Sign in

Steve YARA Synapse Miller

@stvemillertime.bsky.social
2K followers 235 following 62 posts

writing & sharing on adversary tradecraft, malware, threat detection, ics/ot + cyber physical intel, and of course all things #yara

PostsRepliesMedia
Steve YARA Synapse Miller @stvemillertime.bsky.social · 18/10/2025
If you need me I'll be in the Andromeda Galaxy
161
Steve YARA Synapse Miller @stvemillertime.bsky.social · 03/07/2025
Imo the security product market is almost always a decade behind needs, but over time ends up being pulled to meet the adversary where they are operating. In the 2010s the market came late to the endpoint, in the 2020s late to the cloud, in the 2030s it'll be back to the network.
270
Steve YARA Synapse Miller @stvemillertime.bsky.social · 19/06/2025
Summer of George
191
Steve YARA Synapse Miller @stvemillertime.bsky.social · 28/05/2025
My top 5 movies about ~hacking probably say more about my age than anything else, but still: #1 - Hackers (1995) #2 - War Games (1983) #3 - Johnny Mnemonic (1995) #4 - Ghost in the Shell (1995) #5 - Office Space (1999) <- surprisingly full of hacks
5140
Steve YARA Synapse Miller @stvemillertime.bsky.social · 09/05/2025
The Wire, but a cybercrime version of it
151
Steve YARA Synapse Miller @stvemillertime.bsky.social · 08/05/2025
imo, great defenders think like attackers and great attackers think like defenders and great security folks think like both and great intelligence folks think like neither beep boop computers
0111
Steve YARA Synapse Miller @stvemillertime.bsky.social · 27/04/2025
I used to secretly judge folks that don't *love* music. But I learned that not everyone has the same ability to _detect_ musical features (pitch, rhythm, harmony etc). This happens not in the ear but in the brain. W/ diff neuro wiring & genes, folks don't always hear what I hear.
020
Steve YARA Synapse Miller @stvemillertime.bsky.social · 12/04/2025
"The game is out there, and it's either play or get played." - Omar
010
Steve YARA Synapse Miller @stvemillertime.bsky.social · 11/04/2025
Which of the Warhammer 40K races and factions should I get into? Sisters of Battle? Space Wolves? Henry Cavill?
010
Steve YARA Synapse Miller @stvemillertime.bsky.social · 07/04/2025
Really neat exposé on RDP tradecraft to include signed .rdp configs, resource redirection, RemoteApps and probably PyRDP. cloud.google.com/blog/topics/...
cloud.google.com
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
1123
Reposted by Steve YARA Synapse Miller
gab 🇺🇦🇵🇸 @gabagool.ing · 07/04/2025
Excellent breakdown of the “Rogue RDP” TTP we’ve seen susp Russian APT UNC5837 using in their campaigns written by my colleague Rohit (@IzySec over on X)
cloud.google.com
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
0168
Reposted by Steve YARA Synapse Miller
Ronnie Salomonsen @r0ns3n.dk · 07/04/2025
Windows Remote Desktop Protocol: Remote to Rogue cloud.google.com/blog/topics/...
cloud.google.com
Windows Remote Desktop Protocol: Remote to Rogue | Google Cloud Blog
A novel phishing campaign by Russia-nexus espionage actors targeting European government and military organizations.
031
Reposted by Steve YARA Synapse Miller
Doug Metz @dwmetz.bsky.social · 03/03/2025
Introducing MalChela. A YARA and Malware Analysis utility written in Rust. #DFIR #MalwareAnalysis #YARA #Hashing
bakerstreetforensics.com
MalChela – A YARA and Malware Analysis Toolkit written in Rust
Saturday was for Python. Sunday was for Rust. After my success with the Python + YARA + Hashing, I decided to take things to the next level. Over the past few years I've created a number of Python and PowerShell scripts related to YARA and Malware Analysis. What if I combined them into a single utility? While we're at it, let's rewrite them all from scratch in Rust.
073
Reposted by Steve YARA Synapse Miller
Doug Metz @dwmetz.bsky.social · 02/03/2025
Seeing these scrips run brings me joy. #DFIR #MalwareAnalysis #Python #YARA
083
Reposted by Steve YARA Synapse Miller
Doug Metz @dwmetz.bsky.social · 01/03/2025
Creating custom hash sets with YARA and Python I don't like to brag, he said, but you should see the size of my malware library. For a recent project, I wanted to produce a hash set for all the malware files in my repository. Included in the library are malware samples for Windows and other…
bakerstreetforensics.com
Creating custom hash sets with YARA and Python
I don't like to brag, he said, but you should see the size of my malware library. For a recent project, I wanted to produce a hash set for all the malware files in my repository. Included in the library are malware samples for Windows and other platforms. Within the library there are also a lot of pdf's with write ups corresponding to different samples.
