Viewing profile — ddiinn2
ddiinn2
HN member- Joined
- Mon, Mar 23, 2015, 1:05 PM UTC
- HN karma
- 4
- Public activity
- 9 items
- HN profile
- View on Hacker News ↗
About ddiinn2
Recent public activity
-
comment
Comment #12063641
There are two main advancements beyond "classic" honeypots: 1. Honeypots are easy to fingerprint (see our blackhat talk, https://www.youtube.com/watch?v=Pjvr25lMKSY ) 2. Most honey…
-
comment
Comment #12063101
Any questions, we'd be happy to answer
-
comment
Comment #9795973
The trick is to make the breadcrumbs the type of data that an attacker is interested in, but a regular user will never be aware of. For example in windows there is a cache of used …
-
comment
Comment #9795959
Like was said before, you have to attack the decoy to recognize it and that enables catching the attack traffic. Also the mere fact that they recount every single action 10 times o…
-
comment
Comment #9795947
When you get one alert that you realize isn't false and has the forensic data tied to it, you can use it as a harness against the loads of information from all the other sensors (f…
-
comment
Comment #9791944
- What is alerted on (or "attack") is configurable and can range from code being executed (which is the true positive alert) to connecting to ports(which has more noise) - It needs…
-
comment
Comment #9791639
Each decoy is configured to look exactly the way that makes sense for the network it's in. An example is a git server with interesting code or an employees pc that shares files tha…
-
comment
Comment #9791582
Hi, dean here (Cymmetria CTO). Two great questions: 1. The concept being that from looking at the machine on the network we don't do anything different then regular machines, so th…
- story