{"id":3617,"date":"2017-12-13T19:51:03","date_gmt":"2017-12-13T18:51:03","guid":{"rendered":"http:\/\/securite.intrinsec.com\/?p=3617"},"modified":"2017-12-13T19:51:03","modified_gmt":"2017-12-13T18:51:03","slug":"botconf-2017-jour-3","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-3\/","title":{"rendered":"Botconf 2017 \u2013 Day Three"},"content":{"rendered":"<p>Links to the reports for each day:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.intrinsec.com\/en\/2017\/12\/11\/botconf-2017-jour-1\/\">Botconf 2017 \u2013 Day One<\/a><\/li>\n<li><a href=\"https:\/\/www.intrinsec.com\/en\/2017\/12\/12\/botconf-2017-jour-2\/\">Botconf 2017 \u2013 Day Two<\/a><\/li>\n<\/ul>\n<h1>Formatting for justice: crime doesn&#039;t pay, neither does rich text<\/h1>\n<p>Anthony Kasza \u2022 <a href=\"https:\/\/twitter.com\/anthonykasza\">@anthonykasza<\/a> \u2022 Palo Alto Networks<\/p>\n<p>The speaker presents the Rich Text Format (RTF) developed by Microsoft in 1987. He explains that hexadecimal content as well as functions can be interpreted directly and highlights the techniques used to insert obfuscated code into certain RTF objects.<\/p>\n<p>He then presents several tools for generating RTF files that include executable code, as well as analysis suites such as rtfdump, rtfobj, and pyRTF. Beyond manual analysis, it is possible to identify suspicious patterns using simple Yara rules that monitor values such as insrsid, rsidtbl, ddeauto, etc.<\/p>\n<p>He concludes with the use of the DDEAUTO feature, which we have <a href=\"https:\/\/www.intrinsec.com\/en\/2017\/10\/20\/malware-infections-dde-office\/\">already dedicated an article<\/a>.<\/p>\n<p><a href=\"https:\/\/www.botconf.eu\/wp-content\/uploads\/2017\/12\/2017-AnthonyKasza-Formatting-for-justice.pdf\">Presentation support<\/a>.<\/p>\n<h1>PWS, common, ugly but effective<\/h1>\n<p>Paul Jung \u2022 <a href=\"https:\/\/twitter.com\/__Thanat0s__\">@__Thanat0s__<\/a> \u2022 Excellium<\/p>\n<p>The speaker presents an overview of password-stealing malware (PWS). This malware can generally steal the following information:<\/p>\n<ul>\n<li>Identifiers in the browser<\/li>\n<li>Configuration files<\/li>\n<li>registry database<\/li>\n<li>Cryptocurrency wallets<\/li>\n<li>Serial numbers<\/li>\n<li>Screenshots<\/li>\n<li>Keyboard strokes<\/li>\n<li>etc.<\/li>\n<\/ul>\n<p>These malware programs are distributed quite openly on forums; the situation is such that the authors carefully craft the software&#039;s presentation and provide comparative advertising videos to promote their product. A veritable parallel economy\u2026<\/p>\n<h1>Nyetya malware &amp; MeDoc connection<\/h1>\n<p>Paul Rascagnes \u2022 <a href=\"https:\/\/twitter.com\/r00tbsd\">@r00tbsd<\/a> \u2022 Talos, Cisco<\/p>\n<p>The speaker revisits the Nyetya\/NotPetya incident and explains how Talos was able to trace the infection back to its source. Several of their clients were reporting infections, while the team&#039;s honeypot systems weren&#039;t recording any new infections. Analysts then turned to their clients&#039; IT systems and ultimately identified ME Docs as the common link.<\/p>\n<p>The remainder of the conference presents a detailed analysis of the malware, which recalls information <a href=\"http:\/\/blog.talosintelligence.com\/2017\/06\/worldwide-ransomware-variant.html\">already published<\/a>, and compares the characteristics of Nyetya and BadRabbit in passing:<img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-3618\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2017\/12\/botconf-2017-nyetya-badrabbit.jpg\" alt=\"\" width=\"1200\" height=\"714\" \/><\/p>\n<h1>Math + GPU + DNS = cracking Locky seeds in real time without analyzing samples<\/h1>\n<p>Yohai Einav \u2022 Nominum, Akamai<br \/>\nYuriy Yuzifovich \u2022 Nominum, Akamai<\/p>\n<p>The speakers briefly recap the popularity of ransomware, which stems from a simple reason: we all have data we value on our devices. They then explain the typical operating method of ransomware, which queries its command and control (C&amp;C) server to obtain an encryption key used in the infection. Therefore, if these requests are blocked at the DNS level, it is possible to prevent the malware from functioning.