View Topics

Alert Triage
4 minutes
False Positive Madness: Reducing the Burden of Time-Wasting Alerts
Security teams have a lot of noise and false positives to deal with in their day-to-day jobs. Every organization is managing thousands of alerts each month.

Incident Response
3 minutes
Cyber Threat Diversion: Managing the False Positive Madness
Security teams have a lot of noise to deal with in their day-to-day jobs. Every organization is managing thousands of alerts each month — and that’s in an ideal scenario. Some are dealing with this volume on a daily basis, making it nearly impossible to stay ahead of possible threats.

Malware Analysis
5 minutes
Meet the Founders: Alon Cohen
Serial entrepreneur Alon Cohen co-founded and grew one of the world’s first cyber security startups, CyberArk, which eventually became a ‘unicorn’.

Research
4 minutes
North Korea and Iran Use CodeProject to Develop Their Malware
In the software development world, engineers frequently use ready-made code for various tasks, whether it involves copying a snippet from Stack Overflow, taking a library from Github, or reusing a company’s own rich, legacy code base.

Research
5 minutes
Evidence Aurora Operation Still Active Part 2: More Ties Uncovered Between CCleaner Hack & Chinese Hackers
We have found new evidence in the next stage payloads of the CCleaner supply chain attack that provide a stronger link between this attack and the Axiom group.

Research
4 minutes
Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner
Recently, there have been a few attacks with a supply chain infection, such as Shadowpad being implanted in many of Netsarang’s products, affecting millions of people. You may have the most up to date cyber security software, but when the software you are trusting to keep you protected gets infected there is a problem.

Malware Analysis
5 minutes
Intezer Community Tip: How to Optimize ssdeep Comparisons with ElasticSearch
Using ssdeep to find similarities between files can be quite effective when employing the right optimization methods

Research
6 minutes
New Variants of Agent.BTZ/ComRAT Found: The Threat That Hit The Pentagon In 2008 Still Evolving; Part 2/2
Our previous blog post was a short brief of new Agent.BTZ variants that we found. This second part in the series will demonstrate in greater detail exactly how we discovered these new variants.

Malware Analysis
6 minutes
About the Founders: Meet CEO Itai Tevet
Itai Tevet was the self-described ‘PC kid’ whose fascination with technology led to a strong interest in information security–an interest that benefited him as he grew into increasingly more responsible cyber security leadership roles within the Israeli Defense Forces (IDF).

Incident Response
6 minutes
Why Identifying ‘Good or Bad’ is Not Enough
Not performing a deeper analysis after the initial infection prevents us from performing an effective remediation to the actual problem.

Research
4 minutes
New Variants of Agent.BTZ/ComRAT Found: The Threat That Hit The Pentagon In 2008 Still Evolving; Part 1/2
Agent.BTZ–also known as ComRAT–is one of the world’s oldest known state-sponsored threats, mainly known for the 2008 Pentagon breach. Technically speaking, Agent.BTZ is a sophisticated user-mode RAT developed and operated by the Turla group in conjunction with Snake/Uroburos rootkit.

Research
4 minutes
“EternalMiner” Copycats exploiting SambaCry for cryptocurrency mining
About eight weeks ago, a critical RCE vulnerability present in every Samba version since 2010 was reported and patched. This vulnerability is mostly known as “SambaCry” after the famous WannaCry attack targeting Windows systems vulnerable to “EternalBlue” SMB exploit.

Incident Response
5 minutes
Without a Trace: The Dangers of Fileless Malware
Every day, wars are being waged on invisible battlefields. The enemy is hiding and stealthily leveling its attacks from within.

Incident Response
3 minutes
Introducing Cybersecurity DNA: the Intezer Company Blog
Have you ever searched for a needle in a haystack? In the world of cyber security, it might be that one problematic section or piece of code. Detecting cyber attacks certainly matters, but diagnosing them is also critically important.


