NeeRaj Singh

19 posts

NeeRaj Singh

NeeRaj Singh

@_ginnare

Security Researcher @WithSecure

Katılım Ocak 2010
429 Takip Edilen88 Takipçiler
NeeRaj Singh retweetledi
Kazem
Kazem@mkazemhn·
Recently I researched activity from some DPRK baddies called Andariel. The investigation involved 2 set of attacks, a staging server, some new RATs, and tools/TTPs - all attributable to Andariel. The report is now live: labs.withsecure.com/publications/a… #malware #andariel #dprk
English
0
1
1
260
NeeRaj Singh retweetledi
Katie Nickels
Katie Nickels@likethecoins·
A couple thoughts on ATT&CK Evaluations...yes, the marketing is ridiculous. I also hope the useful parts of these evaluations won't get completely lost in that. You can find a lot of insight on tools if you dive into the results. Here are some example questions to consider...
Katie Nickels tweet media
English
3
31
117
15K
NeeRaj Singh retweetledi
Kazem
Kazem@mkazemhn·
🧵 #DUCKTAIL has adapted their infection chain in a short span of time since our latest report was published. I have summarized their latest execution chain in the attached figure. In short:
Kazem tweet media
Yogesh Londhe@suyog41

Ducktail lnk sample c655b7a30f35fb9fe50a7269260d8986 0366e8df2869398541307e42f4547f1f a0d2be72860652716863d51a9811c502 b0c6f0e3338ac66be1ac2505856e2b04 drops svczHost.exe D3E815A620DBC31AEBB4BA85A2DD6E80 C2 : ductai[.]xyz vulinh[.]online #Ducktail #APT #IOC

English
1
8
19
7.4K
NeeRaj Singh retweetledi
Kazem
Kazem@mkazemhn·
1/3 I am happy to share the latest research I had been working on - "Meet the Ducks". We've witnessed an uptick of threat activity surrounding #Meta's ad ecosystem from Vietnam since early 2023 - some highlighted by us as well as other vendors & security researchers in the past.
WithSecure™@WithSecure

NEW RESEARCH: In their latest report, @mkazemhn and @_ginnare dive into Vietnamese cyber crime targeting Meta Business accounts, with specific attention paid to DUCKTAIL & a new threat called DUCKPORT labs.withsecure.com/publications/m… #meettheducks #ducktail #duckport #CyberSecurity

English
1
4
5
2.1K
NeeRaj Singh retweetledi
r0zetta
r0zetta@r0zetta·
Are language model "hallucinations" always useless? Might they be used to generate new research ideas? After all, some of the most interesting developments in machine learning have happened by chance. In this short thread, I'll present some findings on this topic. 1/10
English
1
3
1
3.9K
NeeRaj Singh retweetledi
ATT&CK
ATT&CK@MITREattack·
Let's continue our ATT&CK misunderstandings series & discuss procedures. People sometimes assume ATT&CK is trying to cover every possible way a (sub-)technique can be done, but our procedures only cover what we've seen in public reporting tied to Groups, Software, or Campaigns.
ATT&CK tweet media
English
6
63
132
63.4K
NeeRaj Singh retweetledi
Augusto Barros
Augusto Barros@apbarros·
SOC analysts and detection engineers who like to publicly write/talk about detection content should put out more about the false positives they usually have to deal with. I feel that false positives often suffer from what academics call the "Publication bias"
English
5
14
75
0
NeeRaj Singh retweetledi
Kimberly
Kimberly@StopMalvertisin·
Dark Reading | Internet Searches Reveal Surprisingly Prevalent Ransomware stpmvt.com/3z5Abqd
English
0
1
1
0