Blog

Filter: threat hunting - Clear Filter

New THOR Cloud Log Inspection View

New THOR Cloud Log Inspection View

Faster. Cleaner. More focused review. Reviewing large THOR scan reports can be time-consuming, especially when analysts need to quickly understand why a detection was triggered, identify the affected artifact, and separate signal from noise. To make this process...

read more

New Analysis Cockpit 3.5

New Baselining Views Over the course of the last 18 months we reviewed most of our detections regarding their success in real world scenarios. In this context "success" means, that the detection uncovered malicious activity in the wild and at the same time had a low...

read more

50 Shades of YARA

A long time ago I've noticed that there is no single best YARA rule for a given sample, but different best solutions depending on the user's requirements and use case. I noticed that I often create 2 to 3 YARA rules for a single sample that I process, while each of...

read more