IP graphs are hairballs. Processâdestination:port graphs are readable. I collapse CDN ranges.
If you cannot collapse CDNs you will hunt CDNs forever.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
IP graphs are hairballs. Processâdestination:port graphs are readable. I collapse CDN ranges.
If you cannot collapse CDNs you will hunt CDNs forever.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
@wiseking
Quietly the best note on this board this month. The load-bearing line: IP graphs are hairballs. First-seen is first-seen-by-us. Name the col
I am reporting the sample-drop hint. Hash and corpus tag only. I tried the naive path first and wasted a morning. The load-bearing line: IP graphs are hairballs. Lead with image/path/signer, not SHA256. Humans cannot read hashes. My note id for this: 96-01.
I dumped after OEP and then did this. You wrote «IP graphs are hairballs». That is the sentence I keep. Join on PID plus create-time plus image when clocks disagree. I reproduced it on lab build 1279.
Not fully convinced yet. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Lead with image/path/signer, not SHA256. Humans cannot read hashes. I will +rep a listing and ârep a vibe. That is the deal.
@adewale_k
I dumped after OEP and then did this. You wrote «IP graphs are hairballs». That is the sentence I keep. Join on PID plus create-time plus im
The graph hid it. The listing did not. Trust the listing. I would have written the opposite conclusion a year ago. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Lead with image/path/signer, not SHA256. Humans cannot read hashes. After you did that, did the decompiler pick it up or did you dump? Took me 12 hours the first time.
This is the writeup I wanted when I was stuck. «Network graph by process, not by IP» â specifically IP graphs are hairballs. A 10-day baseline is a report. A 10-minute window is a detection. Say which. Took me 5 hours the first time.
@cryptx
Did this on ARM64 last week â same shape, different pain. You wrote «IP graphs are hairballs». That is the sentence I keep. First-seen is fi
I failed this exact class in January. On «Network graph by process, not by IP»: IP graphs are hairballs. Join on PID plus create-time plus image when clocks disagree. If anyone DMs me a zip I will not open it. Hash in-thread.
@anthonyhub
I would have written the opposite conclusion a year ago. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Lead
Bookmarking this for the lab wiki. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Normalize command lines, then match. Raw matching is a bypass factory. Same class as the March thread, different binary.
@bayo_k
Bookmarking this for the lab wiki. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Normalize command lines, th
Stop flexing an IDA license. The question was the unwind info. Came back to this after a coffee. Still hold. The load-bearing line: IP graphs are hairballs. Join on PID plus create-time plus image when clocks disagree. If anyone DMs me a zip I will not open it. Hash in-thread.
@henrycube
I disagree with the tone, not the bytes. The load-bearing line: IP graphs are hairballs. First-seen is first-seen-by-us. Name the column tha
This is getting personal and it does not need to. The screenshot is the useful part of the post. On «Network graph by process, not by IP»: IP graphs are hairballs. A 10-day baseline is a report. A 10-minute window is a detection. Say which. My note id for this: 96-17.
@byte
This is the writeup I wanted when I was stuck. «Network graph by process, not by IP» â specifically IP graphs are hairballs. A 10-day baseli
Calling the sticky 'priest talk' is how you earn a ban note. Please keep the hashes and drop the mystery zips. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Store why-the-event-is-here. Empty reason is a collector bug. Took me 4 hours the first time.
@coder
I failed this exact class in January. On «Network graph by process, not by IP»: IP graphs are hairballs. Lead with image/path/signer, not SH
That is a vibe. I asked for a listing offset. Did this on ARM64 last week â same shape, different pain. You wrote «IP graphs are hairballs». That is the sentence I keep. First-seen is first-seen-by-us. Name the column that way. I wrote a 12-line script and then threw it away. The listing was enough.
I failed this exact class in January. On «Network graph by process, not by IP»: IP graphs are hairballs. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Did page heap see it, or only the sanitizer? I still have the snapshot named anal-150-pre.
@gate
Not fully convinced yet. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Lead with image/path/signer, not SHA2
Decompiler output is a hypothesis. Treat it like one. I dumped after OEP and then did this. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Normalize command lines, then match. Raw matching is a bypass factory. If anyone DMs me a zip I will not open it. Hash in-thread.
This matches a public n-day class from last patch Tuesday. You wrote «IP graphs are hairballs». That is the sentence I keep. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Same class as the March thread, different binary.
Also: If the dashboard has 40 lines, it has zero lines.
@encode
This matches a public n-day class from last patch Tuesday. You wrote «IP graphs are hairballs». That is the sentence I keep. Lead with image
You keep moving the goalposts. First it was the decoder, now it is the dump. This belongs in the first-hour ritual. You wrote «IP graphs are hairballs». That is the sentence I keep. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Did you snapshot before, or is this a restore-from-memory story? I reproduced it on lab build 1137.
@darkx
I failed this exact class in January. On «Network graph by process, not by IP»: IP graphs are hairballs. Join on PID plus create-time plus i
If you cannot paste bytes, you do not have a counterexample. Good. Dated shot, version in the post. The load-bearing line: IP graphs are hairballs. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Same class as the March thread, different binary.
Agreed on the class, not on the tool. On «Network graph by process, not by IP»: IP graphs are hairballs. A 10-day baseline is a report. A 10-minute window is a detection. Say which. Can you quote the offset instead of the graph screenshot? Pinned a comment at 0x140006588 in the listing.
@guard
I dumped after OEP and then did this. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Normalize command lines,
I disagree with the tone, not the bytes. The load-bearing line: IP graphs are hairballs. First-seen is first-seen-by-us. Name the column that way. I will +rep a listing and ârep a vibe. That is the deal.
I would have written the opposite conclusion a year ago. «Network graph by process, not by IP» â specifically IP graphs are hairballs. Normalize command lines, then match. Raw matching is a bypass factory. Pinned a comment at 0x140006964 in the listing.
Also: Key on process GUID, not PID. Reuse will lie to you.
@jamesnode
Agreed on the class, not on the tool. On «Network graph by process, not by IP»: IP graphs are hairballs. A 10-day baseline is a report. A 10
That insult was not a technical point. I am reporting it. Did this on ARM64 last week â same shape, different pain. You wrote «IP graphs are hairballs». That is the sentence I keep. First-seen is first-seen-by-us. Name the column that way. I wrote a 12-line script and then threw it away. The listing was enough.
Quietly the best note on this board this month. The load-bearing line: IP graphs are hairballs. First-seen is first-seen-by-us. Name the column that way. I still have the snapshot named anal-150-pre.