opening (2), according (2), site (2), mitre (2), att (2), ish (2), showed (2), coding (2), addendum (2), jan (2), dozen (2), discussed (2), operated (2), manner (2), protocol (2), happens (2), hallucinates (2), record (2), chiara (2), rob (2), instance (2), concern (2), release (2), illustrates (2), finally (2), states (2), operational (2), errors (2), illustrate (2), says (2), set (2), offensive (2), estimated (2), tactical (2), operations (2), away (2), low (2), slow (2), matthew (2), maybe (2), iocs (2), employed (2), earlier (2), physically (2), impossible (2), request (2), rates (2), fields (2), misused (2), software (2), never (2), attempting (2), dealing (2), apply (2), valuable (2), elcomsoft (2), types (2), program (2), execution (2), directory (2), install (2), traditional (2), alternative (2), investigative (2), driverframeworks (2), usermode (2), recorded (2), must (2), includes (2), series (2), similarly (2), definitely (2), cory (2), quite (2), nicole (2), smartphones (2), unfortunately (2), her (2), pca (2), button (2), involves (2), platform (2), arun (2), deployed (2), feb (2), credit (2), card (2), structured (2), followed (2), managing (2), life (2), cycle (2), service (2), determining (2), samas (2), pst (2), screen (2), xstreader (2), docx (2), rsids (2), amcache (2), lines (2), word (2), modified (2), adding (2), stuff (2), engaging (2), thorough (2), machine (2), laid (2), control (2), efficacy (2), insight (2), sniper (2), power (2), huntress (2), sophos (2), included (2), dongles (2), items (2), automation (2), modicum (2), prone (2), lessons (2), lab (2), intake (2), acquired (2), laptops (2), wouldn (2), processing (2), bunch (2), missed (2), prefetch (2), extract (2), thing (2), everyone (2), assess (2), locate (2), kicking (2), took (2), levels (2), responsible (2), consistently (2), truly (2), framework (2), unknown (2), certified (2), visa (2), completing (2), easier (2), guesswork (2), meet (2), longer (2), ibm (2), equipment (2), fte (2), roles (2), stay (2), aggregated (2), logical (2), continue (2), accessed (2), requires (2), aggregate (2), review (2), 4th (2), disparate (2), patterns (2), accumulation (2), aggregation (2), observations (2), wiped (2), populated (2), mandiant (2), cozybear (2), embedded (2), thehackernews (2), reports (2), leading (2), commands (2), enterprise (2), awesome, inc, powered, blogger, 163, 118, 108, 166, 2010, 109, 2011, 2012, 2015, 2017, 2019, 2021, forensicitguy, inside, nsa, equation, ttps, china, lense, inversecos, xworm, static, cyberdefnerd, pivoting, clustering, apt, ure, introducing, huntable, studio, dfirtnt, wordpress, com, law, enforcement, forbidden, shavers, weeks, study, foss, conversational, listen, easter, eggs, marvel, conspiracies, speculation, upcoming, spoil, superhero, require, misinterprets, takes, wrong, action, deems, false, effects, snowball, rails, leaving, worse, position, expansive, dynamic, seem, realize, reality, belies, defending, lacks, map, vision, hence, realizing, coded, credentials, brute, guessing, magnitude, greeted, warmly, ambivalent, quietly, hostile, shrug, contractor, contact, advisor, export, nodded, handed, none, hex, immediately, indeed, exported, renamed, disappointed, bring, bear, happy, enthusiastic, sought, opposite, suspicious, shoulder, standing, mine, rubber, meets, road, coalface, higher, founder, ceo, vast, landscape, gov, cisa, agencies, therefore, effectively, recognized, workstations, critical, controllers, browse, lack, compartmentalization, connect, efforts, succeed, brings, manufacturing, offices, deploying, due, privacy, laws, establishing, stealing, artificiality, ignored, stop, course, possibly, simplest, operating, magical, intuition, mystical, abilities, discern, network, told, disparity, asymmetric, asymmetry, identify, deduct, convinced, internet, return, compromised, shells, challenge, status, speed, presents, game, defense, final, watching, myself, readers, college, communications, non, represents, google, 2000, quarter, century, responding, socs, mssps, currently, mdr, joe, rogan, guest, interview, synopsis, huang, tsyganskiy, video, preferences, big, gratuitous, small, hilarity, sit, ads, shoutz, sponsors, perspectives, extensions, paraben, provider, directly, basically, walking, spoke, inaugural, conference, json, version, industry, inordinate, mastering, freely, shiny, majority, articulation, forth, tease, usual, repo, publicly, anyone, googling, designed, extensible, assistance, turned, hour, choose, route, helps, hive, testing, win11, sustain, warfighters, endeavors, expand, taled, incumbent, sign, chaos, brought, consume, meeting, beer, adult, beverages, seemed, reach, youtube, channels, sponsored, courses, self, paced, blogging, entertaining, adversary, craft, viable, methodologies, ultimately, amounts, familiarity, explorer, valli, nayagam, chokkalingam, interestingly, linked, ntuser, man, deceptiq, dec, 1995, talking, ever, entries, tied, stand, d33f351a4aeea5e608853d1a56661059, downloaded, cloudsek, maintains, silver, fox, rolled, worry, expecting, flaming, poop, dropped, doorstep, rest, assured, explanation, behind, referred, diagnostic, though, kit, give, shot, deadpool, figured, opportunities, pull, popped, related, mplog_parser, mpwpptracing, yyyymmdd, hhmmss, 