Contra - A professional network for the jobs and skills of the futureWorking through the MITRE ATT&CK Evaluations APT29 dataset in Splunk and documenting everything I...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Working through the MITRE ATT&CK Evaluations APT29 dataset in Splunk and documenting everything I find. Part 1 covers EventID 1, the initial dropper, steganographic payload execution inside a PNG image, and what the EventID distribution revealed about how APT29 avoids process-based detection. The Sigma detection rules for every technique I find across the full series will publish on Substack. Part 1 is here: https://open.substack.com/pub/manishrawat21/p/hunting-apt29-in-196071-logs-what?r=7dntti&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true
#Cybersecurity #ThreatHunting #APT29 #DetectionEngineering #infosec #Contra
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started