Drew
2.4K posts

Drew
@bugfireIO
malware detection and analysis, hunting and gathering, threat research. Views are my own. https://t.co/efJDIXnaLi



🚨 NEW VIDEO DROP FROM PANDA 🐼 I got a full walkthrough of @ThruntingLabs from @Kostastsale and this platform is different - no simulations. You are investigating REAL intrusions with REAL telemetry - query actual EDR logs in Elastic, Splunk, or Azure Log Analytics. If you're in blue team / SOC / IR or aspiring to be - I highly recommend checking it out 🔗 youtube.com/watch?v=YC-E5D…





New 'Zombie ZIP' technique lets malware slip past security tools bleepingcomputer.com/news/security/… bleepingcomputer.com/news/security/…



Using the YARA Language Server to enforce rule metadata standards: virustotal.github.io/yara-x/blog/en…










Don't be fooled by LLM reversing. Yes, they are a great help, but analysis reports are full of tiny and bigger mistakes, even with 5(!) validation passes. Which means you can't trust them. Which means you have to validate everything.





