RSSAmplifier

Blog

pyosec

Security Research

pyosec.comRSS feed ↗10 posts

Latest posts

Detecting Phishing using Visual Similarity

I’m back from Prague, having just presented my current research on detecting phishing using visual similarity. If you want to check it out, slides and code can be found on the presentations page.

QuBit Prague, May 26-28, 2025

2024 and 2025

I presented new work on crawling URLs at scale and identifying similar activity using screenshot similarity at DeepSec in November, 2024. I am continuing to work on this topic, using LLMs and crawling optimization to better build it out. I’ll be presenting again at Qubit Prague, May 22, 2025. My... Read More

Searching for Phishing using Screenshot Similarity

I’m currently building a process and interface to crawl known-bad phishing pages, where I take a screenshot and collect other data. That data is going to be used to find similar-looking screenshots and similar-behaving network traffic from streaming logs of visited URLs. This is initially for a talk I’m doing... Read More

Goals: Security for all

I’ve been thinking about this for a while. I have a fantastic job working with Cisco Talos and hope to keep doing it for a while. My team is great and the work is fulfilling, challenging, fun, and satisfies my passions to help make cybersecurity better for a lot of... Read More

DeepSec 2023

I had the wonderful opportunity to once again present my current work at Deepsec, in Vienna in November, 2023. I presented new work on URL Analysis at Scale. The research resulted in building a web app and API that can use spelling, natural language processing, machine learning, and some other... Read More

Ransomware Over Time

I used data from the (now defunct) malware wiki and cyber.nj.gov to create this timeline, which I keep up to date when possible. The timeline is generated using timeline.knightlab.com. The data I managed to collect from the malware wiki before it disappeared can be downloaded as a CSV here

Webinar on Threat Hunting

Today, I took part in a Cisco webinar on threat hunting processes and thoughts. Check it out here! Bust Threats or Risk Getting Busted .

Qubit Bulgaria

I presented on automating threat intelligence yesterday at QuBit in Sofia, Bulgaria. This was my first time giving this presentation, and as usual (for me), I was coding up to the moment I walked on stage. I thought it went really well and learned a lot from the audience. What... Read More

Which Providers Have the Most Phishing Content?

Phishing is an efficient method for an attacker to deliver malware or harvest credentials from unsuspecting victims. By sending out a mass or targeted email designed to look like it came from a bank or other legitimate source, an attacker can acquire a fair number of user credentials or deliver... Read More