If you need me I'll be in the Andromeda Galaxy
Steve YARA Synapse Miller
@stvemillertime.bsky.social
threat intelligence @google writing & sharing on adversary tradecraft, malware, threat detection, ics/ot + cyber physical intel, and of course all things #yara
Imo the security product market is almost always a decade behind needs, but over time ends up being pulled to meet the adversary where they are operating. In the 2010s the market came late to the endpoint, in the 2020s late to the cloud, in the 2030s it'll be back to the network.
My top 5 movies about ~hacking probably say more about my age than anything else, but still: #1 - Hackers (1995) #2 - War Games (1983) #3 - Johnny Mnemonic (1995) #4 - Ghost in the Shell (1995) #5 - Office Space (1999) <- surprisingly full of hacks
The Wire, but a cybercrime version of it
imo, great defenders think like attackers and great attackers think like defenders and great security folks think like both and great intelligence folks think like neither beep boop computers
I used to secretly judge folks that don't *love* music. But I learned that not everyone has the same ability to _detect_ musical features (pitch, rhythm, harmony etc). This happens not in the ear but in the brain. W/ diff neuro wiring & genes, folks don't always hear what I hear.
"The game is out there, and it's either play or get played." - Omar
Which of the Warhammer 40K races and factions should I get into? Sisters of Battle? Space Wolves? Henry Cavill?
Really neat exposé on RDP tradecraft to include signed .rdp configs, resource redirection, RemoteApps and probably PyRDP. cloud.google.com/blog/topics/...
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
cloud.google.com
Excellent breakdown of the “Rogue RDP” TTP we’ve seen susp Russian APT UNC5837 using in their campaigns written by my colleague Rohit (@IzySec over on X)
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
cloud.google.com
Introducing MalChela. A YARA and Malware Analysis utility written in Rust. #DFIR #MalwareAnalysis #YARA #Hashing
MalChela – A YARA and Malware Analysis Toolkit written in Rust
Saturday was for Python. Sunday was for Rust. After my success with the Python + YARA + Hashing, I decided to take things to the next level. Over the past few years I've created a number of Python and PowerShell scripts related to YARA and Malware Analysis. What if I combined them into a single utility? While we're at it, let's rewrite them all from scratch in Rust.
bakerstreetforensics.com
Seeing these scrips run brings me joy. #DFIR #MalwareAnalysis #Python #YARA
Creating custom hash sets with YARA and Python I don't like to brag, he said, but you should see the size of my malware library. For a recent project, I wanted to produce a hash set for all the malware files in my repository. Included in the library are malware samples for Windows and other…
Creating custom hash sets with YARA and Python I don't like to brag, he said, but you should see the size of my malware library. For a recent project, I wanted to produce a hash set for all the malware files in my repository. Included in the library are malware samples for Windows and other…
Creating custom hash sets with YARA and Python
I don't like to brag, he said, but you should see the size of my malware library. For a recent project, I wanted to produce a hash set for all the malware files in my repository. Included in the library are malware samples for Windows and other platforms. Within the library there are also a lot of pdf's with write ups corresponding to different samples.
bakerstreetforensics.com
Do not despair, my friends, the only way out is through; And the climate will probably kill us all pretty soon anyway
SSH is the cyber blood magick of both the world's most stalwart orgs and the world's toughest adversaries.
You’re an MSS or SVR cyber targeter who’s spent years trying to find an access vector into SPS/PAM; then suddenly a pack of high-profile, right-wing, edgelord zoomers — who will definitely click on any link they think will get them laid — just get admin access. Prepositioning acquisition speedrun.
Years of mediocre gen AI commodities will birth a generation of neo-luddites who refuse to delegate the joys of art, music, writing & human connection to machines. They'll sketch, read human-gen pBooks, buy vinyls at concerts, share hand-written original pre-trend non-memes.
If you want to test out my YARA rule linting work use this PR: github.com/VirusTotal/y... If you want to get the basic gist of it, this config file change has documentation on it: github.com/VirusTotal/y... Just set it in your config file and use "yr check" for now. Happy #100DaysOfYARA. ;)
Which subscription news services do you pay for? I want premium, non content farm, mostly human-written science, tech, security news. I'm considering things like The Information, 404 media, MIT Tech Review, etc, but looking for recommendations. (I get NYT, AP, Reuters already)
A unique finding, a novel artifact, a hidden curio, a piece of something yet unknown to the world. With each discovery comes a bewitching temptation to believe you alone know a secret, and own it.
In your opinion, what are the differences between cyber security journalism and cyber threat intelligence?
come to think of it, it's actually pretty easy; probably can be simplified but I wanted 4 chars as anchors at the front
How would you detect something like this, generically? SOFT_WARE\Micros_oft\Win_dows\Curr_entVer_sion\Ru_n
Lovely creature comforts in YARA-X such as basic stats for scanned, match number and time. 502551 file(s) scanned in 35.8s. 0 file(s) matched.
I often use my personal SIGINT experiences to describe CN APT groups, and rightly accused of mirroring bias. Still, CN has been pillaging and imitating us for decades, so if you want to see what they're up to today on the CNO front, look at what the IC was doing 10+ years ago.
There is no "right" way to write YARA rules. You may dislike my rule format preferences or content decisions, just as I might dislike your document with bland vocabulary, unimaginative prose. There are ineffective ways to use YARA, but there's no right way. Find your style.