092
Steve YARA Synapse Miller @stvemillertime.bsky.social · 01/03/2025
Do not despair, my friends, the only way out is through; And the climate will probably kill us all pretty soon anyway
2100
Steve YARA Synapse Miller @stvemillertime.bsky.social · 25/02/2025
One rule's FP is another rule's FN.
040
Steve YARA Synapse Miller @stvemillertime.bsky.social · 21/02/2025
SSH is the cyber blood magick of both the world's most stalwart orgs and the world's toughest adversaries.
010
Reposted by Steve YARA Synapse Miller
Horkos @wylienewmark.bsky.social · 05/02/2025
You’re an MSS or SVR cyber targeter who’s spent years trying to find an access vector into SPS/PAM; then suddenly a pack of high-profile, right-wing, edgelord zoomers — who will definitely click on any link they think will get them laid — just get admin access. Prepositioning acquisition speedrun.
16314
Steve YARA Synapse Miller @stvemillertime.bsky.social · 10/01/2025
Years of mediocre gen AI commodities will birth a generation of neo-luddites who refuse to delegate the joys of art, music, writing & human connection to machines. They'll sketch, read human-gen pBooks, buy vinyls at concerts, share hand-written original pre-trend non-memes.
120
Reposted by Steve YARA Synapse Miller
Wesley Shields @wxs.bsky.social · 09/01/2025
If you want to test out my YARA rule linting work use this PR: github.com/VirusTotal/y... If you want to get the basic gist of it, this config file change has documentation on it: github.com/VirusTotal/y... Just set it in your config file and use "yr check" for now. Happy #100DaysOfYARA. ;)
1146
Steve YARA Synapse Miller @stvemillertime.bsky.social · 31/12/2024
Which subscription news services do you pay for? I want premium, non content farm, mostly human-written science, tech, security news. I'm considering things like The Information, 404 media, MIT Tech Review, etc, but looking for recommendations. (I get NYT, AP, Reuters already)
341
Steve YARA Synapse Miller @stvemillertime.bsky.social · 15/12/2024
A unique finding, a novel artifact, a hidden curio, a piece of something yet unknown to the world. With each discovery comes a bewitching temptation to believe you alone know a secret, and own it.
040
Steve YARA Synapse Miller @stvemillertime.bsky.social · 13/12/2024
In your opinion, what are the differences between cyber security journalism and cyber threat intelligence?
7174
Reposted by Steve YARA Synapse Miller
Hexacorn @hexacorn.bsky.social · 08/12/2024
come to think of it, it's actually pretty easy; probably can be simplified but I wanted 4 chars as anchors at the front
132
Steve YARA Synapse Miller @stvemillertime.bsky.social · 07/12/2024
How would you detect something like this, generically? SOFT_WARE\Micros_oft\Win_dows\Curr_entVer_sion\Ru_n
540
Steve YARA Synapse Miller @stvemillertime.bsky.social · 07/12/2024
Lovely creature comforts in YARA-X such as basic stats for scanned, match number and time. 502551 file(s) scanned in 35.8s. 0 file(s) matched.
1160
Steve YARA Synapse Miller @stvemillertime.bsky.social · 06/12/2024
I often use my personal SIGINT experiences to describe CN APT groups, and rightly accused of mirroring bias. Still, CN has been pillaging and imitating us for decades, so if you want to see what they're up to today on the CNO front, look at what the IC was doing 10+ years ago.
150
Steve YARA Synapse Miller @stvemillertime.bsky.social · 06/12/2024
Curate your collection
190
Steve YARA Synapse Miller @stvemillertime.bsky.social · 05/12/2024
There is no "right" way to write YARA rules. You may dislike my rule format preferences or content decisions, just as I might dislike your document with bland vocabulary, unimaginative prose. There are ineffective ways to use YARA, but there's no right way. Find your style.
3103
Reposted by Steve YARA Synapse Miller
Wesley Shields @wxs.bsky.social · 04/12/2024
While I don’t necessarily disagree I think a lot of the NIH syndrome comes from the fact that they have built decades of engineering foundations and often shoe-horning outside tech to work with it is a lot of work and a maintenance nightmare. It’s more about intertia than hubris.
172
Steve YARA Synapse Miller @stvemillertime.bsky.social · 04/12/2024
There is a latent hubris in both msft & goog that any problem is solvable w/ their own tech because of prior successes & massive amounts of resources. I think this is foolish because I often see smaller, less "powerful" tools out-perform goliath systems through elegant design.
0102
Steve YARA Synapse Miller @stvemillertime.bsky.social · 02/12/2024
There's a cool course called "Smiller for Security Analysts" and its basically three straight weeks of me waving my hands and going on about YARA and tradecraft and malware and detection, which can be helpful (and fun!) for folks who are getting into that stuff.
