Go offline with the Player FM app!
Hiding in Plain Sight: How Defenders Get Creative with Image Detection
Manage episode 468342852 series 3348167
Hello to all our Cyber Pals! Join host Selena Larson and guest host, Sarah Sabotka, as they speak with Kyle Eaton, Senior Security Research Engineer at Proofpoint.
They explore the evolving world of image-based threat detection and the deceptive tactics cybercriminals use to evade defenses. From image lures embedded in emails, PDFs, and Office documents to the surprising ways attackers reuse visuals across campaigns, this conversation break down how detection engineering is adapting to counter new threats.
There is also examination of how AI is shaping both cyber deception and detection, raising the question of how generative AI is influencing image-based security.
Listeners will gain insights into real-world detection successes, persistent threats like TA505 and Emotet, and the role of instincts in cybersecurity—because, as Selena notes, sometimes good detection is all about the vibes.
Key Topics Covered:
- Characteristics of Image-Based Threats
- Groups like TA505 and Emotet historically using recognizable image lures
- OneNote-Based Malware Detection (2023) & the Challenges with OneNote
- Shift to PDF-Based Threats
- PDF Object Hashing for Attribution & Detection
- Image-Based Threat Detection Insights
- Generative AI’s Impact on Image-Based Threats
Join us as we uncover real-world detection wins, explore persistent threats like TA505 and Emotet, and dive into the importance of instincts in cybersecurity—because, as our guest puts it, sometimes good detection is all about the vibes.
Resources mentioned:
https://github.com/target/halogen
For more information about Proofpoint, check out our website.
Subscribe & Follow:
Don't miss out on future episodes—subscribe to the Discarded Podcast on your favorite platform.
80 episodes
Manage episode 468342852 series 3348167
Hello to all our Cyber Pals! Join host Selena Larson and guest host, Sarah Sabotka, as they speak with Kyle Eaton, Senior Security Research Engineer at Proofpoint.
They explore the evolving world of image-based threat detection and the deceptive tactics cybercriminals use to evade defenses. From image lures embedded in emails, PDFs, and Office documents to the surprising ways attackers reuse visuals across campaigns, this conversation break down how detection engineering is adapting to counter new threats.
There is also examination of how AI is shaping both cyber deception and detection, raising the question of how generative AI is influencing image-based security.
Listeners will gain insights into real-world detection successes, persistent threats like TA505 and Emotet, and the role of instincts in cybersecurity—because, as Selena notes, sometimes good detection is all about the vibes.
Key Topics Covered:
- Characteristics of Image-Based Threats
- Groups like TA505 and Emotet historically using recognizable image lures
- OneNote-Based Malware Detection (2023) & the Challenges with OneNote
- Shift to PDF-Based Threats
- PDF Object Hashing for Attribution & Detection
- Image-Based Threat Detection Insights
- Generative AI’s Impact on Image-Based Threats
Join us as we uncover real-world detection wins, explore persistent threats like TA505 and Emotet, and dive into the importance of instincts in cybersecurity—because, as our guest puts it, sometimes good detection is all about the vibes.
Resources mentioned:
https://github.com/target/halogen
For more information about Proofpoint, check out our website.
Subscribe & Follow:
Don't miss out on future episodes—subscribe to the Discarded Podcast on your favorite platform.
80 episodes
All episodes
×
1 The ClickFix Convergence: How Threat Actors Blur the Lines 35:49

1 The Art of the Innocent Ask: How Threat Actors Use Benign Conversations 58:09

1 Diving Into Cyber Journalism: FOIA, Fraud, and the Fight Against Online Threats 46:35

1 Your Best Defense against Social Engineering: The Gray-Matter Firewall 51:06

1 Hiding in Plain Sight: How Defenders Get Creative with Image Detection 45:52

1 Cyber Groundhog Day and romance scams, featuring Only Malware in the Building 40:48

1 The Power of Partnerships: An Interview with the NSA’s Kristina Walter 39:30

1 The Battle for a Safer Internet: Inside Domain Takedowns and Threat Actor Tactics 38:05

1 Hackers, Heists, and Heroes: The Evolving Ransomware Game 57:06

1 Stealth, Scale, and Strategy: Exploring China’s Covert Network Tactics 49:28

1 Scams, Smishing, and Safety Nets: How Emerging Threats Catches Phish 51:07

1 Pig Butcher Scammers Put Job Seekers On The Menu 39:28

1 Under Siege: How Hackers Exploit Cloud Vulnerabilities 33:08

1 Champagne Attack Chains on a Kool-Aid Budget 33:38
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.