00000003, fffffffeffffffff, bin, naming, convention, programdata, unlikely, please, contrived, scenarios, ctfs, valid, love, free, expense, become, performing, alone, serving, greeter, church, firewall, examined, begin, xenix, unless, essential, decades, controller, versus, typical, significantly, sets, cheating, leveraging, stores, massive, amount, hoping, ton, urls, slide, explain, enrich, decorate, gathered, carrier, webinar, invited, routes, webinars, keeps, bubble, hint, rarely, tough, draw, bead, invaluable, insider, option, concerning, several, audits, staging, exfiltration, pasted, imagine, expands, guy, enables, dumps, clears, shipping, feed, consisting, exactly, emails, documents, swaths, redacting, inclusion, wow, searched, essentially, replica, whoa, navigate, stackoverflow, navigating, shown, named, app, decided, desktop, logo, examples, t1115, admit, batch, native, stick, rom, far, signs, interacting, infostealers, bitcoin, wallet, hopes, pastes, enabling, transaction, modifies, thomas, roccia, morning, worth, considering, assistants, blindly, sound, mentality, facing, emphatically, guys, front, middleware, wasn, supporting, fair, iteration, doppelpaymer, operators, relied, collections, acquiring, minimal, timely, acquire, hours, breach, megabytes, configured, performs, attribution, hallucination, retrieved, job, failure, simplifications, confusion, gallese, she, mit, lecturer, attempt, riemann, hypothesis, math, hasn, solved, 160, stood, statements, users, prompt, light, unable, examination, lee, sans, fame, announced, integrated, mcp, visibility, usage, terms, hallucinations, freaking, handled, probably, fast, loud, increases, velocity, obvious, addressed, pros, taste, mouth, nitty, gritty, details, staple, genre, becomes, akin, commonly, ooda, loop, smaller, tighter, iterated, humanly, hopefully, fired, closer, chains, nation, execute, independently, espionage, title, table, starts, professional, appropriately, dev, term, slop, adopted, perfect, responder, cleared, conditions, recommendation, foremost, prove, disprove, maintain, implementations, edge, excellent, weber, resources, mar, landesk, suggest, granularity, shellbags, transversal, past, msiinstaller, illustrating, pursue, stated, versions, activation, powershell, activated, quick, garrett, moreau, removed, usbstor, category, eye, investigate, recommended, recommends, nirsoft, usbdeview, covering, expect, tracked, impact, gone, peer, reviewed, paper, timeframe, pursuant, violation, acceptable, policies, csam, production, cameras, cable, traditionally, validate, contains, pointers, precious, whenever, tremendous, identifies, camera, smart, distinction, couple, blogs, posting, articles, player, appx, universal, session, macos, dig, wmp, forward, yelp, aspect, rating, ride, driver, hospitals, affiliate, hits, hospital, brand, damaged, hacker, botherder, 0x80, usss, carder, planet, cybercrime, evolution, breaking, apart, compartmentalizing, monetization, opted, allowing, brokers, iabs, steal, profit, reportedly, assist, stolen, krebs, agreed, released, beercow, handle, larger, ost, personally, lately, extracting, forked, author, ross, plagiarism, thoroughly, shimcache, too, win, demonstrates, nuances, ole, storage, doc, retained, damning, slack, space, blair, 2003, caught, demonstration, save, identifiers, timestamp, correlated, demonstrate, whom, msword, launched, formats, draft, removing, weekly, monthly, fewer, intentional, check, combined, utilizing, purposes, rules, commentator, nice, overview, casual, viewing, properties, generating, identifying, deceptive, short, future, dude, bone, tuesday, virtual, overlays, mft, usn, journal, browser, drawing, armor, ironman, pieces, aligned, picture, powerful, fills, spreadsheet, incredible, spot, discussing, nod, pogue, brewer, micro, lindsey, records, separate, pivot, ripper, eventmap, secureworks, owned, attributed, muddywater, stripped, stamp, spacing, reduced, drafted, parts, sections, walk, create, tln, admitting, friday, boarding, headquarters, least, licenses, products, total, art, sat, walked, selecting, select, minutes, selected, profile, assume, extent, fancy, build, extend, external, intensive, heavy, lifting, efficient, frees, development, baking, learn, drives, sent, technician, care, connecting, extraction, inform, ready, mount, single, press, stone, immutable, baseline, deviate, justification, deviation, collected, boom, repeatable, repeatability, collect, looked, hve, restricting, taking, conducting, automating, virustotal, cpu, form, entry, automatically, manual, additional, ones, oversight, inconsistent, strategic, inefficient, mess, thankfully, cannot, replicated, operationalize, institutional, base, completion, accuracy, spend, chasing, rabbit, holes, quickly, answers, spackle, guesses, tickets, active, reported, message, expected, necessary, methods, bulk_extractor, volatility, returned, pandemic, lockdown, shy, tenure, amazing, director, large, highest, deeper, escalated, practices, dug, established, employing, edr, technology, drastically, reduce, 000, touched, hands, tidbit, researching, remained, marked, guaranteed, mix, benign, arbitrary, driving, mandatory, remove, giving, arose, troubleshoot, importantly, meant, obligations, timeliness, uncover, pertinent, requirements
