all blogs

Explore our blog

AI SOC

AI

Company News

5 minutes

Loop engineering comes to the SOC: Introducing the Intezer Org Brain

Organizational context in an AI SOC is table stakes. Org Brain is very different. It learns, it recalls, it fetches what it's missing, and it gets sharper with every alert it touches, all autonomously.

Itai Tevet

Detection Engineering

AI SOC

8 minutes

Detection engineering in the AI era

AI is lowering the barrier to sophisticated attacks. Explore why detection engineering matters and where most programs fall short.

Zev Schonberg

View Topics
SOAR
MDR
AI SOC
Detection Engineering
Threat Hunting
Threat Bulletin
The SecOps Automation Blog
SOC
Research
Malware Analysis
Knowledge Base
Incident Response
Company News
Cloud Security
CISO
Alert Triage
AI
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Reset
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Incident Response

4 minutes

2019: A Year-in-Review

Incident Response

1 minute

Now Supporting Genetic Malware Analysis for Android Applications

Malware Analysis

4 minutes

Intezer Analyze Community: Buhtrap, Divergent, Kronos, and More

November's community detections comprise a range of malware types, including banking trojans, exploit kits, and nation-state sponsored threats.

Incident Response

4 minutes

Revealing the Origins of Software with Genetic Analysis

By revealing the origins of software, the Genetic Analysis approach can detect in-memory threats designed by attackers to not generate noise.

Incident Response

2 minutes

Genetic Malware Analysis for Golang

Intezer Analyze now supports genetic analysis for files created with the Golang programming language. Users can detect and classify malware written in Go, within seconds!

Threat Hunting

3 minutes

Intezer Analyze Community Halloween Edition: Trickbot or Treat!

In the spirit of Halloween we’re spotlighting three “spooky” threats detected by the Intezer Analyze community in October. And as a special treat, we’re giving away three code-based YARA signatures which can be used to hunt for additional variants of these threats!

Incident Response

2 minutes

Intezer Analyze Use Case: Visibility Among Global SOCs

SOCs from the same organization can leverage Intezer Analyze to automatically share classifications and remediation tactics on previous incidents.

Research

3 minutes

Russian Cybercrime Group FullofDeep Behind QNAPCrypt Ransomware Campaigns

We can assess with high confidence that FullofDeep, a Russian cybercrime group specializing in ransomware operations, is behind both the original QNAPCrypt campaigns and the newly identified ransomware variant.

Incident Response

8 minutes

Why we Should be Paying More Attention to Linux Threats

By applying a Genetic Malware Analysis approach, and adhering to the mitigation recommendations outlined in this blog, users of Linux-based systems—particularly organizations hosting their data on Linux cloud servers—can better protect themselves from the threats posed by this emerging landscape.

Malware Analysis

4 minutes

Intezer Analyze Community: GonnaCry, HawkEye, BXAQ and More

In July, Intezer Analyze community users detected GonnaCry ransomware, the HawkEye malware kit, and BXAQ, the spyware the Chinese authorities have been installing onto foreign travelers’ Android devices.

Malware Analysis

3 minutes

Intezer Analyze Community: Mapping Code Connections Between Malware Samples

Studying genetic connections between malware samples and families detected and classified by the Intezer Analyze community.

Research

8 minutes

Watching the WatchBog: New BlueKeep Scanner and Linux Exploits

Researchers have discovered a new version of WatchBog, a cryptocurrency-mining botnet operational since November 2018. It is estimated that 4,500 Linux machines have been infected by this new malware campaign since June 2019.

Research

8 minutes

EvilGnome: Rare Malware Spying on Linux Desktop Users

EvilGnome, a rare type of malware with zero detections in VirusTotal, is spying on Linux desktop users by allowing the recording of audio conversations. The malware has infrastructure connections to Russian APT Gamaredon Group.

Malware Analysis

4 minutes

Intezer Analyze Community: BlackSquid, RobbinHood Ransomware and More

Intezer Analyze community detections from June included BlackSquid, RobinHood ransomware, Pacifier APT and Linux threats HiddenWasp and GreedyAntd.

Incident Response

3 minutes

Intezer and IBM Resilient Integrate to Enrich Threat Investigations with Genetic Malware Analysis

The integration between Intezer Analyze™ and IBM Resilient enables users of both platforms to enrich their incident response with Genetic Malware Analysis.