Introduction

Status
Not open for further replies.

SecurityAnalyst

New Member
Thread author
May 20, 2017
0
Hi, MT.

I'm a British security analyst, mainly working with various SIEM solutions for an un-named national healthcare provider... I'm keen to understand malware on a more technical level. I'd be happy to hear suggestions on tools and resources!

Looking forward to getting to know you all

SecAn
 

SecurityAnalyst

New Member
Thread author
May 20, 2017
0
So what does everyone do and where? I work in the north of England as a security analyst. I've worked for a couple of huge companies in SIEM focused roles and currently work for a national CERT (you may be able to guess which one by tying this comment with the original posting), essentially getting it off the ground.
 

SecurityAnalyst

New Member
Thread author
May 20, 2017
0
Hey @lab34 - Performance testing sounds like good fun. So are your team effectively trying to break software? My role is quite varied - threat intelligence writing, SIEM investigations, incident management - all round good fun. The recent outbreak of WannaCry across the national health service has highlighted some skill gaps in the team which is why I'm here beginning my journey into malware analysis.
 

ahity

Level 1
Verified
May 16, 2017
46
So what does everyone do and where? I work in the north of England as a security analyst. I've worked for a couple of huge companies in SIEM focused roles and currently work for a national CERT (you may be able to guess which one by tying this comment with the original posting), essentially getting it off the ground.

im just testing malware on my main lalptop (dont have lab computer :p) on virtualbox and testing antivirus, its risk. but its better when im not doing anything..
im very newbie i hope i can learn something worth from this forum, maybe about reverse enginering malware or something else about security ..
 

SecurityAnalyst

New Member
Thread author
May 20, 2017
0
Ah, cool. What are you testing, @ahity ? I've just set up an ESXi server on my LAN with a few OSs. I connect to it from work to test but my testing methods consist of little more than Wireshark and ProcMon - just to gather some quick IOCs. I've just started reading Practical Malware Analysis which I'm finding really useful.
 

lab34

Level 6
Verified
Well-known
Mar 28, 2017
263
Hey @lab34 - Performance testing sounds like good fun. So are your team effectively trying to break software? My role is quite varied - threat intelligence writing, SIEM investigations, incident management - all round good fun. The recent outbreak of WannaCry across the national health service has highlighted some skill gaps in the team which is why I'm here beginning my journey into malware analysis.
Yes, sometimes it breaks ;)
We are doing load tests based on what the dev teams ask us. And sometimes they want to know how far their app/infrastructure can go.
The difficulties begin when they ask why their app is not performant...
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top