I had the pleasure of presenting at #FIRSTCTI25 in Berlin:
"The Art of Pivoting – How You Can Discover More from Adversaries with Existing Information."
The talk explored how unconventional indicators, like cookie names, QR codes, HTTP headers (HHHash), DOM structures, and reused Google Analytics IDs, can reveal surprising links across threat actor infrastructure and behavior.
We also shared real-world insights from our crawling and analysis with AIL, including:
- How “weak” indicators can gain strength through composite correlation
- Unexpected metadata reuse across Tor services and social platforms
- How AIL enables more creative and effective pivoting workflows
Slides https://www.ail-project.org/assets/img/slides/the-art-of-pivoting.pdf
#threatintel #threatintelligence #cti #opensource #cybersecurity #darkweb
@misp @ail_project @circl
Thanks to @terrtia for the crazy discussions around correlations!