OpenFraudMonitoring V1.0
A follow-up to my OpenFraudMonitoring presentation, covering two new features built to empower investigations: a graph view for correlating sessions, and behavioral fingerprinting with behavior-based risk rules.
A follow-up to my OpenFraudMonitoring presentation, covering two new features built to empower investigations: a graph view for correlating sessions, and behavioral fingerprinting with behavior-based risk rules.
Technical analysis of a recent UNC1151 (GhostWriter) campaign targeting Ukrainian entities. Covers deobfuscation of the OYSTERFRESH dropper and OYSTERBLUES backdoor, CTI infrastructure hunting, and a MITRE ATT&CK technique mapping.
This blog post describes my latest development project, which is a Fraud Monitoring solution that fingerprints users and enables the detection of Threat Actors. I give an example of how it enabled me to discover malicious behavior on one of my selfhosted microservices.
This report documents the internals of the V7.4 builder of Xworm, and analyzes various samples compiled with all available flags in order to understand the implementation methods of the malware. A YARA detection rule and a MITRE ATT&CK technique mapping are provided.