Category: DFIR Lab – Binalyze

Binalyze and ThreatMon Join Forces to Operationalize Threat Intelligence Inside Investigation Workflows

Binalyze x ThreatMon collab blog

Binalyze and ThreatMon Join Forces to Operationalize Threat Intelligence Inside Investigation Workflows

Threat intelligence is most valuable when security teams can act on it.

Most organizations already have access to intelligence feeds, IOCs, and threat context from trusted sources. But turning that intelligence into practical investigation and hunting content often remains a manual, time-consuming process. Analysts need to export IOCs, convert them into usable rules, upload those rules into security tools, and continuously maintain them as intelligence changes.

For busy SOC, IR, DFIR, MDR, and MSSP teams, that operational burden can slow down proactive threat hunting.

That is why Binalyze and ThreatMon are joining forces through a Technology Alliance to help security teams move faster from threat intelligence to investigation-ready action.

With Binalyze AIR’s new Cyber Threat Intelligence (STIX/TAXII Feed) Integration, supported intelligence can be imported into AIR and transformed into ready-to-use YARA, Sigma, and osquery triage rules. The result is a practical way to operationalize threat intelligence inside threat-hunting and investigation workflows.

AIR in Action: AsyncRAT’s 30 Days of Key-logging

An Incident Response Investigation with Binalyze AIR

The seemingly unending work to detect the silent workings of malware is a constant and stark reminder of the stakes in modern incident response. In one recent Incident Response (IR) engagement, the Binalyze CERT (Customer Experience Response Team) uncovered a prolonged campaign involving the well-known malware family AsyncRAT.

How Threat Hunting is the Ultimate SOC Approach

Threat hunting has emerged as the ultimate approach for Security Operations Centers (SOCs) to stay ahead of cyber threats. This proactive method involves actively searching for potential threats that might evade standard security tools, ensuring that SOCs can detect and respond to threats before they cause significant damage.

Introducing Binalyze MITRE ATT&CK Analyzer 6.3.0

We are pleased to announce the release of Binalyze MITRE ATT&CK Analyzer version 6.3.0! This latest update rolled out on 07/08/24, brings significant enhancements and improvements designed to boost your threat investigation and analysis capabilities. In this blog, we’ll take a closer look at the key updates and highlight some of the more critical issues our new rules can now detect.

Threat Hunting with DRONE and MITRE ATT&CK Analyzer

We recently updated Binalyze AIR MITRE ATT&CK Analyzer to version 5.7.0. This update brings significant enhancements to our threat detection capabilities, reinforcing our commitment to providing the best cybersecurity solutions. In this blog post, we’ll dive into the key updates in this release and introduce you to the powerful combination of Binalyze DRONE and MITRE ATT&CK within Binalyze AIR.

Enhancing Threat Detection and Analysis during Investigations

In today’s rapidly evolving threat landscape, organizations and MSSPs face growing numbers of cyber adversaries, ranging from sophisticated nation-states to opportunistic cybercriminals. To effectively combat these threats, security professionals require advanced automated tools and methodologies that provide deep insights into attacker tactics and techniques. Binalyze AIR’s automated compromise assessment, DRONE, coupled with the integration of MITRE ATT&CK, represents a powerful arsenal in the cybersecurity armory.