{"id":228094,"date":"2017-12-12T15:20:11","date_gmt":"2017-12-12T14:20:11","guid":{"rendered":"http:\/\/securite.intrinsec.com\/?p=3603"},"modified":"2017-12-12T15:20:11","modified_gmt":"2017-12-12T14:20:11","slug":"botconf-2017-jour-2","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-2\/","title":{"rendered":"Botconf 2017 \u2013 Day Two"},"content":{"rendered":"<p>Links to the reports for each day:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.intrinsec.com\/en\/2017\/12\/11\/botconf-2017-jour-1\/\">Botconf 2017 \u2013 Day One<\/a><\/li>\n<li><a href=\"https:\/\/www.intrinsec.com\/en\/2017\/12\/13\/botconf-2017-jour-3\/\">Botconf 2017 \u2013 Day Three<\/a><\/li>\n<\/ul>\n<h1>KnightCrawler<\/h1>\n<p>F\u00e9lix Aim\u00e9 \u2022 <a href=\"https:\/\/twitter.com\/felixaime\">@felixaime<\/a> \u2022 GReAT, Kaspersky<\/p>\n<p>The speaker presents his &quot;KnightCrawler&quot; tool, developed to detect &quot;watering hole&quot; attacks. It detects malicious content (such as exploit kits) injected into legitimate websites. Three use cases are considered:<\/p>\n<ul>\n<li>Direct injection of contents<\/li>\n<li>Manipulating a booby-trapped script<\/li>\n<li>Display of malicious advertisements<\/li>\n<\/ul>\n<p>Analyzing these attacks is complicated by the fact that, being rather targeted, several conditions must generally be met to trigger an attack: IP geolocation, browser fingerprinting, etc. The speaker therefore set up a distributed infrastructure to automate searches for suspicious content, before concluding with a few examples of attacks identified by his tool.<\/p>\n<p><a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2017\/12\/2017-FelixAime_Kinghtcrawler.pdf\">Presentation support<\/a><\/p>\n<h1>The (makes me) WannaCry Investigation<\/h1>\n<p>Alan Neville \u2022 <a href=\"https:\/\/twitter.com\/abnev\">@abnev<\/a> \u2022 Symantec<\/p>\n<p>The speaker begins by putting the WannaCry infection figures into perspective in relation to recent major &quot;epidemics&quot;:<\/p>\n<ul>\n<li>2003: Blaster reaches 16 million machines<\/li>\n<li>2008: Conficker affects 15 million systems<\/li>\n<li>2017: WannaCry only caused 300,000 victims<\/li>\n<\/ul>\n<p>He continues with a technical description of the malware, before presenting internal feedback from Symantec. Their initial detections date back to February 2017, when it was being distributed without ETERNALBLUE. A campaign was then identified in March\/April, where it was deployed via <em>backdoors<\/em> already in place. Regarding the May attack, the high speed of malware propagation made it impossible to identify the initial vector.<\/p>\n<h1>Malware Uncertainty Principle<\/h1>\n<p>Maria Jose Erquiaga \u2022 <a href=\"https:\/\/twitter.com\/MaryJo_E\">@MaryJo_E<\/a> \u2022 Cuyo University<\/p>\n<p>The speaker described a malware analysis project targeting systems using HTTPS for communication. Initially, they set up a relatively simple analysis lab using the mitmproxy tool. Subsequently, sample selection was performed by scanning TLS blacklists to identify and obtain the malware responsible for these communications.<\/p>\n<p>The presentation then moves on to several encountered cases, focusing in particular on instances where malware uses a binary protocol below the TLS layer. In such cases, simple traffic analysis is no longer sufficient; in-depth malware analysis is necessary.<\/p>\n<h1>Knock Knock\u2026 Who\u2019s there? admin admin, Get In!<\/h1>\n<p>Anna Shirokova \u2022 <a href=\"https:\/\/twitter.com\/AnnaBandicoot\">@AnnaBandicoot<\/a> \u2022 Cisco<\/p>\n<p>The speaker presents brute-force attacks in the CMS landscape. Although relatively unsophisticated, the sheer number of accessible, unprotected sites makes these attacks profitable, judging by their current prevalence.<\/p>\n<p>During the first part of her presentation, she listed the history of the most well-known &quot;brute-forcer&quot; malware such as FortDisco, Mayhem, and Aethra. Among the methods frequently used are the following:<\/p>\n<ul>\n<li>Vertical brute-force: searches for multiple identifiers on a site at once; ;<\/li>\n<li>Horizontal brute-force: executes the same pair of credentials on different sites. This method has the advantage of limiting the frequency of attempts on individual sites and therefore has a greater chance of bypassing brute-force protections.<\/li>\n<\/ul>\n<p>She then focused on the Sathurbot botnet, first detected in 2013. It is built on a modular principle, with &quot;backdoor,&quot; &quot;downloader,&quot; and &quot;web crawler&quot; functionalities. The latter uses advanced operators from several search engines to find exposed WordPress and Joomla! CMSs.