Wednesday, June 24, 2026
World News Prime
No Result
View All Result
  • Home
  • Breaking News
  • Business
  • Politics
  • Health
  • Sports
  • Entertainment
  • Technology
  • Gaming
  • Travel
  • Lifestyle
World News Prime
  • Home
  • Breaking News
  • Business
  • Politics
  • Health
  • Sports
  • Entertainment
  • Technology
  • Gaming
  • Travel
  • Lifestyle
No Result
View All Result
World News Prime
No Result
View All Result
Home Business

Uplevelling Black Hat Threat Hunters

June 24, 2026
in Business
Reading Time: 5 mins read
0 0
0
Uplevelling Black Hat Threat Hunters
Share on FacebookShare on Twitter


At Black Hat, each new knowledge supply is a trade-off.

Extra telemetry means higher visibility – but in addition extra knowledge for menace hunters to sift by.

From SMA to SAA: Identical Want, Completely different Drawback

Lately, Splunk Assault Analyzer (SAA) outmoded Safe Malware Analytics (SMA) because the official malware menace evaluation platform at Black Hat. 

With SMA, we had a easy and efficient sample: 

Submissions exceeding a rating threshold

Routinely surfaced to the Menace Hunters’ incident queue on Cisco XDR

It labored nicely. So naturally, we needed the identical consequence with SAA.

SAA offers granular knowledge throughout a number of sourcetypes, permitting for important flexibility in how data is introduced. By mapping these knowledge streams collectively, we tailor-made our reporting to ship a complete, cohesive view of our menace panorama.

The Turning Level: Collaboration

That is the place David and Lily stepped in. They constructed a question that:

Extracts submission metadata (URL, Job ID, engines used)

Makes use of the Job ID to retrieve high-scoring outcomes (≥85)

Joins and reshapes each datasets right into a single, usable construction

This was a transformative shift. By tailoring our configuration to fulfill our particular necessities, we unlocked a brand new stage of visibility. This method delivered the deep, actionable insights essential to optimize our workflow.

Constructing the Workflow

With the question prepared, the main target shifted to automation.

As a substitute of ranging from scratch, we reused current ingestion parts and tailored them for this knowledge construction.

Building the workflow

Then got here an necessary choice: Concentrate on what issues for detection of threats at Black Hat. 

SAA can settle for any file format and URLs for evaluation which implies we noticed many protocols getting used, together with:

However solely HTTP had significant quantity and relevance for the occasion.

So, we minimize the remaining. POP3/SMTP would get an opportunity subsequent time round.

This was precision – prioritizing affect over completeness.

Enriching with Community Context and lowering noise 

A file submitted by way of HTTP doesn’t exist in isolation – it has community context. So, we enriched every submission with:

Associated site visitors telemetry

Directionality

Motion context (allowed vs blocked)

This turned remoted outcomes into one thing menace hunters might really examine.

EnrichingWithNetworkContextEnrichingWithNetworkContext
EnrichingWithNetworkContextEnrichingWithNetworkContext

At this stage, we hit acquainted challenges: 

Timestamp normalization (epoch → RFC3339)

Motion context extraction (allowed vs blocked)

Visitors directionality

All needed for correct ingestion into XDR.

One situation practically derailed the correlation logic. Visitors originating from inside zones was routed by zScaler, leading to:

Shared vacation spot IPs

A number of unrelated occasions bundled collectively

This might create false correlations – precisely the noise we had been making an attempt to keep away from.

The repair? A focused exception to filter it out.

Extremely personalized – however efficient.

The End result: Higher Alerts for Hunters 

The workflow produced a brand new detection stream in Cisco XDR – powered by SAA submissions, enriched with community context.

Malicious script detected by mozillaMalicious script detected by mozilla

At first look, some alerts seemed essential primarily based on their attributes of: 

Excessive scores

A number of inside programs concerned

Suspicious JavaScript obfuscation behaviour

However investigation informed a distinct story. 

A authentic Twitter embed. Flagged by heuristics. 

False constructive. And that’s the purpose. 

With correct context and evaluation from Assault Storyboard, the workforce shortly validated and dismissed it.

CDN WidgetCDN Widget

And that’s the true win. This workflow wasn’t about including one other knowledge supply. 

It was about:

Surfacing high-risk submissions mechanically

Offering community context for sooner triage

Serving to menace hunters dismiss noise sooner

This workflow is way from excellent. It’s going to evolve, identical to every little thing else we construct at Black Hat. 

“Ultimately, the very best detection isn’t the highest scored one – it’s the one you’ll be able to act on.” 

Take a look at the opposite blogs from our workforce at Black Hat Asia 2026. 

About Black Hat 

Black Hat is the cybersecurity business’s most established and in-depth safety occasion collection. Based in 1997, these annual, multi-day occasions present attendees with the most recent in cybersecurity analysis, growth, and tendencies. Pushed by the wants of the neighborhood, Black Hat occasions showcase content material immediately from the neighborhood by Briefings shows, Trainings programs, Summits, and extra. Because the occasion collection the place all profession ranges and educational disciplines convene to collaborate, community, and talk about the cybersecurity subjects that matter most to them, attendees can discover Black Hat occasions in america, Canada, Europe, Center East and Africa, and Asia. For extra data, please go to www.Black Hat.com.

We’d love to listen to what you suppose! Ask a query and keep related with Cisco Safety on social media.

Cisco Safety Social Media

LinkedInFacebookInstagram



Source link

Tags: BlackBlack HatCisco Breach ProtectionCisco Secure AccessCisco Security CloudCisco TalosCisco User ProtectionCisco XDRCybersecurityFirewallHatHuntersNetwork Operations CenterNOCSecurity Operations CenterSOCSplunk CloudSplunk Enterprise SecurityThousandEyesthreatUplevelling
Previous Post

Deadly Heatwave Blankets Europe With Record High Temperatures

Next Post

Jenny Mollen Opens Up About ‘Really Bizarre’ Jason Biggs Split – Says ‘It’s Still Romantic,’ Huh?! – Perez Hilton

Related Posts

Calvin Klein, Adidas and Uniqlo ads banned for misleading ‘recycled’ claims
Business

Calvin Klein, Adidas and Uniqlo ads banned for misleading ‘recycled’ claims

June 24, 2026
New AI feature can help break scammers’ ‘spells’, says Starling Bank
Business

New AI feature can help break scammers’ ‘spells’, says Starling Bank

June 24, 2026
Celebrating Excellence: 2026 USCa NetAcad Partner Conference
Business

Celebrating Excellence: 2026 USCa NetAcad Partner Conference

June 23, 2026
Hiring An Operations Coordinator? Check Out These Agencies.
Business

Hiring An Operations Coordinator? Check Out These Agencies.

June 23, 2026
What Is The Difference Between Image Enhancement And Upscaling? – Young Upstarts
Business

What Is The Difference Between Image Enhancement And Upscaling? – Young Upstarts

June 24, 2026
Major high street bank launches savings account paying 8% interest
Business

Major high street bank launches savings account paying 8% interest

June 23, 2026
Next Post
Jenny Mollen Opens Up About ‘Really Bizarre’ Jason Biggs Split – Says ‘It’s Still Romantic,’ Huh?! – Perez Hilton

Jenny Mollen Opens Up About 'Really Bizarre' Jason Biggs Split - Says 'It's Still Romantic,' Huh?! - Perez Hilton

Celebrating Excellence: 2026 USCa NetAcad Partner Conference

Celebrating Excellence: 2026 USCa NetAcad Partner Conference

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
China’s New Five-Year Plan Prioritizes Robotics. The World Should Pay Attention.

China’s New Five-Year Plan Prioritizes Robotics. The World Should Pay Attention.

March 14, 2026
The 10 Most Beautiful Women in History According to AI

The 10 Most Beautiful Women in History According to AI

October 16, 2025
Concussion saw Macy lose her ‘spark’, but a new trial helped her recover

Concussion saw Macy lose her ‘spark’, but a new trial helped her recover

May 27, 2026
England’s 2026 World Cup home and away kits leaked

England’s 2026 World Cup home and away kits leaked

October 10, 2025
Summer 2026 Horror Preview: Every Major Horror Movie Coming to Theatres

Summer 2026 Horror Preview: Every Major Horror Movie Coming to Theatres

May 10, 2026
bet365 bonus code: Bet , get 5 in bonus bets for French Open Women’s Final

bet365 bonus code: Bet $10, get $365 in bonus bets for French Open Women’s Final

June 6, 2026
Major gas stations are using AI to keep prices inflated, lawsuit says

Major gas stations are using AI to keep prices inflated, lawsuit says

June 24, 2026
Hegseth bucked vaccine policy. How’d that turn out?

Hegseth bucked vaccine policy. How’d that turn out?

June 24, 2026
Live: Jam-packed day as last round of World Cup group clashes kicks off

Live: Jam-packed day as last round of World Cup group clashes kicks off

June 24, 2026
Bill Gates says Jeffrey Epstein sought to blackmail him over extramarital affairs

Bill Gates says Jeffrey Epstein sought to blackmail him over extramarital affairs

June 24, 2026
Clean sweep as 3 candidates endorsed by Mamdani win primaries in New York

Clean sweep as 3 candidates endorsed by Mamdani win primaries in New York

June 24, 2026
Deadspin | Orioles embrace season’s second half, starting with finale vs. Angels

Deadspin | Orioles embrace season’s second half, starting with finale vs. Angels

June 24, 2026
World News Prime

Discover the latest world news, insightful analysis, and comprehensive coverage at World News Prime. Stay updated on global events, business, technology, sports, and culture with trusted reporting you can rely on.

CATEGORIES

  • Breaking News
  • Business
  • Entertainment
  • Gaming
  • Health
  • Lifestyle
  • Politics
  • Sports
  • Technology
  • Travel

LATEST UPDATES

  • Major gas stations are using AI to keep prices inflated, lawsuit says
  • Hegseth bucked vaccine policy. How’d that turn out?
  • Live: Jam-packed day as last round of World Cup group clashes kicks off
  • About Us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Policy
  • Terms and Conditions
  • Contact Us

© 2025 World News Prime.
World News Prime is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Breaking News
  • Business
  • Politics
  • Health
  • Sports
  • Entertainment
  • Technology
  • Gaming
  • Travel
  • Lifestyle

© 2025 World News Prime.
World News Prime is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In