Text of the page (random words):
s lnk file metadata truly fully exploited the last time i can remember really seeing lnk file metadata incorporated into analysis was the mandiant write up on cozybear from nov 2018 where figures 5 6 illustrate differences been 2016 and 2018 campaigns by comparing lnk file metadata figure 1 lnk metadata source thehackernews a recent article from thehackernews described an attack chain that started off with a zip archive containing an lnk file pretending to be a hangul word processing hwp document as a lure the article does not provide figure or image numbers but does contain the image seen in figure 1 albeit not with a description within close proximity to the image you have to read on a bit of the description this image does provide something of a comparison between two observed lnk files albeit without the full breadth of metadata while the image does describe the timestamps as all zero wiped there s no apparent reference to a machine id netbios name field either as populated or wiped nor is there any mention of extra data blocks and whether or not they exist and are populated the point is that there is significant value in tracking lnk file metadata across campaigns as doing so gives us a better view into threat actor tooling and situational awareness for example in the mandiant comparison of the two cozybear campaigns 2016 2018 they used embedded timestamps to support a finding in their analysis in figure 1 we see in the comparison between the two lnk files that the timestamps were zeroed out by looking further into available metadata we can make determinations around the threat actor tooling as well as the process they use for developing the lnk files and the lures providing insight into their situational awareness but i get it all of this requires rigor first analysts and organizations need to know that this information is available and then they need to know how to extract it aggregate it and track it then findings need to be supported by accumulated data as part of a review process posted by h carvey at 8 09 am no comments email this blogthis share to x share to facebook share to pinterest rigor in threat intel i m just going to say it iocs are not threat intel lists of ip addresses and domain names without context are data points and information not intel threat intel is based on patterns developed from the accumulation aggregation of data in 2016 i took a look at about half a dozen samas ransomware engagements all worked by different ir analysts all of these analysts were focused on servicing the ir consulting business model that is work the engagement write the report and deliver it to the customer so that they could move on to the next engagement however by looking across multiple engagements i began to see commonalities and overlaps in threat actor activity including initial access as well as other phases of the attack that led up to the ransomware deployment within the impacted infrastructures by seeing verifying and confirming activities that were observed consistently i e initial access confidence increased in the understanding of that attack phase this was particularly valuable when for whatever reason logs or other artifacts weren t available as a result of our supported observations and findings we published a blog post describing our findings and someone reading our blog post reached out to let us know that they d look for some of the initial indicators and were able to prevent their own organization from being ransomed later a good bit of the content provided in that original 2016 blog post was transitioned to another blog post in 2018 and the company was then later purchased by sophos however the point remains we were able to develop an extremely granular understanding of the threat actor s attack chain and timing based on accumulating data across multiple engagements and then aggregating it into threat intelligence about the threat actor threat intel is based on patterns developed from an accumulation and aggregation of data so we can use data from multiple incidents to fill in gaps in observations understanding and detections we can better understand a threat actor s capabilities and situational awareness and develop a better understanding of how the threat actor operates not only in similar environments but also across multiple disparate environments and how they respond to various stimulus or obstacles we get to see what really goes on when a threat actor gains access to an endpoint or infrastructure what actions they take in what sequence and with what timing as well as how they respond to challenges such as when something they were observed doing or using on previous engagements is not available or some security tooling hampers