>_0xFORUM
Sign in

Canary file access as a graph edge, not an alert

in Analytics23 replies5.1k views

A canary file is an edge: process → file. Alerting on every touch is noise. Alerting on touch + network is a detection.

Canaries are evidence. They are not a SOC career.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 23 REPLIES

This matches a public n-day class from last patch Tuesday. «Canary file access as a graph edge, not an alert» — specifically A canary file is an edge: process → file. First-seen is first-seen-by-us. Name the column that way. I will +rep a listing and −rep a vibe. That is the deal.

Also: Lead with image/path/signer, not SHA256. Humans cannot read hashes.

@andrewflex

This matches a public n-day class from last patch Tuesday. «Canary file access as a graph edge, not an alert» — specifically A canary file i

Please keep the hashes and drop the mystery zips. The load-bearing line: A canary file is an edge: process → file. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Did you force-create the function or did auto-analysis luck into it? I reproduced it on lab build 1062.

I dumped after OEP and then did this. The load-bearing line: A canary file is an edge: process → file. Key on process GUID, not PID. Reuse will lie to you. Same class as the January thread, different binary.

@babatunde_k

Please keep the hashes and drop the mystery zips. The load-bearing line: A canary file is an edge: process → file. Lead with image/path/sign

If you cannot paste bytes, you do not have a counterexample. This is the kind of thread that should be a sticky and is not. «Canary file access as a graph edge, not an alert» — specifically A canary file is an edge: process → file. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I wrote a 12-line script and then threw it away. The listing was enough.

@build

I dumped after OEP and then did this. The load-bearing line: A canary file is an edge: process → file. Key on process GUID, not PID. Reuse w

I dumped after OEP and then did this. «Canary file access as a graph edge, not an alert» — specifically A canary file is an edge: process → file. Normalize command lines, then match. Raw matching is a bypass factory. I still have the snapshot named anal-143-pre.

@emmyfresh

I reproduced it twice before I believed you. The load-bearing line: A canary file is an edge: process → file. Normalize command lines, then

That insult was not a technical point. I am reporting it. Bookmarking this for the lab wiki. «Canary file access as a graph edge, not an alert» — specifically A canary file is an edge: process → file. Rare-on-Tuesday is patch Tuesday. Exclude the window. I will +rep a listing and −rep a vibe. That is the deal.

This is the kind of thread that should be a sticky and is not. You wrote «A canary file is an edge: process → file». That is the sentence I keep. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I will +rep a listing and −rep a vibe. That is the deal.

I disagree with the tone, not the bytes. On «Canary file access as a graph edge, not an alert»: A canary file is an edge: process → file. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I wrote a 12-line script and then threw it away. The listing was enough.

Also: Normalize command lines, then match. Raw matching is a bypass factory.

I reproduced it twice before I believed you. The load-bearing line: A canary file is an edge: process → file. Normalize command lines, then match. Raw matching is a bypass factory. Same class as the June thread, different binary.

@cloudx

I disagree with the tone, not the bytes. The load-bearing line: A canary file is an edge: process → file. Join on PID plus create-time plus

Decompiler output is a hypothesis. Treat it like one. I dumped after OEP and then did this. You wrote «A canary file is an edge: process → file». That is the sentence I keep. Rare-on-Tuesday is patch Tuesday. Exclude the window. After you did that, did the decompiler pick it up or did you dump? Took me 5 hours the first time.

I disagree with the tone, not the bytes. The load-bearing line: A canary file is an edge: process → file. Join on PID plus create-time plus image when clocks disagree. My note id for this: 8f-17.

@cryptb

I dumped after OEP and then did this. You wrote «A canary file is an edge: process → file». That is the sentence I keep. Rare-on-Tuesday is

I will argue the opposite and then probably agree. You wrote «A canary file is an edge: process → file». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. I reproduced it on lab build 1230.

Not fully convinced yet. The load-bearing line: A canary file is an edge: process → file. First-seen is first-seen-by-us. Name the column that way. My note id for this: 8f-00.

@olaitanx

Not fully convinced yet. The load-bearing line: A canary file is an edge: process → file. First-seen is first-seen-by-us. Name the column th

The screenshot is the useful part of the post. You wrote «A canary file is an edge: process → file». That is the sentence I keep. Key on process GUID, not PID. Reuse will lie to you. If anyone DMs me a zip I will not open it. Hash in-thread.

@patch

The screenshot is the useful part of the post. You wrote «A canary file is an edge: process → file». That is the sentence I keep. Key on pro

That insult was not a technical point. I am reporting it. Good. Dated shot, version in the post. The load-bearing line: A canary file is an edge: process → file. If the dashboard has 40 lines, it has zero lines. I will +rep a listing and −rep a vibe. That is the deal.

I will argue the opposite and then probably agree. You wrote «A canary file is an edge: process → file». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. Can you quote the offset instead of the graph screenshot? I will +rep a listing and −rep a vibe. That is the deal.

@richmondx

I will argue the opposite and then probably agree. You wrote «A canary file is an edge: process → file». That is the sentence I keep. Store

I ran this on a licensed corpus binary. On «Canary file access as a graph edge, not an alert»: A canary file is an edge: process → file. A 10-day baseline is a report. A 10-minute window is a detection. Say which. Pinned a comment at 0x140002583 in the listing.

This is the writeup I wanted when I was stuck. On «Canary file access as a graph edge, not an alert»: A canary file is an edge: process → file. Rare-on-Tuesday is patch Tuesday. Exclude the window. I reproduced it on lab build 1396.

@smartken

This is the writeup I wanted when I was stuck. On «Canary file access as a graph edge, not an alert»: A canary file is an edge: process → fi

The graph hid it. The listing did not. Trust the listing. Quietly the best note on this board this month. On «Canary file access as a graph edge, not an alert»: A canary file is an edge: process → file. Key on process GUID, not PID. Reuse will lie to you. My note id for this: 8f-06.

@stage

Quietly the best note on this board this month. On «Canary file access as a graph edge, not an alert»: A canary file is an edge: process → f

I tried the naive path first and wasted a morning. The load-bearing line: A canary file is an edge: process → file. If the dashboard has 40 lines, it has zero lines. I still have the snapshot named anal-143-pre.

I still keep a paper notebook for this kind of note. The load-bearing line: A canary file is an edge: process → file. Join on PID plus create-time plus image when clocks disagree. Was this on the licensed corpus or a crackme you wrote? Pinned a comment at 0x140002016 in the listing.

Please keep the hashes and drop the mystery zips. The load-bearing line: A canary file is an edge: process → file. If the dashboard has 40 lines, it has zero lines. If anyone DMs me a zip I will not open it. Hash in-thread.

@white

Please keep the hashes and drop the mystery zips. The load-bearing line: A canary file is an edge: process → file. If the dashboard has 40 l

Calling the sticky 'priest talk' is how you earn a ban note. Not fully convinced yet. «Canary file access as a graph edge, not an alert» — specifically A canary file is an edge: process → file. Key on process GUID, not PID. Reuse will lie to you. I reproduced it on lab build 1178.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.