Founder @vtxproject
Father of the #APT1 Report @mandiant / @fireeye
Inventor of synapse, vivisect, UNCs, imphash, ...
DEFCON CTF Champion, Founder of Kenshoto
Mar 26, 2021 • 7 tweets • 2 min read
A quick thread on observer bias…
In 2011, I was fortunate to be a part of @Mandiant, when the threat intelligence team was just beginning to coalesce. Back then, threat activity came in 3 flavors: APT, FIN, and everything else, and it was a problem...
I created the UNC concept specifically to thwart a form of Observer Bias I had witnessed both inside and outside the IC. If newly observed activity wasn’t quickly attributed to a known threat group it wasn’t deemed important