or completely inhibits their ability to continue in their attack i ve seen actors try 3 times to run the ver command before succeeding the 4th time i ve seen the same threat actor make multiple attempts to launch their malicious dll via rundll32 exe across multiple incidents i ve seen threat actors respond to security tooling deleting their malware by attempting to uninstall applications that aren t even installed on the endpoint i ve also seen threat actors access an infrastructure orient themselves and then step off on their attack chain installing multiple disparate persistence mechanisms i ve seen threat actors determine what s running on the endpoint before copying over their tooling and i ve seen threat actors simply blind the available tooling with no prior recon as if they already knew what they were dealing with in the infrastructure rigor all that being said we also have to understand that errors compound as we aggregate that data as well this is why analysts must take a rigorous approach to populating that aggregated data one that includes review where analysts need to be able to justify their findings rather than simply have them thrown into the pile and accepted as fact or truth albeit without question i know i know no one wants to hear that threat intel requires rigor i get it it s much easier to simply state something as fact than it is to provide the evidence to support that statement take data exfil for example i ve seen data exfil a number of times and proven it during one incident the threat actor archived data on one endpoint where we were able to capture the archival command line which included the threat actor s archive password and we found that the threat actor had moved the archives to an endpoint that was running an accessible web server they copied the files to a web directory accessed the web server from outside and requested the files then deleted the files from the web server in this case we had the captured command line file names proof of data exfil in the web server logs and we imaged the physical disk for the server and recovered the deleted archives during another engagement a threat actor had accessed a remote linux based infrastructure and transitioned to the corporate windows based infrastructure something they weren t supposed to be able to do the threat actor created archives on a windows server and copied them to a linux system we had copies of the archives on both endpoints relevant file system time stamps and netflow showing the transfer but think about how many times do we see a threat actor creating archives or simply that winzip or 7zip was run and based on just that observation state the threat actor exfiltrated data i mean sure it s a logical assumption but are we able to support that assumption with evidence in a high stress engagement where the impacted org is trying to assess risk it s easy to say data was exfiltrated but if that s all you ve got how do you then answer the question to where the same is true for other data as well if we see a bunch of failed login attempts to rdp mssql etc that originate from a particular ip address or workstation name and then we see a successful login how is this finding described to a customer most often it s failed login attempts originating from identifier resulted in a successful login we say this because it s a logical assumption yet i ve seen endpoints with thousands of failed login attempts and neither the user name nor the source ip address of the successful login are found on the list of failed login attempts in addition the failed login attempts often continue well after the successful login but it s an assumption and as data is aggregated across multiple engagements assumptions need to be clearly identified as such otherwise they are simply an error that compounds across that data and makes it s way into the intel as such posted by h carvey at 8 02 am no comments email this blogthis share to x share to facebook share to pinterest saturday june 27 2026 consistency i ve worked a lot of places over the years all for varying lengths of time while this worked against me in the early days with potential employers wondering why i didn t stay longer at my previous employer and wondering how long i d potentially stay with them this became less of an issue later in my career during my career in the private sector i ve run vulnerability assessments and spent over 26 yrs in digital forensics and incident response some in fte roles and much more in consultant roles in 2006 i started in a dfir consulting role at iss which evolved 6 months later when the company purchase by ibm was completed i then became a plank owner of the ibm iss x force ers team one of the original members of the team even before we expanded when i started i was provided with a complete outfitting of equipment including but not limited to write blockers cabling laptops and dongles for encase 4 22 encase 6 19 and ftk as our team grew in size everyone received similar albeit updated in some cases equipment when i started at iss i was one of 4 responders and we each did our own thing