ZombieLucy
banner
zombielucy.bsky.social
ZombieLucy
@zombielucy.bsky.social
(Blog)goblinloot.net
This is nice medium.com/@vanvleet/cr.... In Microsoft Sentinel you can use ingestion_time() to measure delays on ingestion and alert on them.
Creating Resilient Detections
How to make your threat detection queries resilient to ingest delay and query failures.
medium.com
November 22, 2024 at 12:43 PM
Spyware staging before host based data is collected. TCP connection is first used to verify CnC is live before continued execution.

Look out for page permissions and network connections like these in the same tree
April 1, 2024 at 6:23 PM
04a34696c2cf0da7237f395b0eef934880482607d408eb92e6906cce6df1323b
app.malcore.io/share/65f0eeee…

overlap with :bea1d58d168b267c27b1028b47bd6ad19e249630abb7c03cfffede8568749203
March 31, 2024 at 12:30 AM
March 30, 2024 at 10:09 PM
me looking at a closed alert for F_1A33DA file name
September 4, 2023 at 4:09 PM
September 4, 2023 at 4:05 PM
August 13, 2023 at 2:41 PM
August 13, 2023 at 2:41 PM
August 13, 2023 at 2:40 PM
August 13, 2023 at 2:40 PM
August 13, 2023 at 2:39 PM
August 8, 2023 at 6:17 AM
Dismantle the want for entry level analysts
https://www.goblinloot.net/
Goblin Loot
www.goblinloot.net
August 8, 2023 at 6:14 AM