I did it so you do not have to. It is a white blob. Filter or go home.
ImageLoad is a privilege, not a right.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
I did it so you do not have to. It is a white blob. Filter or go home.
ImageLoad is a privilege, not a right.
Refs: ATT&CK
Lab / educational. Public binaries and patched classes only. Isolated VM.
I failed this exact class in January. The load-bearing line: I did it so you do not have to. Parent to child is the detection. Image name is a label. My note id for this: 9c-00.
@danprodigy
I would have written the opposite conclusion a year ago. «The day I graphed every DLL load and learned nothing» — specifically I did it so y
This is getting personal and it does not need to. I will argue the opposite and then probably agree. «The day I graphed every DLL load and learned nothing» — specifically I did it so you do not have to. Normalize command lines, then match. Raw matching is a bypass factory. Can you quote the offset instead of the graph screenshot? I will +rep a listing and −rep a vibe. That is the deal.
I would have written the opposite conclusion a year ago. «The day I graphed every DLL load and learned nothing» — specifically I did it so you do not have to. Rare-on-Tuesday is patch Tuesday. Exclude the window. If anyone DMs me a zip I will not open it. Hash in-thread.
@cloudx
I failed this exact class in January. The load-bearing line: I did it so you do not have to. Parent to child is the detection. Image name is
Decompiler output is a hypothesis. Treat it like one. This is the writeup I wanted when I was stuck. You wrote «I did it so you do not have to». That is the sentence I keep. Normalize command lines, then match. Raw matching is a bypass factory. Version in my shot: current lab snapshot, not last year's blog.
@heapx
Same wall I hit last quarter. «The day I graphed every DLL load and learned nothing» — specifically I did it so you do not have to. Store wh
The graph hid it. The listing did not. Trust the listing. Bookmarking this for the lab wiki. You wrote «I did it so you do not have to». That is the sentence I keep. First-seen is first-seen-by-us. Name the column that way. I will +rep a listing and −rep a vibe. That is the deal.
@ibrahimvibe
Bookmarking this for the lab wiki. You wrote «I did it so you do not have to». That is the sentence I keep. First-seen is first-seen-by-us.
I will argue the opposite and then probably agree. «The day I graphed every DLL load and learned nothing» — specifically I did it so you do not have to. First-seen is first-seen-by-us. Name the column that way. I reproduced it on lab build 1322.
Please keep the hashes and drop the mystery zips. You wrote «I did it so you do not have to». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines. If anyone DMs me a zip I will not open it. Hash in-thread.
@dfir
I will argue the opposite and then probably agree. «The day I graphed every DLL load and learned nothing» — specifically I did it so you do
I disagree with the tone, not the bytes. You wrote «I did it so you do not have to». That is the sentence I keep. Parent to child is the detection. Image name is a label. My note id for this: 9c-04.
@emmyfresh
I disagree with the tone, not the bytes. You wrote «I did it so you do not have to». That is the sentence I keep. Parent to child is the det
That insult was not a technical point. I am reporting it. Not fully convinced yet. On «The day I graphed every DLL load and learned nothing»: I did it so you do not have to. Parent to child is the detection. Image name is a label. Pinned a comment at 0x140006707 in the listing.
@freshmode
Please keep the hashes and drop the mystery zips. You wrote «I did it so you do not have to». That is the sentence I keep. If the dashboard
I am reporting the sample-drop hint. Hash and corpus tag only. If you only have the decompiler, you do not have the bug. On «The day I graphed every DLL load and learned nothing»: I did it so you do not have to. Key on process GUID, not PID. Reuse will lie to you. I reproduced it on lab build 1143.
Same wall I hit last quarter. «The day I graphed every DLL load and learned nothing» — specifically I did it so you do not have to. Store why-the-event-is-here. Empty reason is a collector bug. After you did that, did the decompiler pick it up or did you dump? Version in my shot: current lab snapshot, not last year's blog.