SOC Analyst Training: How SOC analysts can detect threat actors abusing legit tools
Good apps gone bad? 😈 Security researchers Ryan Robinson and Nicole Fishbein dig in As a SOC analyst, you need to be familiar with how trusted tools are misused by attackers. You ALSO need to know which detection methods will be effective in your environment and trigger alerts when attackers are using legitimate tools. But it is very challenging to detect the usage of legitimate applications by attackers while avoiding false positive alerts and alert fatigue. Since these applications are frequently used by the system and endpoint users, it is harder to detect when an application is exploited by attackers and issue an alert. Check out our blog for more about detecting and hunting legit applications that are being used for malicious purposes: https://www.intezer.com/blog/incident... 2:00 Life hack examples: Using (or misusing!) items in completely new ways 5:12 Is the tool in the hands of a trusted user, or deployed by someone with malicious intent? 7:18 Detecting malicious mshta.exe (Using a legitimate and signed binary as mshta gives attackers the means to execute arbitrary code stored on a remote server while bypassing browser security settings.) 12:16 Using Sigma for creating a detection rule to catch misuse of mshta 16:35 How malicious actors abuse PsExec command-line utility for admins 21:55 Detecting PsExec with Sigma based on behavior 25:58 The struggles of false positives 27:51 Squiblydoo - abusing the Regsvr32 command-line utility 37:29 Offensive security tools - a closer look at Patfish aka Paranoid Fish

Connecting Intezer with SentinelOne to Automate Incident Response

SOC Analyst Training: How to Detect Phishing Emails

Lessons from the Anthropic AI Espionage Report - How can SOC prepare for the age of AI?

5 Cybersecurity Certificates You Should Avoid (Do THIS Instead)

The Cybersecurity Certifications That Still Matter in 2026

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

The Internet Group That Changed Hacking Forever

What Is AI-Native Security? The Future of Security Operations

Zero to CTI: A Novice’s Journey into Threat Intelligence

Facing the Vulnpocalypse with lcamtuf

THESE Apps Are SPYING on You — Shut Them Off NOW!

The Biggest Lies in Cybersecurity

35C3 - Du kannst alles hacken – du darfst dich nur nicht erwischen lassen.

Web Scraping Using Python For Beginners and File Handling in Python | Python Web Scraping

OWASP Top 10 2025: Your complete guide to securing your applications

Best Hacking Laptop 2023

Firewall Fundamentals Explained | Network Security for Beginners

Something is jamming GPS over Europe. Here's what we found

#08 Should Fraud and Cybersecurity Teams Converge?

