True Lies

Many times within the industry, we hear things stated repeatedly, or with authority, or both, and simply accept them as fact, as being true. However, a lot of times, these statements of "truth" are based on the aperture and perspective of the individual, and when we look at a broader set of data, we sometimes find that not only are these statements not true, but the exact opposite is, in fact, the case. 

In the early part of this century, I was in contact with a couple of folks (well known names at the time) regarding a virus they'd written. The virus would only impact NTFS file systems, in that it would copy the binary content of an EXE to an alternate data stream (ADS) attached to the EXE, and then zero out the content of the "parent" file. And yes, this was back when you could choose which file system you wanted, FAT or NTFS, and a lot of folks chose FAT, for whatever reason. On FAT file systems, the virus would simply zero out the file. 

When I asked these guys about the virus, they didn't have any concerns about it, because in their view, everyone was aware of ADSs; they thought that this phenomenon was well-known and well-understood by…well…everyone. However, I found that folks I worked with…other DF analysts, admins, and IT staff/customers I engaged with had no idea what an ADS was, what it meant, and how they could impact a system. 

Around the same time, there were issues with Windows servers running web servers whose content, or portions of it, was derived from an MSSQL database. Without input validation, this reliance on the database server would open the organization up to a SQL injection attack, and we saw quite a few of these in the early 2000's. We could see where recon commands were run, via the web logs, and in a couple of instances, we saw where the threat actor created a database table, added 512 byte sections of a binary file to the rows/cells of the table, and when they'd "uploaded" the file, had the database pull out the rows, re-assemble and execute the EXE file. 

At the time of this writing (Aug 2026), we still see this going on. When I say "we", I don't just mean those of us who work for my employer, in our day job…I mean the entire community. We're still seeing this…so, if/when someone makes derisive comment about this method of attack, implying that it's passé, the data shows us that it's still in use, because it still works. 

Something else that seems to be one of those "universal true-isms" that everyone seems to accept as fact is the idea that once IOCs and TTPs associated with a threat actor are shared, that they've been "burned", because the threat actor will see this in the public arena and change what they do, and disappear from sight. I've seen and heard this talked about for more than a decade and a half, and specifically in the past 4+ yrs, I've been neck-deep, every day, in data that shows us otherwise. We've developed indicators from incidents where we thought, "oh, this will be a great detection, let's be sure not to publicize it…", only to Google the indicator and find out someone else already shared it 3 yrs ago. 

Finally, Daniel Woods recently posted on LinkedIn about a study that had been conducted across a wealth of data, from ransomware incidents and published negotiation transcripts. That data pretty much showed that a lot of what many of us thought/said would happen, didn't. In short, we have/had a feeling about how things would work, but looking at the data showed that things weren't actually working out that way.

The point is, there's a lot of things we tend to feel strongly about in this industry, maybe because we've heard others say these things with authority, or because based on our own aperture, this is what we feel the data is telling us. However, these things are very often shown to be false when we look at a broader data set, or just start looking at the data.

This article has been indexed from Windows Incident Response

Read the original article: