#falsepositiveprevention

Alexandre Dulaunoyadulau@infosec.exchange
2023-03-20

How do you deal with your Yara rules on VT matching CTF content on a regular basis in VirusTotal or other source? I see more and more
false-positives included in CTI content from CTF or cyber security exercises.

I'm usually trying to do these nowadays:

  • Keeping track of existing CTF names
  • Collecting IPs and host related to CTF infrastructure
  • Collecting GitHub account and repo related to CTF

I'm close to create a MISP warning-lists to facilitate the detection of false-positive. If you have other ideas, let me know.

#cti #falsepositiveprevention #threatintel #ctf

🔗 github.com/MISP/misp-warningli

2023-01-18

Experiencing false positives, a DDoS attack or something else?
 
As many have read at Reuters, hivepro and other sources there was (or is?) a DDoS attack against several organizations going on, which also targeted the danish financial sector. 
 
On 2023-01-02 our analytics identified a danish banking site as false positive in multiple different CTI sources. It is absolutely clear that this is a benign website, but these sources still claim it's a phishing URL - even after 2 weeks. 

Interestingly one of the sources is a very prominent CTI source - operated by a large cybersecurity company and this URL has been verfied as phishing by multiple people from the community. As this is such an obvious false positive and in combination of reading the articles about the cyber attack targeting also the banks in Denmark, we are wondering if this could also be an attempt of that group? Or symphatisants? And if so - why is the community verification not effective here?  
 
Sure, chance is high this is just coincidence. But what if not? Supply chain attacks on CTI sources - could this be a new attack vector we need to worry about? 
 
At least it's a good example how valuable a good false positive analytics is - for CTI provider and consumers.
 
See also: 
hivepro.com/pro-russian-hackti

reuters.com/technology/denmark
 
#cti #threatintelligence #ticura #falsepositive #falsepositiveprevention #banking #infrastructure #vulnerable

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst