>_0xFORUM
Sign in

I want a 'why this is here' field on every stored event

in Analytics12 replies332 views

reason=unsigned_child | canary_touch | sampled. If reason is empty, the collector has a bug.

Provenance of telemetry is telemetry.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 12 REPLIES

I tried the naive path first and wasted a morning. The load-bearing line: reason=unsigned_child | canary_touch | sampled. Rare-on-Tuesday is patch Tuesday. Exclude the window. I will +rep a listing and −rep a vibe. That is the deal.

@zenx

The screenshot is the useful part of the post. You wrote «reason=unsigned_child | canary_touch | sampled». That is the sentence I keep. Norm

You keep moving the goalposts. First it was the decoder, now it is the dump. Quietly the best note on this board this month. «I want a 'why this is here' field on every stored event» — specifically reason=unsigned_child | canary_touch | sampled. If the dashboard has 40 lines, it has zero lines. If anyone DMs me a zip I will not open it. Hash in-thread.

@null

I tried the naive path first and wasted a morning. The load-bearing line: reason=unsigned_child | canary_touch | sampled. Rare-on-Tuesday is

The graph hid it. The listing did not. Trust the listing. This is the writeup I wanted when I was stuck. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_touch | sampled. Parent to child is the detection. Image name is a label. If anyone DMs me a zip I will not open it. Hash in-thread.

Agreed on the class, not on the tool. You wrote «reason=unsigned_child | canary_touch | sampled». That is the sentence I keep. Normalize command lines, then match. Raw matching is a bypass factory. I still have the snapshot named anal-168-pre.

@primealex

Agreed on the class, not on the tool. You wrote «reason=unsigned_child | canary_touch | sampled». That is the sentence I keep. Normalize com

Stop flexing an IDA license. The question was the unwind info. I ran this on a licensed corpus binary. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_touch | sampled. Parent to child is the detection. Image name is a label. Was this on the licensed corpus or a crackme you wrote? Version in my shot: current lab snapshot, not last year's blog.

@resrch

I ran this on a licensed corpus binary. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_touch |

I disagree with the tone, not the bytes. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_touch | sampled. If the dashboard has 40 lines, it has zero lines. Same class as the October thread, different binary.

@sbox

I disagree with the tone, not the bytes. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_touch

Calling the sticky 'priest talk' is how you earn a ban note. Not fully convinced yet. You wrote «reason=unsigned_child | canary_touch | sampled». That is the sentence I keep. First-seen is first-seen-by-us. Name the column that way. I wrote a 12-line script and then threw it away. The listing was enough.

Quietly the best note on this board this month. The load-bearing line: reason=unsigned_child | canary_touch | sampled. Store why-the-event-is-here. Empty reason is a collector bug. I wrote a 12-line script and then threw it away. The listing was enough.

@stack

Quietly the best note on this board this month. The load-bearing line: reason=unsigned_child | canary_touch | sampled. Store why-the-event-i

That is a vibe. I asked for a listing offset. This matches a public n-day class from last patch Tuesday. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_touch | sampled. Join on PID plus create-time plus image when clocks disagree. If anyone DMs me a zip I will not open it. Hash in-thread.

Good. Dated shot, version in the post. The load-bearing line: reason=unsigned_child | canary_touch | sampled. Key on process GUID, not PID. Reuse will lie to you. Is the hang the incomplete patch, or a second bug? Same class as the October thread, different binary.

@vectrx

Good. Dated shot, version in the post. The load-bearing line: reason=unsigned_child | canary_touch | sampled. Key on process GUID, not PID.

If you cannot paste bytes, you do not have a counterexample. This is the writeup I wanted when I was stuck. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_touch | sampled. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I reproduced it on lab build 1114.

@wanx

This is the writeup I wanted when I was stuck. On «I want a 'why this is here' field on every stored event»: reason=unsigned_child | canary_

The screenshot is the useful part of the post. You wrote «reason=unsigned_child | canary_touch | sampled». That is the sentence I keep. Normalize command lines, then match. Raw matching is a bypass factory. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.