View Topics

Threat Hunting
5 minutes
Threat Hunting Rule Extraction and Use Cases
Learn how to extract IOCs and behavioral indicators to a hunting rule format for your endpoint security system.

Alert Triage
6 minutes
CrowdStrike + Intezer: Automation for Alert Triage and Threat Hunting
Intezer’s solution for CrowdStrike functions as a virtual Tier 1, removing false positives and giving clear recommendations for every alert.

Alert Triage
2 minutes
macOS Threats: Automate Mac Alert Triage with Intezer
Automatically triage your security alerts about macOS files, processes, and endpoints by integrating with Intezer.

Threat Hunting
5 minutes
Detection Rules for Lightning Framework (and How to Make Them With Osquery)
Get hunting for traces of Lightning Framework, a new Linux threat, using this query pack we made with osquery.

Research
8 minutes
Lightning Framework: New Undetected “Swiss Army Knife” Linux Malware ⚡
A new Linux malware we're calling Lightning Framework has modular plugins and the ability to install multiple types of rootkits.

Incident Response
5 minutes
Autonomous SecOps: Your AI-Driven Tier 1 SOC Team
We are helping security teams go beyond individual file analysis to automate their entire Endpoint and Email alert triage processes with our new dashboard. Autonomous SecOps provides a better, more affordable alternative to in-house Tier 1 teams or external Managed Detection & Response services.

Research
13 minutes
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
OrBit is a new Linux malware that hijacks the execution flow, evading and gaining persistence to get remote access and steal information.

Research
9 minutes
YTStealer Malware: “YouTube Cookies! Om Nom Nom Nom”
YTStealer is a new malware we believe is sold as a service on the Dark Web for stealing authentication cookies from YouTube content creators.

Alert Triage
8 minutes
Needle in a Haystack: Analyzing Every Alert to Find Serious Threats
One of the greatest challenges SOC teams face is the high volume of daily alerts about suspicious files and endpoints to investigate.

Malware Analysis
2 minutes
Summary of Symbiote Research (A New, Nearly-Impossible-to-Detect Linux Threat)

Research
17 minutes
Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat
Symbiote is a new Linux® malware we discovered that acts in a parasitic nature, infecting other running processes to inflict damage on machines.

Threat Hunting
3 minutes
Stay Ahead of the Latest Threats with Threat Family Tracking
Subscribe to threat actors/malware families in Intezer and receive notifications for new IoCs and detection opportunities.

Threat Hunting
10 minutes
SOC Level Up: Threat Hunting and Detection With Sigma
Sigma is a universal markup language for analyzing logs, which you can use to write threat hunting and detection rules for evolving threats.




