Close Menu
geekfence.comgeekfence.com
    What's Hot

    Everest Group launches Innovation Watch on Agentic AI in Wealth Management Technology 

    July 21, 2026

    Apple says it fixed a vulnerability in its Hide My Email tool that let anyone see a user’s real email address; researchers first reported the issue in June 2025 (Joseph Cox/404 Media)

    July 21, 2026

    Alan Turing’s biggest AI assumption may have been wrong

    July 21, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Cyber Security»Uplevelling Black Hat Threat Hunters
    Cyber Security

    Uplevelling Black Hat Threat Hunters

    AdminBy AdminJune 24, 2026No Comments4 Mins Read5 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Uplevelling Black Hat Threat Hunters
    Share
    Facebook Twitter LinkedIn Pinterest Email


    At Black Hat, every new data source is a trade-off.

    More telemetry means better visibility – but also more data for threat hunters to sift through.

    From SMA to SAA: Same Need, Different Problem

    Recently, Splunk Attack Analyzer (SAA) superseded Secure Malware Analytics (SMA) as the official malware threat analysis platform at Black Hat. 

    With SMA, we had a simple and effective pattern: 

    • Submissions exceeding a score threshold
    • Automatically surfaced to the Threat Hunters’ incident queue on Cisco XDR

    It worked well. So naturally, we wanted the same outcome with SAA.

    SAA provides granular data across multiple sourcetypes, allowing for significant flexibility in how information is presented. By mapping these data streams together, we tailored our reporting to deliver a comprehensive, cohesive view of our threat landscape.

    The Turning Point: Collaboration

    This is where David and Lily stepped in. They built a query that:

    1. Extracts submission metadata (URL, Job ID, engines used)
    2. Uses the Job ID to retrieve high-scoring results (≥85)
    3. Joins and reshapes both datasets into a single, usable structure

    This was a transformative shift. By tailoring our configuration to meet our specific requirements, we unlocked a new level of visibility. This approach delivered the deep, actionable insights necessary to optimize our workflow.

    Building the Workflow

    With the query ready, the focus shifted to automation.

    Instead of starting from scratch, we reused existing ingestion components and adapted them for this data structure.

    Building the workflow

    Then came an important decision: Focus on what matters for detection of threats at Black Hat. 

    SAA can accept any file format and URLs for analysis which means we saw many protocols being used, including:

    But only HTTP had meaningful volume and relevance for the event.

    So, we cut the rest. POP3/SMTP would get a chance next time around.

    This was precision – prioritizing impact over completeness.

    Enriching with Network Context and reducing noise 

    A file submitted via HTTP doesn’t exist in isolation – it has network context. So, we enriched each submission with:

    • Related traffic telemetry
    • Directionality
    • Action context (allowed vs blocked)

    This turned isolated results into something threat hunters could actually investigate.

    EnrichingWithNetworkContext
    EnrichingWithNetworkContext

    At this stage, we hit familiar challenges: 

    • Timestamp normalization (epoch → RFC3339)
    • Action context extraction (allowed vs blocked)
    • Traffic directionality

    All necessary for proper ingestion into XDR.

    One issue nearly derailed the correlation logic. Traffic originating from internal zones was routed through zScaler, resulting in:

    • Shared destination IPs
    • Multiple unrelated events bundled together

    This could create false correlations – exactly the noise we were trying to avoid.

    The fix? A targeted exception to filter it out.

    Highly customized – but effective.

    The Outcome: Better Signals for Hunters 

    The workflow produced a new detection stream in Cisco XDR – powered by SAA submissions, enriched with network context.

    Malicious script detected by mozilla

    At first glance, some alerts looked critical based on their attributes of: 

    • High scores
    • Multiple internal systems involved
    • Suspicious JavaScript obfuscation behaviour

    But investigation told a different story. 

    A legitimate Twitter embed. Flagged by heuristics. 

    False positive. And that’s the point. 

    With proper context and analysis from Attack Storyboard, the team quickly validated and dismissed it.

    CDN Widget

    And that’s the real win. This workflow wasn’t about adding another data source. 

    It was about:

    • Surfacing high-risk submissions automatically
    • Providing network context for faster triage
    • Helping threat hunters dismiss noise faster

    This workflow is far from perfect. It will evolve, just like everything else we build at Black Hat. 

    “In the end, the best detection isn’t the highest scored one – it’s the one you can act on.” 

    Check out the other blogs from our team at Black Hat Asia 2026. 

    About Black Hat 

    Black Hat is the cybersecurity industry’s most established and in-depth security event series. Founded in 1997, these annual, multi-day events provide attendees with the latest in cybersecurity research, development, and trends. Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more. As the event series where all career levels and academic disciplines convene to collaborate, network, and discuss the cybersecurity topics that matter most to them, attendees can find Black Hat events in the United States, Canada, Europe, Middle East and Africa, and Asia. For more information, please visit www.Black Hat.com.


    We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

    Cisco Security Social Media

    LinkedIn
    Facebook
    Instagram





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Ukraine warns fake CAPTCHAs are being used to make you hack yourself

    July 21, 2026

    UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

    July 19, 2026

    Microsoft Patches a Record 570 Security Flaws – Krebs on Security

    July 18, 2026

    Forgotten UEFI shims undermining Secure Boot

    July 17, 2026

    UK Puts AWS, Azure, Google Cloud, and Oracle Under Direct Financial Oversight

    July 16, 2026

    Lean IT, future-ready: Making wireless careers attractive in the age of AI

    July 15, 2026
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 202562 Views

    Hard-braking events as indicators of road segment crash risk

    January 14, 202631 Views

    Redefining AI efficiency with extreme compression

    March 25, 202630 Views
    Don't Miss

    Everest Group launches Innovation Watch on Agentic AI in Wealth Management Technology 

    July 21, 2026

    Artificial Intelligence (AI) is becoming a standard capability across wealth management technology platforms. Advisor copilots, automated meeting preparation,…

    Apple says it fixed a vulnerability in its Hide My Email tool that let anyone see a user’s real email address; researchers first reported the issue in June 2025 (Joseph Cox/404 Media)

    July 21, 2026

    Alan Turing’s biggest AI assumption may have been wrong

    July 21, 2026

    Why Data-Driven Businesses Still Use USB Drives

    July 21, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    Everest Group launches Innovation Watch on Agentic AI in Wealth Management Technology 

    July 21, 2026

    Apple says it fixed a vulnerability in its Hide My Email tool that let anyone see a user’s real email address; researchers first reported the issue in June 2025 (Joseph Cox/404 Media)

    July 21, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.