083
Steve YARA Synapse Miller @stvemillertime.bsky.social · 27/11/2024
Binary Ninja plugin for copy and pasting bytes into YARA friendly format, courtesy of @re.wtf github.com/ald3ns/copy-... Rumor has it there's a next-generation version in the works that will probably blow your mind.
github.com
GitHub - ald3ns/copy-as-yara: This is a little plugin to copy disassembly in a way that is usable in YARA rules!
This is a little plugin to copy disassembly in a way that is usable in YARA rules! - ald3ns/copy-as-yara
0245
Steve YARA Synapse Miller @stvemillertime.bsky.social · 26/11/2024
I've not spoken to many analysts who feel they are properly equipped to do their *best* work. Most feel they could be moving faster, scaling bigger, helping more, if only they had the right vehicles, tooling, data. I wonder if thats because we're critics (in good & bad ways).
010
Steve YARA Synapse Miller @stvemillertime.bsky.social · 26/11/2024
020
Steve YARA Synapse Miller @stvemillertime.bsky.social · 26/11/2024
In my experience, reverse engineering malware is like one of those sliding block puzzles where there's only one empty space, but instead of being a 5x5 grid of an image, its a tedious 1000x1000 grid of bytes
media.tenor.com
a collage of images of a girl with yellow hair
ALT: a collage of images of a girl with yellow hair
131
Steve YARA Synapse Miller @stvemillertime.bsky.social · 26/11/2024
Does anyone use FLOSS with Binary Ninja? Do you have to create a script to import the FLOSS json?
101
Steve YARA Synapse Miller @stvemillertime.bsky.social · 25/11/2024
I suppose I don't think DoSing a C2 system is 'hacking back' per se, because I believe the knowledge that made me aware of the C2 node is a qualified invite to the party and more than a sufficient excuse to bring thousands of friends.
2160
Steve YARA Synapse Miller @stvemillertime.bsky.social · 24/11/2024
LLMs are nice because you can make lemonade out of a big pile of trash data that you've stored for decades. But on the other hand, your output might still be a distillate of what is ultimately trash to begin with.
160
Steve YARA Synapse Miller @stvemillertime.bsky.social · 23/11/2024
For my #100daysofYARA 2025, I plan to focus on YARA-X experiments and scripting/plugins for Binary Ninja.
1211
Steve YARA Synapse Miller @stvemillertime.bsky.social · 23/11/2024
You'd know from my job history that I am not loyal to corporations. Mandiant is no longer a company, but it is still an ethos & an ideology that I believe can transform thinking in the security space, & I will do everything I can to ensure that Google Threat Intelligence carries that spirit forward.
0130
Steve YARA Synapse Miller @stvemillertime.bsky.social · 22/11/2024
*downselection of activity not to scale
22313
Steve YARA Synapse Miller @stvemillertime.bsky.social · 21/11/2024
When investigating a logic match (YARA/Suricata/Sigma etc rule) we are assessing the extent to which the match aligns w/ the phenomena the rule was meant to describe. This means analysts (SOC/IR etc) need to understand those phenomena & imo rule metadata is consistently insufficient.
060
Steve YARA Synapse Miller @stvemillertime.bsky.social · 19/11/2024
It can be helpful to think about what you're trying to get away from. What is the "South Star" for your product, organization, or workflow? Given how much time I spend copying and pasting data from one system to another, Ctrl+C Ctrl-V is my South Star in almost everything.
140
Reposted by Steve YARA Synapse Miller
Joe Slowik @pylos.co · 18/11/2024
It's only an "ORB" if it is from the Cheltenham region of UK, otherwise it is just a sparkling botnet
4415
Steve YARA Synapse Miller @stvemillertime.bsky.social · 18/11/2024
Much like the conservation of mass-energy, the "detection evasion paradox" suggests that detection surface area cannot be created nor destroyed, only transformed or transferred to another form. Every attempt to hide generates a new signal.
0153
Steve YARA Synapse Miller @stvemillertime.bsky.social · 18/11/2024
I think many UI/UX designers severely underestimate the amount of information I want on my screen. What is the point of my giant, hi-res screen, if you're just going to chew up the real-estate with empty space and oversized nonsense? Sorry, but I do not want a link preview to be half the screen.
2110
Steve YARA Synapse Miller @stvemillertime.bsky.social · 16/11/2024
Another example of the "detection evasion paradox" is in the xz backdoor. The developer used Trie encoding of strings to obfuscate the malicious code. But the Trie may have caused the latency in the program that later raised flags to engineers that something was amiss, which I think is pretty funny.
media.tenor.com
a christmas tree made up of green and white letters
ALT: a christmas tree made up of green and white letters
140