<\/p>\n<p>The problem is that the vast majority of ransomware relies on Domain Generation Algorithms (DGAs) and therefore uses ephemeral domains for communication. Like pseudo-random number generators, these algorithms remain predictable as long as the &quot;seed&quot; with which they were initialized is known. Researchers started with a simple principle: by knowing the algorithm used and observing domain names in real-time use, it is possible to find the seed and thus know all the domains that will be used by an infection campaign.<\/p>\n<p>By using the DNS feed accessible to Nominum (50 million unique domains per day) and knowing the DGA used by Locky, the speakers were able to set up a computing platform that was able to find the seeds used in campaigns in a reasonable time.<\/p>\n<h1>Hunting attacker activities \u2013 methods for discovering, detecting lateral movements<\/h1>\n<p>Keisuke Muda \u2022 JPCERT\/CC<br \/>\nShusei Tomonaga \u2022 <a href=\"https:\/\/twitter.com\/shu_tom\">@shu_tom<\/a> \u2022 JPCERT\/CC<\/p>\n<p>The speakers presented the detection methods used to identify lateral movement within a Windows environment. Their work was based on concrete analyses of five APTs that targeted Japan, noting that recurring patterns consistently appeared.<\/p>\n<p>To do this, they rely on internal Windows logs and those generated by the Sysmon utility, which can provide additional information. The advantage of this approach is to detect patterns using legitimate tools or not directly associated with malware (such as PsExec), which would therefore go undetected by antivirus software.<\/p>\n<p>The result of the research was <a href=\"https:\/\/jpcertcc.github.io\/ToolAnalysisResultSheet\/\">published as a website<\/a>, describing each tool and behavior tested and the associated traces.<\/p>\n<h1>Malware, penny stocks, pharma spam \u2013 Necurs delivers<\/h1>\n<p>Jason Schultz \u2022 <a href=\"https:\/\/twitter.com\/jaesonschultz\">@jaesonschultz<\/a> \u2022 Talos, Cisco<\/p>\n<p>The speaker presents the history of the Necurs botnet. First identified in December 2012, it is responsible for distributing 90% spam emails observed by Cisco. Among the interesting characteristics of this botnet are the following:<\/p>\n<ul>\n<li>Very few IP addresses are reused, making this type of marker useless for tracking or blocking spam.<\/li>\n<li>The distribution appears to be done via addresses derived from data leaks and common &quot;aliases&quot; (e.g., admin, webmaster, info, sales)<\/li>\n<li>Locky is primarily distributed through this botnet.<\/li>\n<\/ul>\n<h1>Thinking outside the (sand)box<\/h1>\n<p>\u0141ukasz Siewierski \u2022 <a href=\"https:\/\/twitter.com\/maldr0id\">@maldr9id<\/a> \u2022 Google<\/p>\n<p>The speaker presents the new security measures implemented in the latest versions of Android, including application sandboxing which allows granularity in the permissions system.<\/p>\n<p>Faced with this situation, malware authors rely on three main methods:<\/p>\n<ul>\n<li>Social engineering: highlighting messages that lead the user to believe that the requested permissions are legitimate.<\/li>\n<li>Exploiting an existing component: Xposed is a framework that allows &quot;hooking&quot; system calls, commonly used by modders to alter the behavior of their devices. If the component is active, malware simply attaches itself to permission requests to grant them automatically. Note that Xposed is a fairly &quot;low-level&quot; component that must be installed manually and therefore does not affect the majority of potential malware targets.<\/li>\n<li>Rooting the terminal: exploiting a vulnerability on the device is ultimately the most direct method to bypass the protections in place.<\/li>\n<\/ul>\n<h1>Advanced threat hunting<\/h1>\n<p>Robert Simmons \u2022 <a href=\"https:\/\/twitter.com\/MalwareUtkonos\">@MalwareUtkonos<\/a> \u2022 Threat Connect<\/p>\n<p>The speaker begins by reminding us that there are several types of Threat Intelligence, each with its own methods and applications:<\/p>\n<ul>\n<li>Tactical<\/li>\n<li>Technical<\/li>\n<li>Operational<\/li>\n<li>Strategic<\/li>\n<\/ul>\n<p>The presentation focuses on the tactical side. Considering that most teams have limited staff, they must work with limited resources and a constant flow of data and information. It is therefore imperative to streamline tasks as much as possible. A few examples are given:<\/p>\n<ul>\n<li>Automate as many low-value tasks as possible (first-level malware analysis).<\/li>\n<li>Facilitate the sharing and traceability of indicators (centralize and version all detection rules)<\/li>\n<li>Prioritize the processing of alerts to focus on the most relevant events (high importance, high indicator reliability)<\/li>\n<li>Define performance indicators to assess the system&#039;s effectiveness and identify areas for improvement.