Bitbison discovered a new standalone, self-propagating Mini Shai-Hulud variant during a real-world React2Shell campaign with multiple execution paths, persistence mechanisms and extensive credential theft.
Bitbison gave us the complete causal visibility to detect and analyze all this data at scale.
Full analysis: https://t.co/992khI1QUb
I have seen Bitbison, and it is an incredible thing. Being able to see causality across your servers and network will unlock so many capabilities. Doing it for builds creates an entirely new level of security detection for supply chain attacks - literally knowing that a file was (or wasn't) created by the 'normal' chain of causality that results in a build.
Congrats to @0xF390 and the team. I'm a believer.
We're public! https://t.co/slej0PtCmS
A few people thought it was a little crazy to transition from my academic career to a startup. I've spent much of my professional life trying to have impact by pushing the state of the art. But Bitbison is a clear opportunity to completely reimagine the technological underpinnings of systems security. I'm excited to be part of a team pushing forward what's possible here, while solving some of the most interesting technical problems I've worked on.
Excited to be back to my roots in systems security after 25 years of being away, working alongside trusted friends and colleagues on https://t.co/51XoYET0xX.
This is the hardest technical problem I've worked on. It has required rethinking everything from the underlying data model to memory management and storage representation. After two years of research and development, and with the support of incredible design partners, advisors, investors and early users, we're ready to open Bitbison to more design partners.
Bitbison records the complete execution history of a system at production scale, making a fundamentally better approach to detection and investigation feasible. It delivers complete preservation of causal activity on your system at production scale, at a fraction of the cost of existing runtime monitoring solutions that typically capture less than 1% of system behavior.
Today we're opening early access for two offerings:
- Bitbison for Servers
- Bitbison for Build
I'll be sharing much more about the product, the engineering challenges and what we've built over the coming weeks.
Thank you to everyone who has believed in us and helped make this possible. We couldn't have done it without our design partners, advisors, investors and early supporters.
Thanks to @dougallj 's input, https://t.co/oouZdpjCOa 's neon code has been tuned for the M1's 3.2 GHz firestorm (P cores).
The new code computes the same eps-universal hash function at a peak throughput 16.5 b/c (data in L1). That's over 49 GB/s, with collision bounds!
@tlipcon@pkhuong LLDB / GDB are best bets, but heavy-weight as you point out. Next is https://t.co/7MD36qdjLy but it is out of date and has some accuracy issues. Otherwise, Backtrace, which will work well for this use-case (we also provide access to the core debugging library, C interface).
Happy to finally publish my work on the two vulnerabilities in the Linux kernel I've found: CVE-2022-1015 and CVE-2022-1016! I'll be talking some background, a deeper look into nf_tables, and a local privilege escalation PoC! (code on my github)
https://t.co/8cummKtTHT
Have you ever wanted to measure your reorder buffer size, without needing to compile and run a pesky native app? Then try the Web ROB Size Tester today! It's not very accurate, but it is online!
https://t.co/Ww90gJJUhL