Brutkey

Darren Meyer :donor:
@darrenpmeyer@infosec.exchange

Behaviors to look for: unusual DNS, weird repo access, large external data transfers. Over 185 signals in total, including request completion times, interval between requests, sequences and patterns, HTTP methods used and codes in responses, file types being transmitted – Estep & M #BHUSA #LivePost


Darren Meyer :donor:
@darrenpmeyer@infosec.exchange

Attributions under test are fairly reliable, but not perfect. – Estep & M #BHUSA #LivePost

Darren Meyer :donor:
@darrenpmeyer@infosec.exchange

Trained an XGBoost model per application, only 93 out of 500k were incorrectly attributed for worst case (Box) – Estep & M #BHUSA #LivePost