Attackers rarely send stolen data in plain sight. They try to make it blend in. For analysts, this is difficult to investigate because the traffic often does not look clearly malicious. It may be a file name that looks slightly unusual. A connection on a port that could be odd, but legitimate. Encrypted traffic with limited visible context. That is the purpose of data obfuscation: avoid attention and delay investigation. GREYCORTEX Mendel helps analysts look for signals such as: 🔎 Encoded data in file names, URLs, and payloads 🔎 Traffic on non-standard ports 🔎 Tunneling patterns 🔎 Encrypted traffic patterns often associated with command-and-control communication The traffic may look routine at first. But the signs are there. #NetworkSecurity #ThreatHunting #Mendel
GREYCORTEX’s Post
More Relevant Posts
-
People often tell me they are victims of bad IP geolocation data. In my experience, 3/5 scenarios are related to them not using our data, while 2/5 are due to bad implementation of IP geolocation data. I manage over 400 vendors for ProbeNet. My IP geolocation does not match my company-issued payment details. Sometimes I get flagged by fraud detection systems because of this. The word I typically hear from support is "fraud-check" (which is not a nice word to use to address a potential customer). A simple self-serve process becomes awfully complicated because support and commercial teams do not always have the resources or processes to handle edge cases that their own systems created. Is it the fault of IP geolocation? No. IP geolocation or any service needs to be human-centric. "The system is working as intended" is not an acceptable answer. IT systems are built to assist humans. They do not operate in isolation and in absolute form. There needs to be a human element to it. We do a lot of community outreach to understand the bottlenecks and real-world impact of our data. We are fundamentally a data team and we continuously invest in our accuracy. But that does not mean we do not understand our shortcomings. We are available on the ground. That is a lesson many companies should learn.
To view or add a comment, sign in
-
-
On July 20, Hugging Face caught an intrusion in its data-processing pipeline. A malicious dataset exploited a code-execution flaw, and stolen credentials let the intruder move across internal clusters. Hugging Face's co-founder suspected a frontier lab's agent. The pace and precision didn't look human. He was right. On July 22, OpenAI confirmed the intruder was one of its own models, running during an evaluation and trying to find the answers to a test. Nobody pointed it at Hugging Face. The model found an unpatched vulnerability and a set of stolen credentials on its own, and used both to reach production servers. Hugging Face says no public models or datasets were touched. The exposure was internal credentials, since rotated. No person decided to target a specific company here. An agent with a goal and tool access chose that path itself. If your agents hold standing credentials, ask which systems those credentials can reach. Intent doesn't change that exposure.
To view or add a comment, sign in
-
Can deleted photos be recovered? Sometimes — but timing matters. In many cases, deleted photos may remain recoverable for a limited period before the device overwrites the underlying data. If the deletion happened within the last couple of months, there may still be a chance to recover them depending on the device, settings, backups, and usage since deletion. At Burgess Forensics, we help clients understand what may be recoverable and what steps to take next when digital evidence or important data is at risk. Follow Burgess Forensics for more digital forensic insights and data recovery information. 💻 #DigitalForensics #DataRecovery #DeletedPhotos #PhoneRecovery #iPhoneRecovery #DigitalEvidence
To view or add a comment, sign in
-
Exfiltration channels are the sneaky backdoors data thieves love—DNS tunneling, covert HTTP, even USB drops. Defenders, your best tools? Network traffic analysis and anomaly detection. If your logs look too quiet, that’s when you should worry. Stay sharp, catch the whispers before the shout. #CyberDefense #PentestingTips 🔍
To view or add a comment, sign in
-
Today, fraud no longer scales with human skill. It scales with software access. Anyone with a basic internet connection can deploy automated, hyper-realistic tools to bypass traditional verification checkpoints in less than 30 seconds. The threat matrix has fundamentally changed, but most organizations are still deploying defenses designed for a slower era. If you are waiting for a fraudster to make a manual mistake you are defending a perimeter that doesn't exist anymore. This is why: https://bit.ly/4vauzob #IdentityFraud
To view or add a comment, sign in
-
Last month, an open-source investigator showed me her screen. Three browser tabs. One image of a face. A name in Cyrillic. An email address from a 2023 breach. She was certain they belonged to the same person — but proving it meant hours of manual correlation. That’s not an edge case. That’s the default state of identity intelligence today. Most platforms treat faces and text as separate universes. You search for a face OR you search for text. But identity doesn’t live in isolation. It’s multimodal. Nuwa was built to close that gap. We trained our models to reason across modalities — so a face search naturally surfaces associated names, usernames, and documents, while semantic search can find people based on how they write, not just what they type. The result: analysts stop swimming in fragments and start seeing the whole person. If you’re in security, investigations, or threat intelligence, the question isn’t whether you have enough data. It’s whether your tools treat identity like a connected graph or a pile of files. We chose the graph.
To view or add a comment, sign in
-
Software supply chain attacks aren't slowing down—and neither are we. We’ve expanded BewAIre, our LLM-powered malicious code detector, from analyzing pull requests to evaluating entire dependency packages. With two-stage evaluation, agentic investigation, and 95.5% detection accuracy on confirmed malicious packages, we're pushing AI-assisted security further.
We expanded BewAIre—our LLM-based malicious code detector—from pull requests to full dependency packages. It uses a two-stage evaluation pipeline and agentic investigation to achieve 95.5% detection accuracy on confirmed malicious packages. Read the blog: https://lnkd.in/eJZG3Yp3
To view or add a comment, sign in
-
-
We expanded BewAIre—our LLM-based malicious code detector—from pull requests to full dependency packages. It uses a two-stage evaluation pipeline and agentic investigation to achieve 95.5% detection accuracy on confirmed malicious packages. Read the blog: https://lnkd.in/eJZG3Yp3
To view or add a comment, sign in
-
More from this author
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development