TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

NSA Cyber Unfetter Project

110 点作者 boredgamer2大约 5 年前

7 条评论

motohagiography大约 5 年前
Good of them to release this, and I have a dog in the race about getting people to think higher-level about security, but ATT&amp;CK, STRIDE and other frameworks tend to be solipsistic, self propagating bullshit.<p>I would also argue that quantitative security risk models serve mainly as a corporate laundering system to obfuscate risk, do not have any meaningful predictive power, and that security compliance has become a make-work field for the unskilled, whose role is to be both an easy mark and a scapegoat for reckless corporate behaviour.<p>Hopefully it will mature to where designers and engineers themselves build in mitigations, the way some of them have with environmental and safety risks, but as a business, I think security is due for some scrutiny.
评论 #23138154 未加载
评论 #23136308 未加载
评论 #23137967 未加载
badrabbit大约 5 年前
Been down this road before, much harder than it looks. MITRE techniques can be deceptive in that you think you can detect on a technique but that is true only for the specific attack scenario. Example: you can detect anomalous scheduled task creation, but is it because you are looking for specific command lines? If so, why can&#x27;t attackers just use .NET ? You can detect cred dumping because procdump.exe or wce.exe is seen,but what you are not looking for process handles to lsass. It can lead to a false sense of security if you&#x27;re not careful.<p>From a threat hunting and detection perspective, I am so glad they are sharing this tool. It becomes very tedious very fast when you take things like this and apply them against the highly nuanced context of your environment.
jgelsey大约 5 年前
What&#x27;s with all the typos on the web site? e.g. &quot;Unfetter Discover: Analyze seucrity gaps and explore adversary tradecraft&quot; or &quot;Unfetter Disocover&quot;.<p>If the goal is to foster adoption these tells scream &quot;disorganized and unprofessional&quot;.
评论 #23137126 未加载
dogma1138大约 5 年前
GitHub docs lead to <a href="http:&#x2F;&#x2F;unfetter.io&#x2F;" rel="nofollow">http:&#x2F;&#x2F;unfetter.io&#x2F;</a> which leads to a GoDaddy landing page...
mey大约 5 年前
<a href="https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;issues&#x2F;1613" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;issues&#x2F;1613</a><p>Looks like the project may be abandoned? Time for a fork?
bibinou大约 5 年前
(2018) <a href="https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;commits&#x2F;master" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;unfetter-discover&#x2F;unfetter&#x2F;commits&#x2F;master</a>
评论 #23134358 未加载
seemslegit大约 5 年前
OK seriously we need to have a talk about this whole &#x27;posture&#x27; thing.
评论 #23135069 未加载