Security Is an Illusion: Malware, IOCs, and Supply Chain Risk
Malware attribution is harder than most teams want to admit.
Attackers can copy another group’s TTPs, swap tools, buy access, abuse trusted update paths, and make your EDR’s story look cleaner than reality. In this episode of C-Suite Cyber, Mike Small and AJ sit down with Diyar Saadi to talk through malware analysis, attribution, targeted attacks, social engineering, firmware malware, and why defenders cannot rely on tools alone.
Expect to hear:
* Why the target often matters more than the malware when figuring out who is behind an attack
* How attackers copy public TTPs to confuse attribution
* Why hashes, IPs, domains, and tool names can be weak evidence on their own
* What defenders misunderstand about MITRE ATT&CK, IOCs, and the Pyramid of Pain
* Why social engineering, initial access brokers, and MFA bypasses are still major business risks
* How firmware malware and update service hijacking can turn trusted updates into compromise paths
* Diyar’s advice for anyone learning malware analysis: OS internals, Windows internals, programming, networking, and curiosity
This one gets into the uncomfortable truth behind a lot of security programs: tools help, but they do not replace fundamentals, manual analysis, or attacker-minded curiosity.
___________________________________
Connect with Diyar:
https://reversethemalware.blogspot.com/
https://www.linkedin.com/in/diyarsaadi/
___________________________________
Links:
https://github.com/Adaptix-Framework/AdaptixC2
https://github.com/bishopfox/sliver
https://github.com/HavocFramework/Havoc
https://www.ransomware.live/
https://github.com/horsicq/detect-it-easy
https://github.com/mandiant/flare-floss
https://github.com/mandiant/capahttps://www.virustotal.com/
https://github.com/mandiant/flare-fakenet-ng
https://hex-rays.com/ida-prohttps://github.com/KasperskyLab/hrtng
https://malwareunicorn.org/https://malapi.io/
___________________________________
Sponsor: Tandem Cyber Solutionshttps://tandemcybersolutions.com/csuitecyber/
___________________________________
Connect with C-Suite Cyber:
LinkedIn [https://www.linkedin.com/company/c-suite-cyber-podcast] [https://x.com/suite_cybe82537]
X [https://x.com/suite_cybe82537]
Instagram [https://www.instagram.com/csuitecyberpodcast/] [https://www.tiktok.com/@c_suite_cyber_podcast]
TikTok [https://www.tiktok.com/@c_suite_cyber_podcast]