Authentic8 Blog Category: Threat Intelligence

Covert Online Investigation Tools: How Yesterday’s DIY Is Today’s Negative ROI

Security Officers, are your online researchers still relying on custom-made covert investigation solutions cobbled together from disparate tools to save money? New research proves that the opposite is happening: It costs you extra.

A few years ago, providing research teams with out-of-the-box capabilities to perform anonymous online research was crazy expensive. The task of enabling cyber threat hunting, without the risk of crippling the network, for example, needed a separate six-figure line item on the IT budget. It’s no wonder that there are so many organizations that rely on a patchwork of make-do and DIY tools and methods.  

Today though, the DIY approach to enabling sensitive research on the open, deep, or dark web is unnecessary, as well as out of sync with the demands of our rapidly changing internet threatscape.

A new comparative analysis by Authentic8 shows how DIY costs leaps and bounds more money than the new, low maintenance, SaaS alternative available today.  

Covert Online Research Costs: DIY Approach vs. Silo Research Toolbox by Authentic8

Source (excerpt): Authentic8 Whitepaper

In a

Webinar: Cloud-based Research Platform for Threat Hunters

One of the most important applications of a cloud browser is investigating threat intelligence. Information security analysts can get quickly overwhelmed with data, from potential risks to false leads. Providing context for threat intelligence is critical for any security operations team.

Investigating leads from threat intelligence can be time-consuming and expensive for an already over-taxed function. Imagine having thousands of alerts, and no way to tell which ones are legitimate and which ones are benign.

Cloud-based technologies make infosec analysts more productive by doing much of the grunt work for them. Instead of slogging through thousands (or millions) of alerts, analysts rely on threat intelligence services like Recorded Future for in-depth and high-speed analysis to bring that down to a manageable number. And a cloud browser like the Silo Research Toolbox gives analysts a safe and efficient way to perform deep analysis on legitimate threats.

Illustration: Silo Research Toolbox - the cloud browser for analysts, researchers and investigators (screenshot)
Silo Research Toolbox on the Dark Web

Authentic8 and Recorded Future are presenting a cloud-based research platform

10 Top Tools for Threat Hunters from Black Hat USA 2018

You weren't able to make it to Las Vegas this year? Check out these ten short reviews of useful tools for threat intelligence researchers and threat hunters presented at Black Hat USA 2018:

Xori: Automated Disassembly

Black Hat USA 2018: 10 Top Tools - Xori

Malware disassembly can be quite tedious, even with a bells-and-whistles IDA Pro license. If only there was a way to automate all of it. That’s where Xori comes in.

Amanda Rousseau and Rich Seymour created a new automated disassembly platform that’s not only free, but fast. Reverse engineers often come across dozens of sample variants from the same family of malware. Having the ability to dissect all the assembly code and tell the results apart, automated and at a fast pace is something need in their arsenal of tools.

There are two modes in Xori, light and full emulation. Light emulation enumerates all the paths in CPU registers, the stack, and you’ll see some instructions. Full emulation follows the code’s path (shows