TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

NSA Cyber Unfetter Project

110 pointsby boredgamer2about 5 years ago

7 comments

motohagiographyabout 5 years ago
Good of them to release this, and I have a dog in the race about getting people to think higher-level about security, but ATT&amp;CK, STRIDE and other frameworks tend to be solipsistic, self propagating bullshit.<p>I would also argue that quantitative security risk models serve mainly as a corporate laundering system to obfuscate risk, do not have any meaningful predictive power, and that security compliance has become a make-work field for the unskilled, whose role is to be both an easy mark and a scapegoat for reckless corporate behaviour.<p>Hopefully it will mature to where designers and engineers themselves build in mitigations, the way some of them have with environmental and safety risks, but as a business, I think security is due for some scrutiny.
评论 #23138154 未加载
评论 #23136308 未加载
评论 #23137967 未加载
badrabbitabout 5 years ago
Been down this road before, much harder than it looks. MITRE techniques can be deceptive in that you think you can detect on a technique but that is true only for the specific attack scenario. Example: you can detect anomalous scheduled task creation, but is it because you are looking for specific command lines? If so, why can&#x27;t attackers just use .NET ? You can detect cred dumping because procdump.exe or wce.exe is seen,but what you are not looking for process handles to lsass. It can lead to a false sense of security if you&#x27;re not careful.<p>From a threat hunting and detection perspective, I am so glad they are sharing this tool. It becomes very tedious very fast when you take things like this and apply them against the highly nuanced context of your environment.
jgelseyabout 5 years ago
What&#x27;s with all the typos on the web site? e.g. &quot;Unfetter Discover: Analyze seucrity gaps and explore adversary tradecraft&quot; or &quot;Unfetter Disocover&quot;.<p>If the goal is to foster adoption these tells scream &quot;disorganized and unprofessional&quot;.
评论 #23137126 未加载
dogma1138about 5 years ago
GitHub docs lead to <a href="http:&#x2F;&#x2F;unfetter.io&#x2F;" rel="nofollow">http:&#x2F;&#x2F;unfetter.io&#x2F;</a> which leads to a GoDaddy landing page...
meyabout 5 years ago
<a href="https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;issues&#x2F;1613" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;issues&#x2F;1613</a><p>Looks like the project may be abandoned? Time for a fork?
bibinouabout 5 years ago
(2018) <a href="https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;commits&#x2F;master" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;commits&#x2F;master</a>
评论 #23134358 未加载
seemslegitabout 5 years ago
OK seriously we need to have a talk about this whole &#x27;posture&#x27; thing.
评论 #23135069 未加载