

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>http://localhost:4000/</id>
  <title>LIA Insights</title>
  <subtitle>Insights and analysis from LIA observations</subtitle>
  <updated>2026-06-03T18:40:32+02:00</updated>
  <author>
    <name>LIA</name>
    <uri>http://localhost:4000/</uri>
  </author>
  <link rel="self" type="application/atom+xml" href="http://localhost:4000/feed.xml"/>
  <link rel="alternate" type="text/html" hreflang="en"
    href="http://localhost:4000/"/>
  <generator uri="https://jekyllrb.com/" version="4.3.4">Jekyll</generator>
  <rights> © 2026 LIA </rights>
  <icon>/assets/img/favicons/favicon.ico</icon>
  <logo>/assets/img/favicons/favicon-96x96.png</logo>


  
  <entry>
    <title>Context Graph: Visualize LIA Intelligence</title>
    <link href="http://localhost:4000/posts/context-graph/" rel="alternate" type="text/html" title="Context Graph: Visualize LIA Intelligence" />
    <published>2026-06-03T09:02:23+02:00</published>
  
    <updated>2026-06-03T09:02:23+02:00</updated>
  
    <id>http://localhost:4000/posts/context-graph/</id>
    <content src="http://localhost:4000/posts/context-graph/" />
    <author>
      <name>LIA</name>
    </author>

  
    
    <category term="updates" />
    
  

  <summary>Threat intelligence has always been about connecting dots. Now you can actually see them in an interactive relationship map built from tasks, payload, detections and infrastructure data.
Today we’re shipping the Context Graph — an interactive relationship visualization layer directly in LIA.



You can start from a blank graph and add a domain, IP address, URL or SHA256 hash. The graph automati...</summary>

  </entry>

  
  <entry>
    <title>LIA Implements Malcat Kesakode for Payload Identification</title>
    <link href="http://localhost:4000/posts/malcat-kesakode/" rel="alternate" type="text/html" title="LIA Implements Malcat Kesakode for Payload Identification" />
    <published>2026-03-10T08:02:23+01:00</published>
  
    <updated>2026-03-10T08:02:23+01:00</updated>
  
    <id>http://localhost:4000/posts/malcat-kesakode/</id>
    <content src="http://localhost:4000/posts/malcat-kesakode/" />
    <author>
      <name>LIA</name>
    </author>

  
    
    <category term="updates" />
    
  

  <summary>Malware is constantly evolving in an effort to evade detection and identification, using different kinds of obfuscation and morphing that makes creating a reliable signature more challenging.

To increase the detection capabilities of downloaded payloads, LIA has partnered with Malcat to implement Kesakode in the payload analysis pipeline.

Kesakode - Fuzzy Detections
Compared to static signatu...</summary>

  </entry>

  
  <entry>
    <title>LIA Update: Bare Metal Sandbox Deployment for Payload Execution</title>
    <link href="http://localhost:4000/posts/major-update/" rel="alternate" type="text/html" title="LIA Update: Bare Metal Sandbox Deployment for Payload Execution" />
    <published>2025-12-04T08:02:23+01:00</published>
  
    <updated>2025-12-04T08:02:23+01:00</updated>
  
    <id>http://localhost:4000/posts/major-update/</id>
    <content src="http://localhost:4000/posts/major-update/" />
    <author>
      <name>LIA</name>
    </author>

  
    
    <category term="updates" />
    
  

  <summary>In September, we mentioned that new features were in the works, and we are excited to share that they are now live. Over the past few months, we have focused heavily on backend improvements and enhancing our existing analysis pipeline. A major part of this effort has been the addition of a new sandbox environment that helps us extract more value from the payloads sourced from tracked families. ...</summary>

  </entry>

  
  <entry>
    <title>Correlating Vidar Stealer Build IDs Based on Loader Tasks</title>
    <link href="http://localhost:4000/posts/vidar-build-id-correlation/" rel="alternate" type="text/html" title="Correlating Vidar Stealer Build IDs Based on Loader Tasks" />
    <published>2024-10-17T09:02:23+02:00</published>
  
    <updated>2024-10-17T09:02:23+02:00</updated>
  
    <id>http://localhost:4000/posts/vidar-build-id-correlation/</id>
    <content src="http://localhost:4000/posts/vidar-build-id-correlation/" />
    <author>
      <name>LIA</name>
    </author>

  
    
    <category term="intelligence" />
    
    <category term="correlation" />
    
  

  <summary>Botnet Identifiers

When running a botnet, threat actors typically want to group bots together to keep track of campaigns or separate access in the administrative panel between users. This is the case in Malware-as-a-Service (MaaS) offerings where the malware author is providing threat actors access to existing infrastructure to manage bots and access information specific to their botnets. When...</summary>

  </entry>

</feed>


