remember when we got a weeks worth of news coverage when Obama called Kanye a jackass?
PDFs have been a constant struggle and I’ve found that this helps. Might be a little biased tho
Proofpoint threat researchers have designed an open-source tool—named PDF Object Hashing—to track and detect the unique characteristics of PDFs used by threat actors... similar to a digital fingerprint. We use this tool internally to help track multiple threat actors with high confidence.
I’ll be presenting at #GrrCON this year about some weird pdf detection ideas I’ve been messing with. Swing by and tell me your file format
Idk about y’all but I don’t plan on giving RU ops a free pass into our customer networks just because some ding dong says they aren’t a threat If anything I might just wanna burn them with more prejudice out of spite for both regimes
Check this episode out to hear about image lures and how we can detect them
New episode of DISCARDED featuring my favorite MS Painter Kyle Eaton 👨🎨 Apple: podcasts.apple.com/us/podcast/d... Spotify: open.spotify.com/episode/5asG... Web: www.buzzsprout.com/2445401/epis...
www.virustotal.com/gui/file/f2a... Also expecting to see indiandefenceforces[.]link soon
VirusTotal
VirusTotal
virustotal.com
departmentofdefence[.]link 🧐
Yara rule to match concatenated zip files. I like this one (biased) because of how we are able to avoid matching nested zip files. More info: x.com/threatinsigh... #yara github.com/EmergingThre...
threatresearch/yara/zip_file.yara at master · EmergingThreats/threatresearch
I wanted to call this repo "Nuclear Football Codes". I was outvoted.. - EmergingThreats/threatresearch
github.com