Thank you! I havenβt looked into writing yara x modules yet, but was thinking about a strelka scanner. Def going to see about yara x now though thatβs a great idea
23.10.2025 19:00 β π 1 π 0 π¬ 1 π 0@0xkyle.bsky.social
phishing, maldocs, threat intel
Thank you! I havenβt looked into writing yara x modules yet, but was thinking about a strelka scanner. Def going to see about yara x now though thatβs a great idea
23.10.2025 19:00 β π 1 π 0 π¬ 1 π 0PDFs have been a constant struggle and Iβve found that this helps. Might be a little biased tho
23.10.2025 18:19 β π 3 π 2 π¬ 1 π 0Iβll be presenting at #GrrCON this year about some weird pdf detection ideas Iβve been messing with. Swing by and tell me your file format
30.09.2025 13:40 β π 3 π 1 π¬ 0 π 0People love people who use ms paint.
13.06.2025 20:34 β π 0 π 0 π¬ 1 π 0Itβs a strong bug.
We donβt need AI for shitty art
30.05.2025 00:32 β π 4 π 1 π¬ 0 π 0Idk about yβall but I donβt plan on giving RU ops a free pass into our customer networks just because some ding dong says they arenβt a threat
If anything I might just wanna burn them with more prejudice out of spite for both regimes
QR codes can be tricky just because the benign and malicious ones can be very similar. But you can use something like halogen to help generate the yara rules for testing it out. github.com/target/halogen
26.02.2025 23:28 β π 3 π 0 π¬ 1 π 0Check this episode out to hear about image lures and how we can detect them
25.02.2025 17:57 β π 5 π 1 π¬ 2 π 0www.virustotal.com/gui/file/f2a...
Also expecting to see indiandefenceforces[.]link soon
Havenβt seen PDFs for this yet but a new domain popped: defenceindia[.]link
04.02.2025 14:10 β π 0 π 0 π¬ 0 π 0departmentofdefence[.]link π§
30.01.2025 13:37 β π 0 π 0 π¬ 1 π 1Yara rule to match concatenated zip files. I like this one (biased) because of how we are able to avoid matching nested zip files.
More info: x.com/threatinsigh...
#yara github.com/EmergingThre...