>_0xFORUM
Sign in

Time buckets: 1s vs 1m vs 1h for the same detection

in Analytics20 replies2.5k views

A burst in 1s is an exploit attempt. In 1h it is a backup job. I keep all three buckets for one rule and I am not sorry.

If your backend cannot do three buckets, your backend is a log dump.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 20 REPLIES

Not fully convinced yet. The load-bearing line: A burst in 1s is an exploit attempt. Store why-the-event-is-here. Empty reason is a collector bug. I reproduced it on lab build 1043.

@ctrlx

Not fully convinced yet. The load-bearing line: A burst in 1s is an exploit attempt. Store why-the-event-is-here. Empty reason is a collecto

Agreed on the class, not on the tool. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. A 10-day baseline is a report. A 10-minute window is a detection. Say which. Pinned a comment at 0x140004f07 in the listing.

@ericjay

I ran this on a licensed corpus binary. The load-bearing line: A burst in 1s is an exploit attempt. Parent to child is the detection. Image

I ran this on a licensed corpus binary. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. A 10-day baseline is a report. A 10-minute window is a detection. Say which. Took me 11 hours the first time.

@davidtrend

Agreed on the class, not on the tool. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. A 10-da

Stop flexing an IDA license. The question was the unwind info. Bookmarking this for the lab wiki. The load-bearing line: A burst in 1s is an exploit attempt. Normalize command lines, then match. Raw matching is a bypass factory. Took me 7 hours the first time.

I ran this on a licensed corpus binary. The load-bearing line: A burst in 1s is an exploit attempt. Parent to child is the detection. Image name is a label. After you did that, did the decompiler pick it up or did you dump? Version in my shot: current lab snapshot, not last year's blog.

@gammx

I ran this on a licensed corpus binary. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. Lead

That is a vibe. I asked for a listing offset. I will argue the opposite and then probably agree. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an exploit attempt. Join on PID plus create-time plus image when clocks disagree. Took me 4 hours the first time.

@logsec

Quietly the best note on this board this month. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an exp

This is the kind of thread that should be a sticky and is not. You wrote «A burst in 1s is an exploit attempt». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines. Is the hang the incomplete patch, or a second bug? I wrote a 12-line script and then threw it away. The listing was enough.

I ran this on a licensed corpus binary. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. Lead with image/path/signer, not SHA256. Humans cannot read hashes. My note id for this: 9d-05.

@jaydenhub

I disagree with the tone, not the bytes. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an exploit at

You keep moving the goalposts. First it was the decoder, now it is the dump. Same wall I hit last quarter. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. Normalize command lines, then match. Raw matching is a bypass factory. My note id for this: 9d-10.

Quietly the best note on this board this month. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an exploit attempt. Normalize command lines, then match. Raw matching is a bypass factory. I still have the snapshot named anal-157-pre.

Also: A 10-day baseline is a report. A 10-minute window is a detection. Say which.

I failed this exact class in January. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an exploit attempt. A 10-day baseline is a report. A 10-minute window is a detection. Say which. What did you key the join on — PID or process GUID? I will +rep a listing and −rep a vibe. That is the deal.

@guardz

I will argue the opposite and then probably agree. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an

Did this on ARM64 last week — same shape, different pain. The load-bearing line: A burst in 1s is an exploit attempt. Key on process GUID, not PID. Reuse will lie to you. Same class as the March thread, different binary.

I disagree with the tone, not the bytes. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an exploit attempt. If the dashboard has 40 lines, it has zero lines. Took me 2 hours the first time.

Good. Dated shot, version in the post. The load-bearing line: A burst in 1s is an exploit attempt. If the dashboard has 40 lines, it has zero lines. If anyone DMs me a zip I will not open it. Hash in-thread.

@modelz

This is the kind of thread that should be a sticky and is not. You wrote «A burst in 1s is an exploit attempt». That is the sentence I keep.

This is getting personal and it does not need to. Same wall I hit last quarter. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. Key on process GUID, not PID. Reuse will lie to you. My note id for this: 9d-14.

This is the writeup I wanted when I was stuck. You wrote «A burst in 1s is an exploit attempt». That is the sentence I keep. First-seen is first-seen-by-us. Name the column that way. I reproduced it on lab build 1171.

@omegax

This is the writeup I wanted when I was stuck. You wrote «A burst in 1s is an exploit attempt». That is the sentence I keep. First-seen is f

Please keep the hashes and drop the mystery zips. The load-bearing line: A burst in 1s is an exploit attempt. Join on PID plus create-time plus image when clocks disagree. Pinned a comment at 0x140004095 in the listing.

Came back to this after a coffee. Still hold. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt. First-seen is first-seen-by-us. Name the column that way. I still have the snapshot named anal-157-pre.

@realchris

Came back to this after a coffee. Still hold. On «Time buckets: 1s vs 1m vs 1h for the same detection»: A burst in 1s is an exploit attempt.

I am reporting the sample-drop hint. Hash and corpus tag only. Did this on ARM64 last week — same shape, different pain. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s is an exploit attempt. Normalize command lines, then match. Raw matching is a bypass factory. Is the hang the incomplete patch, or a second bug? Version in my shot: current lab snapshot, not last year's blog.

@sadiqcrest

Did this on ARM64 last week — same shape, different pain. «Time buckets: 1s vs 1m vs 1h for the same detection» — specifically A burst in 1s

I failed this exact class in January. You wrote «A burst in 1s is an exploit attempt». That is the sentence I keep. Rare-on-Tuesday is patch Tuesday. Exclude the window. I reproduced it on lab build 1032.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.