when it came to analysis there was little in the way of cross pollination sharing of experiences etc as the new team began to grow it was a bit before some of us saw the need for consistency across the team in 2007 members of our team became certified to conduct pci forensic investigations which were subject to very stringent and somewhat arbitrary timelines as part of this chris and i developed a process that we shared with all of the team members using encase to conduct all of the searches required by visa driving the whole pci effort at the time not just the mandatory the credit card number searches the idea was in part to remove the need for individual analysts to have to try to figure out what to do by giving them a common documented step by step process for completing all of the required activities in a consistent manner this way if issues arose they were easier to troubleshoot more importantly having a consistent process meant that there was less room for guesswork and we had confidence that as long as the process was followed we d be able to meet our obligations regarding timeliness this also left more time for analysts to uncover things like initial access and other pertinent information because the guesswork of what to do next in order to meet visa s requirements was no longer something analysts needed to concern themselves with in 2013 i started at company on a team that was already well established this team was responsible for developing and actively employing the edr technology used by the company and this was used to drastically reduce the scoping of targeted threat actor incidents at which point triage or full forensics of specific systems could take place for example one incident involved 15 000 endpoints in a global infrastructure and we found that the threat actor had touched 8 of the systems and been on only 2 few members of the team at the time had actual hands on experience with truly in depth df work and there was very little in the way of sharing of tools techniques and processes between analysts there was no documentation little cross pollination and some issues with consistency in the use of the analysis framework every now and then someone might share a tidbit here and there but different analysts had different ways of using the framework for example one analyst might tag something they hadn t seen before as unknown where another would tag it as definitely malicious with the thought of going back and researching those items a bit more and often they didn t they remained marked the way they were so when those same indicators showed up on another engagement for another analyst it was pretty much guaranteed that you d see a mix of unknown malicious and benign from previous engagements in 2020 i started at a df ir consulting company and spent my first week on boarding at headquarters during that time i made an effort to start engaging with df analysts in part to see what tools they were using and how they were using them what i found was that almost all of the analysts had at least 4 dongles licenses to commercial products and in some cases a total of 5 or more and every analyst had their own way of doing things one analyst described what they did as an art i sat with one analyst as they walked me through how they used one of tools selecting various artifacts to be parsed they d been doing this for some time now and for every case they d go in and manually select each item from memory we spent a few minutes working on it together and we found that the application had a way for analysts to have a set of items be selected every time in a profile unfortunately i returned home at the end of that first week just as the pandemic lockdown was kicking off and just shy of three months into my tenure i and others were laid off it took time but i found an amazing role as the director of the internal soc for a large consulting company one that had three levels of soc analyst the highest l3 were responsible for deeper forensic analysis of incidents that had been escalated up by the prior two levels during my time there while there were some tools discussed what became clear to me was that each of the analysts had their own way of doing things and there was very little in way of documentation case notes etc or cross pollination and there was limited effort to develop a best practices approach to analysis or just something that was employed consistently across the team as a result when a finding was added to a ticket or report there was no clear understanding as to how that finding was developed and when the how was dug into often the results would be different depending upon the analyst i had seen time and again in the tickets that analysts were collecting active memory from reported endpoints and running strings on the memory dump in an effort to locate indications of the use of ip addresses i wrote up a message to the team describing why this was an incorrect approach and that what was expected is that they d use volatility and bulk_extractor to get the necessary information i also provided a technical description as to ...
|