<\/p>\n<h1>Automation Attacks at Scale<\/h1>\n<p>Will Glazier \u2022 <a href=\"https:\/\/twitter.com\/WGlazier21\">@WGlazier21<\/a> \u2022 Stealth Security Inc<\/p>\n<p>Following on from the previous conference, the speaker presented a market of automated attack tools such as brute-forcers and Trojans. These tools come with pre-configured settings containing pre-registered targets. An analysis of these settings allowed researchers to determine that 10% of the targets are among the top 1,000 most visited websites in the world (Alexa ranking). Tests conducted by the presenter showed that a simple script scanning Pastebin for specific patterns returned 20,000 identifiers per day, highlighting the effectiveness of methods that are far from sophisticated.<\/p>\n<p>The speaker then went on to describe additional ways to combat this family of threats:<\/p>\n<ul>\n<li>Analysis of HTTP requests to find patterns specific to attack tools; ;<\/li>\n<li>Machine learning applied to HTTP sessions to identify the behaviors of simulated browsers (e.g., Selenium or PhantomJS); ;<\/li>\n<li>Threat intelligence to cut off the attacker&#039;s sources (e.g., identify a data leak and reset account passwords before they are exploited); ;<\/li>\n<li>Analysis of behaviors beyond individual requests.<\/li>\n<\/ul>\n<h1>Malpedia: A Collaborative Effort to Inventorize the Malware Landscape<\/h1>\n<p>Daniel Plohmann \u2022 <a href=\"https:\/\/twitter.com\/push_pnx\">@push_pnx<\/a> \u2022 Fraunhofer FKIE<\/p>\n<p>The speaker presents a malware encyclopedia project. The idea is to classify each piece of malware uniquely, referencing the platform it affects, the type of malware, and any associated Yara rules.<\/p>\n<p>In order to maintain a healthy corpus, the first step is to use information focused on static analysis to obtain easily reproducible results.<\/p>\n<p>Beyond that, database enrichment follows a few fundamental principles:<\/p>\n<ul>\n<li>Ensure that the content is representative; ;<\/li>\n<li>Being multi-platform oriented \u2013 even though Windows is very well represented; ;<\/li>\n<li>Use non-packaged content; ;<\/li>\n<li>Apply precise labels to the samples; ;<\/li>\n<li>Document the information; ;<\/li>\n<li>Control the distribution of and access to the database.<\/li>\n<\/ul>\n<p>The project is currently online: <a href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\">https:\/\/malpedia.caad.fkie.fraunhofer.de<\/a><\/p>\n<p>Access to generic information is free, while access to the extended section is exclusively subject to validation by the authors.<\/p>\n<p><a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2017\/12\/2017-DanielPlohmann-Malpedia.pdf\">Presentation support<\/a><\/p>\n<h1>YANT \u2013 Yet Another Nymaim Talk<\/h1>\n<p>Sebastian Eschweiler \u2022 Crowdstrike<\/p>\n<p>The speaker presents his experience analyzing the Nymaim malware. Unlike the unsophisticated techniques discussed in other conferences, this malware possesses several anti-analysis features such as obfuscation, encryption of its own code, the use of anti-sandbox techniques, and the execution of x64 code from x86 instructions.<\/p>\n<p>The presenter details several of the techniques used by the malware and how to decode them.<\/p>\n<h1>Augmented Intelligence to Scale Humans Fighting Botnets<\/h1>\n<p>Yuriy Yuzifovich \u2022 Nominum, Akamai<\/p>\n<p>The speaker focuses on DNS traffic and works with various providers, gaining access to over 100 billion DNS queries per day. The analytics team uses this data to combat botnets by monitoring the use of temporary domain names (DGAs) employed by malware.<\/p>\n<p>They developed a tool that primarily relies on known DGA algorithms to predict the domains used for communication between a bot and its C&amp;C client. The tool also monitors the emergence of new domain names and applies machine learning algorithms to discern patterns that may originate from unknown DGAs, and classifies domain names according to known families or correlations found between values.<\/p>\n<h1>Stantinko: a Massive Adware Campaign Operating Covertly since 2012<\/h1>\n<p>Matthieu Faou \u2022 ESET<br \/>\nFr\u00e9d\u00e9ric Vachon \u2022 ESET<\/p>\n<p>The speakers presented the results of their study of the Stantinko botnet. The investigation began with a single report from a specific client concerning strange behavior in their IT system.<\/p>\n<p>The analysis first identified the main component: adware that injects advertisements into victims&#039; browsers. However, the malware doesn&#039;t stop there; it also installs a modular backdoor system, integrating features such as installing malicious browser extensions, SEO fraud, and brute-force attacks.