Kyle Eaton's Avatar

Kyle Eaton

@0xkyle.bsky.social

phishing, maldocs, threat intel

133 Followers  |  64 Following  |  12 Posts  |  Joined: 06.08.2023  |  1.6397

Latest posts by 0xkyle.bsky.social on Bluesky

Thank you! I haven’t looked into writing yara x modules yet, but was thinking about a strelka scanner. Def going to see about yara x now though that’s a great idea

23.10.2025 19:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

PDFs have been a constant struggle and I’ve found that this helps. Might be a little biased tho

23.10.2025 18:19 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

I’ll be presenting at #GrrCON this year about some weird pdf detection ideas I’ve been messing with. Swing by and tell me your file format

30.09.2025 13:40 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

People love people who use ms paint.

13.06.2025 20:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
It’s a strong bug.

It’s a strong bug.

We don’t need AI for shitty art

30.05.2025 00:32 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
a man in an apron is cooking in a kitchen with a sign on the wall that says no smoking ALT: a man in an apron is cooking in a kitchen with a sign on the wall that says no smoking

Cooking up signatures

05.03.2025 22:25 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Idk about y’all but I don’t plan on giving RU ops a free pass into our customer networks just because some ding dong says they aren’t a threat

If anything I might just wanna burn them with more prejudice out of spite for both regimes

01.03.2025 14:29 β€” πŸ‘ 36    πŸ” 9    πŸ’¬ 3    πŸ“Œ 3
Preview
GitHub - target/halogen: Automatically create YARA rules from malicious documents. Automatically create YARA rules from malicious documents. - GitHub - target/halogen: Automatically create YARA rules from malicious documents.

QR codes can be tricky just because the benign and malicious ones can be very similar. But you can use something like halogen to help generate the yara rules for testing it out. github.com/target/halogen

26.02.2025 23:28 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Check this episode out to hear about image lures and how we can detect them

25.02.2025 17:57 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 2    πŸ“Œ 0

www.virustotal.com/gui/file/f2a...

Also expecting to see indiandefenceforces[.]link soon

10.02.2025 18:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Haven’t seen PDFs for this yet but a new domain popped: defenceindia[.]link

04.02.2025 14:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

departmentofdefence[.]link 🧐

30.01.2025 13:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 1
Preview
threatresearch/yara/zip_file.yara at master Β· EmergingThreats/threatresearch I wanted to call this repo "Nuclear Football Codes". I was outvoted.. - EmergingThreats/threatresearch

Yara rule to match concatenated zip files. I like this one (biased) because of how we are able to avoid matching nested zip files.

More info: x.com/threatinsigh...

#yara github.com/EmergingThre...

19.11.2024 21:09 β€” πŸ‘ 15    πŸ” 7    πŸ’¬ 2    πŸ“Œ 1

@0xkyle is following 20 prominent accounts