Malware Intelligence (MALINT): Intelligence Discipline Guide
A malware sample is a confession. It documents what its author wanted, how they build software, and where they expect...
A malware sample is a confession. It documents what its author wanted, how they build software, and where they expect...
Domains are the cheapest and most disposable part of an attack, and the most revealing. Registration and DNS leave a...
Cyber intelligence is what turns telemetry into a story about an adversary. Without it you have logs. With it you...
Every publicly trusted TLS certificate is logged in public within seconds of issuance. That log is one of the richest...
You cannot defend what you do not know you own. Attack surface intelligence is the discipline of inventorying your exposed...
Investigations are compromised by their own footprint far more often than by adversary brilliance. A referrer header, a reused persona,...
A hash tells you a file was seen. A configuration extraction tells you the campaign identifier, the operator's infrastructure and,...
The median intrusion that matters is not loud. It is a valid credential, a legitimate administrative tool and eleven months...
State activity rarely arrives labelled. It surfaces as a procurement order routed through a third-country freight forwarder, a research institute...