<\/p>\n<p>The malware also features anti-detection and anti-analysis mechanisms, including the encryption of code and communications with a unique key per infection.<\/p>","protected":false},"excerpt":{"rendered":"<p>Links to the reports from each day: Botconf 2017 \u2013 first day of Botconf [\u2026]<\/p>","protected":false},"author":1,"featured_media":3599,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,19],"tags":[],"class_list":["post-228094","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cert","category-soc-securite-operationnelle"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Botconf 2017 - deuxi\u00e8me journ\u00e9e - INTRINSEC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Botconf 2017 - deuxi\u00e8me journ\u00e9e\" \/>\n<meta property=\"og:description\" content=\"Liens vers les comptes rendus de chaque journ\u00e9e : Botconf 2017 &#8211; premi\u00e8re journ\u00e9e Botconf [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-2\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-12T14:20:11+00:00\" \/>\n<meta name=\"author\" content=\"Intrinsec\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Intrinsec\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/\"},\"author\":{\"name\":\"Intrinsec\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/ade590fbc7ad6f413727bae7cd3fb799\"},\"headline\":\"Botconf 2017 &#8211; deuxi\u00e8me journ\u00e9e\",\"datePublished\":\"2017-12-12T14:20:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/\"},\"wordCount\":1425,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"articleSection\":[\"CERT\",\"SOC S\u00e9curit\u00e9 Op\u00e9rationnelle\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/\",\"name\":\"Botconf 2017 - deuxi\u00e8me journ\u00e9e - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2017-12-12T14:20:11+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-2\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Botconf 2017 &#8211; deuxi\u00e8me journ\u00e9e\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/ade590fbc7ad6f413727bae7cd3fb799\",\"name\":\"Intrinsec\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"caption\":\"Intrinsec\"},\"sameAs\":[\"https:\\\/\\\/www.intrinsec.com\"],\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/ufhtbqccsz\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Botconf 2017 - Day Two - INTRINSEC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-2\/","og_locale":"en_US","og_type":"article","og_title":"Botconf 2017 - deuxi\u00e8me journ\u00e9e","og_description":"Liens vers les comptes rendus de chaque journ\u00e9e : Botconf 2017 &#8211; premi\u00e8re journ\u00e9e Botconf [&hellip;]","og_url":"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-2\/","og_site_name":"INTRINSEC","article_published_time":"2017-12-12T14:20:11+00:00","author":"Intrinsec","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Intrinsec","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/"},"author":{"name":"Intrinsec","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/ade590fbc7ad6f413727bae7cd3fb799"},"headline":"Botconf 2017 &#8211; deuxi\u00e8me journ\u00e9e","datePublished":"2017-12-12T14:20:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/"},"wordCount":1425,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#primaryimage"},"thumbnailUrl":"","articleSection":["CERT","SOC S\u00e9curit\u00e9 Op\u00e9rationnelle"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/","url":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/","name":"Botconf 2017 - Day Two - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#primaryimage"},"thumbnailUrl":"","datePublished":"2017-12-12T14:20:11+00:00","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Botconf 2017 &#8211; deuxi\u00e8me journ\u00e9e"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/ade590fbc7ad6f413727bae7cd3fb799","name":"Intrinsic","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","caption":"Intrinsec"},"sameAs":["https:\/\/www.intrinsec.com"],"url":"https:\/\/www.intrinsec.com\/en\/author\/ufhtbqccsz\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/228094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=228094"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/228094\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=228094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=228094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=228094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}