<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Links to the reports from each day: Botconf 2017 \u2013 first day of Botconf [\u2026]<\/p>","protected":false},"author":1,"featured_media":3599,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-3617","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cert"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Botconf 2017 - troisi\u00e8me journ\u00e9e - INTRINSEC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-3\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Botconf 2017 - troisi\u00e8me journ\u00e9e\" \/>\n<meta property=\"og:description\" content=\"Liens vers les comptes rendus de chaque journ\u00e9e : Botconf 2017 &#8211; premi\u00e8re journ\u00e9e Botconf [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-3\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-13T18:51:03+00:00\" \/>\n<meta name=\"author\" content=\"Intrinsec\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Intrinsec\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/\"},\"author\":{\"name\":\"Intrinsec\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/ade590fbc7ad6f413727bae7cd3fb799\"},\"headline\":\"Botconf 2017 &#8211; troisi\u00e8me journ\u00e9e\",\"datePublished\":\"2017-12-13T18:51:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/\"},\"wordCount\":1292,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"articleSection\":[\"CERT\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/\",\"name\":\"Botconf 2017 - troisi\u00e8me journ\u00e9e - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2017-12-13T18:51:03+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/botconf-2017-jour-3\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Botconf 2017 &#8211; troisi\u00e8me journ\u00e9e\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/ade590fbc7ad6f413727bae7cd3fb799\",\"name\":\"Intrinsec\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g\",\"caption\":\"Intrinsec\"},\"sameAs\":[\"https:\\\/\\\/www.intrinsec.com\"],\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/ufhtbqccsz\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Botconf 2017 - Day Three - INTRINSEC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-3\/","og_locale":"en_US","og_type":"article","og_title":"Botconf 2017 - troisi\u00e8me journ\u00e9e","og_description":"Liens vers les comptes rendus de chaque journ\u00e9e : Botconf 2017 &#8211; premi\u00e8re journ\u00e9e Botconf [&hellip;]","og_url":"https:\/\/www.intrinsec.com\/en\/botconf-2017-jour-3\/","og_site_name":"INTRINSEC","article_published_time":"2017-12-13T18:51:03+00:00","author":"Intrinsec","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Intrinsec","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/"},"author":{"name":"Intrinsec","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/ade590fbc7ad6f413727bae7cd3fb799"},"headline":"Botconf 2017 &#8211; troisi\u00e8me journ\u00e9e","datePublished":"2017-12-13T18:51:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/"},"wordCount":1292,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#primaryimage"},"thumbnailUrl":"","articleSection":["CERT"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/","url":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/","name":"Botconf 2017 - Day Three - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#primaryimage"},"thumbnailUrl":"","datePublished":"2017-12-13T18:51:03+00:00","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/botconf-2017-jour-3\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Botconf 2017 &#8211; troisi\u00e8me journ\u00e9e"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/ade590fbc7ad6f413727bae7cd3fb799","name":"Intrinsic","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fde6ed961c7078765b03a213927b5c4001b1cef4787255188f5b502a99e6ddd6?s=96&d=retro&r=g","caption":"Intrinsec"},"sameAs":["https:\/\/www.intrinsec.com"],"url":"https:\/\/www.intrinsec.com\/en\/author\/ufhtbqccsz\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/3617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=3617"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/3617\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=3617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=3617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=3617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}