Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

No Hat 2025 - Gaetano Pellegrino - Every Domain Tells a Story: Automatic Attribution from Timelines

Автор: BITM Hacklab

Загружено: 2025-10-27

Просмотров: 110

Описание:

Every Domain Tells a Story: Automatic Attribution from Timelines

Attribution remains one of the most challenging and consequential problems in threat intelligence. While traditional approaches rely heavily on artefacts like malware samples and phishing lures, infrastructure elements - especially domain behaviour - offer a rich source of insight. In this talk, we present a transparent approach to attribution based on machine learning and data mining techniques. It relies on domain timelines, which capture the lifecycle events of domains over time. We introduce the concept of characteristic sets - unordered collections of unique attributes of timeline events - and show how they enable the training of interpretable attribution models using small, analyst-curated datasets. Our framework includes a noise detector and an attributor, designed to remain auditable and supportive of human decision-making. We demonstrate the approach through three case studies involving GhostEmperor, BlindEagle, and Scattered Spider, highlighting both successful attributions and edge cases. In each scenario, our model reveals infrastructure reuse and domain lifecycle traits consistent with those of threat actors. The system not only identifies domains likely linked to known actors but also explains why, offering CTI teams a fast and verifiable decision-support tool. This talk is aimed at threat intel analysts, red teamers, and researchers interested in infrastructure tracking, attacker fingerprinting, and low-volume but high-confidence attribution at scale.


Gaetano Pellegrino - Staff Threat Researcher @Zscaler

Nino Pellegrino is a Staff Threat Researcher at Zscaler’s ThreatLabz, where he investigates Advanced Persistent Threats (APTs), particularly those linked to state-sponsored or highly targeted campaigns. Before this, he worked at Infoblox as a Senior Threat Researcher, focusing on detecting cyber threats through DNS telemetry within the Global Threat Intelligence team. Earlier in his career, Nino served as a consultant for Accenture Security at Telecom Italia Mobile, where he specialised in the analysis of malware and other artefacts involved in complex security incidents. He holds a PhD in cybersecurity from Delft University of Technology (TU Delft), where his research explored the application of state machine learning techniques for threat detection in both network and endpoint telemetry. Due to the often confidential nature of threat intelligence work, public speaking opportunities are rare in this field. Nino’s most recent public talk was at HackInBo Winter Edition in 2023.


LINKS
No Hat - Website: nohat.it
No Hat - X: @nohatcon
No Hat - Bluesky: https://bsky.app/profile/nohatcon.bsk...

G. Pellegrino - Linkedin:   / gllpellegrino  
G. Pellegrino - X: @gibbersen

No Hat 2025 - Gaetano Pellegrino - Every Domain Tells a Story: Automatic Attribution from Timelines

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

No Hat 2025 - Ken Munro - All at sea. Thought your OT / IT infrastructure was complex? Try doing ...

No Hat 2025 - Ken Munro - All at sea. Thought your OT / IT infrastructure was complex? Try doing ...

No Hat 2025 - Maria Khodak - Poison in the Wires: Interactive Network Visualization of Data ...

No Hat 2025 - Maria Khodak - Poison in the Wires: Interactive Network Visualization of Data ...

System Design Concepts Course and Interview Prep

System Design Concepts Course and Interview Prep

No Hat 2025 - G. André, W. Bécard - NTLM reflection is dead, long live NTLM reflection: Story of ...

No Hat 2025 - G. André, W. Bécard - NTLM reflection is dead, long live NTLM reflection: Story of ...

Zero to CTI: A Novice’s Journey into Threat Intelligence

Zero to CTI: A Novice’s Journey into Threat Intelligence

LLM и GPT - как работают большие языковые модели? Визуальное введение в трансформеры

LLM и GPT - как работают большие языковые модели? Визуальное введение в трансформеры

No Hat 2025 - Paul Zenker - Antedating Bananas Don't Matter: State of GenAI Security Solutions

No Hat 2025 - Paul Zenker - Antedating Bananas Don't Matter: State of GenAI Security Solutions

Cybersecurity Architecture: Networks

Cybersecurity Architecture: Networks

Самая сложная модель из тех, что мы реально понимаем

Самая сложная модель из тех, что мы реально понимаем

КАК УСТРОЕН TCP/IP?

КАК УСТРОЕН TCP/IP?

No Hat 2025 - Jr-Wei Huang - PS C: Live Off the .NET Gadgets: Defeating Super Hat’s VM Caching ...

No Hat 2025 - Jr-Wei Huang - PS C: Live Off the .NET Gadgets: Defeating Super Hat’s VM Caching ...

Но что такое нейронная сеть? | Глава 1. Глубокое обучение

Но что такое нейронная сеть? | Глава 1. Глубокое обучение

No Hat 2025 - Maria Khodak - Be Not Afraid: AppSec Solutions for ML Vulnerabilities

No Hat 2025 - Maria Khodak - Be Not Afraid: AppSec Solutions for ML Vulnerabilities

No Hat 2025 - Matthias Deeg - Your Security Update is Not Secure Enough: Hacking Portable ...

No Hat 2025 - Matthias Deeg - Your Security Update is Not Secure Enough: Hacking Portable ...

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

No Hat 2024 - Viktor Chuchurski - A Race to the Bottom - Database Transactions Undermining Your ...

No Hat 2024 - Viktor Chuchurski - A Race to the Bottom - Database Transactions Undermining Your ...

Why Cybersecurity is Recession-Proof // AI Hype vs Reality

Why Cybersecurity is Recession-Proof // AI Hype vs Reality

Dark Web РАСКРЫТ (БЕСПЛАТНО + Инструмент с открытым исходным кодом)

Dark Web РАСКРЫТ (БЕСПЛАТНО + Инструмент с открытым исходным кодом)

Stop the spyware built into Windows right now!

Stop the spyware built into Windows right now!

No Hat 2025 - Efstratios Chatzoglou - Unmasking Credential Leaks: A Security Evaluation of ...

No Hat 2025 - Efstratios Chatzoglou - Unmasking Credential Leaks: A Security Evaluation of ...

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: infodtube@gmail.com