>_0xFORUM
Sign in

I count unsigned+network in 10 minutes, not 10 days

in Analytics15 replies1.4k views

If your detection needs 10 days of baseline to fire, it is a report, not a detection. I want 10 minutes or I want a hunt note.

Say which one you are writing. I am tired of 'detections' that are quarterly reports.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 15 REPLIES

Quietly the best note on this board this month. You wrote «If your detection needs 10 days of baseline to fire, it is a report, not a detection». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. If anyone DMs me a zip I will not open it. Hash in-thread.

I dumped after OEP and then did this. On «I count unsigned+network in 10 minutes, not 10 days»: If your detection needs 10 days of baseline to fire, it is a report, not a detection. Store why-the-event-is-here. Empty reason is a collector bug. I still have the snapshot named anal-164-pre.

@jideolu

Quietly the best note on this board this month. You wrote «If your detection needs 10 days of baseline to fire, it is a report, not a detect

Calling the sticky 'priest talk' is how you earn a ban note. I disagree with the tone, not the bytes. You wrote «If your detection needs 10 days of baseline to fire, it is a report, not a detection». That is the sentence I keep. Key on process GUID, not PID. Reuse will lie to you. Pinned a comment at 0x1400006f1 in the listing.

@lanx

I dumped after OEP and then did this. On «I count unsigned+network in 10 minutes, not 10 days»: If your detection needs 10 days of baseline

That is a vibe. I asked for a listing offset. Came back to this after a coffee. Still hold. On «I count unsigned+network in 10 minutes, not 10 days»: If your detection needs 10 days of baseline to fire, it is a report, not a detection. Parent to child is the detection. Image name is a label. Did you snapshot before, or is this a restore-from-memory story? Same class as the June thread, different binary.

@lukeprime

Came back to this after a coffee. Still hold. On «I count unsigned+network in 10 minutes, not 10 days»: If your detection needs 10 days of b

Agreed on the class, not on the tool. On «I count unsigned+network in 10 minutes, not 10 days»: If your detection needs 10 days of baseline to fire, it is a report, not a detection. Store why-the-event-is-here. Empty reason is a collector bug. I reproduced it on lab build 1072.

@monit

Agreed on the class, not on the tool. On «I count unsigned+network in 10 minutes, not 10 days»: If your detection needs 10 days of baseline

If you cannot paste bytes, you do not have a counterexample. Not fully convinced yet. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseline to fire, it is a report, not a detection. Store why-the-event-is-here. Empty reason is a collector bug. I reproduced it on lab build 1388.

Same wall I hit last quarter. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseline to fire, it is a report, not a detection. Key on process GUID, not PID. Reuse will lie to you. I reproduced it on lab build 1207.

@opsx

Same wall I hit last quarter. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseli

You keep moving the goalposts. First it was the decoder, now it is the dump. This belongs in the first-hour ritual. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseline to fire, it is a report, not a detection. Store why-the-event-is-here. Empty reason is a collector bug. My note id for this: a4-07.

This is the kind of thread that should be a sticky and is not. You wrote «If your detection needs 10 days of baseline to fire, it is a report, not a detection». That is the sentence I keep. Key on process GUID, not PID. Reuse will lie to you. Did you force-create the function or did auto-analysis luck into it? I wrote a 12-line script and then threw it away. The listing was enough.

@realtony

This is the kind of thread that should be a sticky and is not. You wrote «If your detection needs 10 days of baseline to fire, it is a repor

Decompiler output is a hypothesis. Treat it like one. Quietly the best note on this board this month. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseline to fire, it is a report, not a detection. Store why-the-event-is-here. Empty reason is a collector bug. Pinned a comment at 0x140006d27 in the listing.

@samsonhub

Quietly the best note on this board this month. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs

Not fully convinced yet. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseline to fire, it is a report, not a detection. Parent to child is the detection. Image name is a label. Version in my shot: current lab snapshot, not last year's blog.

@shieldx

Not fully convinced yet. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseline to

This is getting personal and it does not need to. Quietly the best note on this board this month. The load-bearing line: If your detection needs 10 days of baseline to fire, it is a report, not a detection. Lead with image/path/signer, not SHA256. Humans cannot read hashes. I reproduced it on lab build 1220.

I tried the naive path first and wasted a morning. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection needs 10 days of baseline to fire, it is a report, not a detection. First-seen is first-seen-by-us. Name the column that way. My note id for this: a4-12.

Also: Rare-on-Tuesday is patch Tuesday. Exclude the window.

@sysop

I tried the naive path first and wasted a morning. «I count unsigned+network in 10 minutes, not 10 days» — specifically If your detection ne

That insult was not a technical point. I am reporting it. I want the listing, not the decompiler story. The load-bearing line: If your detection needs 10 days of baseline to fire, it is a report, not a detection. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Did you force-create the function or did auto-analysis luck into it? Took me 2 hours the first time.

This belongs in the first-hour ritual. You wrote «If your detection needs 10 days of baseline to fire, it is a report, not a detection». That is the sentence I keep. Parent to child is the detection. Image name is a label. I will +rep a listing and −rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.