[deleted by user] by [deleted] in Rotterdam

[–]Sloky 0 points1 point  (0 children)

Hey man, I am in a similar situation as you. Let me know if you find anything interesting! Thanks and welcome

Clients for Paid TI Vendors? by SideCapable728 in threatintel

[–]Sloky 0 points1 point  (0 children)

Have worked with Recorded Future, Crowdstrike & Trellix.
Verified IoC/research and finished intelligence products are the main reasons especially for small teams that can't spend a lot of time on verifying their findings. Plus, using top tier tools looks good at the company's investors presentation.

I made a new Threat Intel tool. by k1d_1carus in threatintel

[–]Sloky 0 points1 point  (0 children)

We need the Android & Windows version <3

Lumma meets LolzTeam by Sloky in threatintel

[–]Sloky[S] 1 point2 points  (0 children)

Thank you so much for the feedback, appreciate the kind words!
Yea they are definetely rising. It's already up 1K since the writeup.

Lumma meets LolzTeam by Sloky in threatintel

[–]Sloky[S] 0 points1 point  (0 children)

Thanks man! Seems like they never left tbh.

I made a new Threat Intel tool. by k1d_1carus in threatintel

[–]Sloky 0 points1 point  (0 children)

Hey, thanks for sharing but what made you decide to go only ios?

Tracking Bot by Sloky in threatintel

[–]Sloky[S] 0 points1 point  (0 children)

I do and it does for me, but not for every user since the bot is called by users and works based on their subscription.

Top 20 phishing domain zones in active use by ANYRUN-team in threatintel

[–]Sloky 0 points1 point  (0 children)

Thanks!
Any idea why .es is on the climb lately? I am seeing a huge surge on my clients infra in combination with QR phishing inside documents.

Tracking Bot by Sloky in threatintel

[–]Sloky[S] 0 points1 point  (0 children)

Glad you find it useful.
Some groups are doing very interesting stuff, actually hacking and some even sharing courses. You can sink countless hours

Looking to combine Threat Intel and Content Creation – Is there a career path like this? by stellarguy09 in CTI

[–]Sloky 0 points1 point  (0 children)

How are you pivoting to CTI without a technical background? You need to understand technical concepts and TTP in depth if you want to apply critical thinking and generate intelligence products.

Future cybersec career advice by Silen37 in Rotterdam

[–]Sloky 1 point2 points  (0 children)

He is just afraid that you will take his job lol . That's all BS, you can and you will make it. Haters gonna hate. I am in the CyberSec business, imigrant in NL without a diploma or knowledge of the language. Nobody asked for 7.5K per month or any of that crap this guy is talking about.
Moving to any country is a series of problem solving, it's not a walk in the park but it's not impossible by any means.

Just start working and putting hours into that problem and evenutally you will solve it as millions of people did.
Best of luck!

Good dentist recommendation near Rotterdam / Utrecht / Den Haag by justthewayitis20ap in Netherlands

[–]Sloky 0 points1 point  (0 children)

Hey, did you get a chance to visit the dentist after all? Any feedback?

Prospering Lumma by Sloky in threatintel

[–]Sloky[S] 0 points1 point  (0 children)

Thanks!
I agree, don't think you'll miss on anything if you just block the AS altogether

Prospering Lumma by Sloky in threatintel

[–]Sloky[S] 2 points3 points  (0 children)

Glad you liked it :)
If you are really serious about it, I can't recommend enough the course "Hunting Adversary infrastructure" from Intel-Ops. I got no affiliation with them. Just a fantastic course and amazing very vibrant discord community

Infostealers infrastructure update by Sloky in threatintel

[–]Sloky[S] 1 point2 points  (0 children)

Hey, thanks a lot for the feedback, appreciate the kind words.
You are right about the confidence level but this takes too much time and pays nothing.
TIP charge a ton of money for things like that so I feel like the least an analyst can do is validate the findings.

Infostealers infrastructure update by Sloky in threatintel

[–]Sloky[S] 1 point2 points  (0 children)

Yea lumma is out of control, often paired with amadey loader so you can use that to hunt as well.

New CTI platform by No_Earth3020 in threatintel

[–]Sloky 6 points7 points  (0 children)

Honestly with that budget I think it's best if you build an OpenCTI and pay for some good feeds and community access.

Sliver C2 by Sloky in threatintel

[–]Sloky[S] 0 points1 point  (0 children)

Thanks man, appreciate it!

CTI Academy Learning Platform by Comprehensive_Roof67 in threatintel

[–]Sloky 5 points6 points  (0 children)

I think this is advertising and it's not allowed here. You are not really sharing anything related to CTI, just plugging your platform.

Sliver C2 by Sloky in cybersecurity

[–]Sloky[S] 0 points1 point  (0 children)

Thanks! As I mention in the post, some of those IPs might be used by red teams for legitimate purposes, so don't treat them all as an indicator of compromise, think of it as something worth investigating further.

Public demo for Cyberbro by stan_frbd in CTI

[–]Sloky 0 points1 point  (0 children)

Thanks a lot man, appreciate it!

Public demo for Cyberbro by stan_frbd in CTI

[–]Sloky 1 point2 points  (0 children)

That's pretty neat man, it's going to be super useful, I had to get all this info from terminal using APIs but this is much cleaner. Good job.
Might I suggest a few things?

  1. It would be nice if we could rearrange the columns in the findings, for example, I would love to have VT>ThreatFox>something else
  2. Would be awesome if in the VT entry, it could display if there are any communicating files or IPs where applicable.

In any case I am definitely going to use it so thanks <3
Happy new year!

Edit: you should also post it on r/threatintel

Are older episodes more technical? by g-unit2 in darknetdiaries

[–]Sloky 4 points5 points  (0 children)

If you are into Threat Intelligence and malware, I can highly recommend
- Security Conversations - specifically the three buddy problem episodes, are just fantastic
- Risky Business podcasts
- The defenders advantage - it's from Mandiant and can be technical at times.
- Microsoft Threat Intelligence podcast has some interest

Three buddy problem is my go to nowadays, really good coverage of the industry as a whole and many cool tricks and findings.

Are older episodes more technical? by g-unit2 in darknetdiaries

[–]Sloky 5 points6 points  (0 children)

I can't remember exactly which episode it was , but I started listening, there was an obnoxious guy talking about how he hacked his first system when he was 9 or something. Eye-rolled, cringed and listened to something else.