8.1 C
Canberra
Wednesday, June 24, 2026

Uplevelling Black Hat Risk Hunters


At Black Hat, each new knowledge supply is a trade-off.

Extra telemetry means higher visibility – but additionally extra knowledge for risk hunters to sift via.

Just lately, Splunk Assault Analyzer (SAA) outmoded Safe Malware Analytics (SMA) because the official malware risk evaluation platform at Black Hat. 

With SMA, we had a easy and efficient sample: 

  • Submissions exceeding a rating threshold
  • Mechanically surfaced to the Risk Hunters’ incident queue on Cisco XDR

It labored effectively. So naturally, we needed the identical consequence with SAA.

SAA supplies granular knowledge throughout a number of sourcetypes, permitting for vital flexibility in how data is offered. By mapping these knowledge streams collectively, we tailor-made our reporting to ship a complete, cohesive view of our risk panorama.

That is the place David and Lily stepped in. They constructed a question that:

  1. Extracts submission metadata (URL, Job ID, engines used)
  2. Makes use of the Job ID to retrieve high-scoring outcomes (≥85)
  3. Joins and reshapes each datasets right into a single, usable construction

This was a transformative shift. By tailoring our configuration to satisfy our particular necessities, we unlocked a brand new stage of visibility. This strategy delivered the deep, actionable insights essential to optimize our workflow.

With the question prepared, the main focus shifted to automation.

As a substitute of ranging from scratch, we reused present ingestion elements and tailored them for this knowledge construction.

Building the workflowBuilding the workflow

Then got here an essential determination: Concentrate on what issues for detection of threats at Black Hat. 

SAA can settle for any file format and URLs for evaluation which implies we noticed many protocols getting used, together with:

However solely HTTP had significant quantity and relevance for the occasion.

So, we reduce the remaining. POP3/SMTP would get an opportunity subsequent time round.

This was precision – prioritizing affect over completeness.

A file submitted through HTTP doesn’t exist in isolation – it has community context. So, we enriched every submission with:

  • Associated visitors telemetry
  • Directionality
  • Motion context (allowed vs blocked)

This turned remoted outcomes into one thing risk hunters may really examine.

EnrichingWithNetworkContextEnrichingWithNetworkContext
EnrichingWithNetworkContextEnrichingWithNetworkContext

At this stage, we hit acquainted challenges: 

  • Timestamp normalization (epoch → RFC3339)
  • Motion context extraction (allowed vs blocked)
  • Site visitors directionality

All crucial for correct ingestion into XDR.

One difficulty almost derailed the correlation logic. Site visitors originating from inside zones was routed via zScaler, leading to:

  • Shared vacation spot IPs
  • A number of unrelated occasions bundled collectively

This may create false correlations – precisely the noise we had been attempting to keep away from.

The repair? A focused exception to filter it out.

Extremely personalized – however efficient.

The workflow produced a brand new detection stream in Cisco XDR – powered by SAA submissions, enriched with community context.

Malicious script detected by mozillaMalicious script detected by mozilla

At first look, some alerts seemed vital primarily based on their attributes of: 

  • Excessive scores
  • A number of inside programs concerned
  • Suspicious JavaScript obfuscation behaviour

However investigation instructed a distinct story. 

A official Twitter embed. Flagged by heuristics. 

False constructive. And that’s the purpose. 

With correct context and evaluation from Assault Storyboard, the crew rapidly validated and dismissed it.

CDN WidgetCDN Widget

And that’s the true win. This workflow wasn’t about including one other knowledge supply. 

It was about:

  • Surfacing high-risk submissions robotically
  • Offering community context for quicker triage
  • Serving to risk hunters dismiss noise quicker

This workflow is way from excellent. It should evolve, identical to every thing else we construct at Black Hat. 

“In the long run, one of the best detection isn’t the highest scored one – it’s the one you possibly can act on.” 

Try the opposite blogs from our crew at Black Hat Asia 2026. 

Black Hat is the cybersecurity trade’s most established and in-depth safety occasion sequence. Based in 1997, these annual, multi-day occasions present attendees with the most recent in cybersecurity analysis, growth, and developments. Pushed by the wants of the group, Black Hat occasions showcase content material immediately from the group via Briefings shows, Trainings programs, Summits, and extra. Because the occasion sequence the place all profession ranges and tutorial disciplines convene to collaborate, community, and talk about the cybersecurity matters that matter most to them, attendees can discover Black Hat occasions in america, Canada, Europe, Center East and Africa, and Asia. For extra data, please go to www.Black Hat.com.


We’d love to listen to what you assume! Ask a query and keep linked with Cisco Safety on social media.

Cisco Safety Social Media

LinkedIn
Fb
Instagram



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles