all blogs

Explore our blog

AI SOC

AI

Company News

5 minutes

Loop engineering comes to the SOC: Introducing the Intezer Org Brain

Organizational context in an AI SOC is table stakes. Org Brain is very different. It learns, it recalls, it fetches what it's missing, and it gets sharper with every alert it touches, all autonomously.

Itai Tevet

Detection Engineering

AI SOC

8 minutes

Detection engineering in the AI era

AI is lowering the barrier to sophisticated attacks. Explore why detection engineering matters and where most programs fall short.

Zev Schonberg

View Topics
SOAR
MDR
AI SOC
Detection Engineering
Threat Hunting
Threat Bulletin
The SecOps Automation Blog
SOC
Research
Malware Analysis
Knowledge Base
Incident Response
Company News
Cloud Security
CISO
Alert Triage
AI
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Reset
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Malware Analysis

8 minutes

ELF Malware Analysis 101: Linux Threats No Longer an Afterthought

Practice ELF malware analysis hands-on. Attackers have targeted the Linux OS aggressively in recent years.

Malware Analysis

2 minutes

Mapping Binaries Inside a Microsoft Azure Cloud Server

This interactive map allows you to explore the code sharing relationship between all binary files in a standard Azure Ubuntu cloud server.

Research

6 minutes

The Evolution of APT15’s Codebase 2020

The Ke3chang group continues to alter its code and substitute basic functionalities in its backdoors.

Cloud Security

3 minutes

Exploitation of SaltStack Vulnerabilities Signals Increase in Cloud Server Attacks

The recent exploitation of SaltStack vulnerabilities signals an increase in cloud server attacks.

Malware Analysis

1 minute

Intezer Analyze community roundup

Maze ransomware and APT41 highlight this month's community samples. Join the free Intezer Analyze community to detect malicious software in seconds.

Malware Analysis

2 minutes

Malicious APKs share code during Covid-19 pandemic

-1331

Cloud Security

4 minutes

Pre-runtime vulnerability scans or runtime protection: Which is better for your IaaS security?

Under Armour’s famous slogan sums up the mission perfectly: We Must Protect this House. But how do security teams protect their Infrastructure as a Service (IaaS) while acknowledging the cloud has unique performance needs?

Research

2 minutes

TTPs matrix for Linux cloud servers

Taking inspiration from the MITRE ATT&CK® framework, we have developed a matrix categorizing adversary tactics and techniques for Linux cloud servers.

Incident Response

2 minutes

Search for revealing strings in Intezer Analyze

Accelerate your file investigations with new and improved string reuse capabilities in Intezer Analyze

Malware Analysis

5 minutes

Evasion Techniques Dissected: A Mirai Case Study

To explain how code reuse analysis is different from signature-based detection approaches, let’s take a look at four Mirai samples which were recently uploaded to VirusTotal.

Malware Analysis

1 minute

Accelerate Reverse Engineering with Intezer Analyze IDA Pro Plugin

Reduce the analysis time from hours to minutes. Immediately focus on the relevant parts of the binary. See the plugin in action.

Incident Response

3 minutes

Ransomware and Spyware Top Intezer Analyze Community Detections

This month’s community highlights span a variety of file formats — APK, ELF and PE. Join the free Intezer Analyze community today.

Malware Analysis

2 minutes

Intezer Featured in IBM X-Force Threat Index

Drawing on previous IBM X-Force collaboration in detecting new malware variants, we used our Genetic Malware Analysis technology to measure malware innovation made by adversaries between 2018 and 2019. This measure of innovation is the extent to which threat actors invested in developing new code, suggesting that adversaries are looking to expand their threat capabilities and evade detection.

Research

8 minutes

New Iranian Campaign Tailored to US Companies Utilizes an Updated Toolset

We have discovered a new phishing campaign conducted by APT34. The Iranian-backed group is using an updated toolset tailored to US-based companies with the intent to evade detection.

Incident Response

4 minutes

Intezer Analyze Community: 2019 Recap and Trends