Security Confidential S19 E0 Diyar Saadi

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Diyar Saadi Ali. Diyar is a cybersecurity professional specializing in cybercrime investigations, SOC operations, and malware analysis. A contributor to the MITRE ATT&CK framework, Diyar has helped strengthen global threat intelligence efforts and defensive strategies. Diyar regularly speaks at international cybersecurity conferences, including Arab Cyber Security, DeepSec, GISEC, BlackHat, and SulyCon, contributing to the advancement of the global cyber community.

00:00 Intro

02:26 Our Guest

03:42 Learning Cybersecurity in Iraq

07:40 The MITRE Attack Framework: Is that all the knowledge we know? 

11:30 There are still tons of unknown vulnerabilities

13:30 You can’t fake motivation

17:00 Defenders are to blame

19:16 Who is coming up with Malware?

22:10 Every crime leaves a trace

24:12 AI is making malware easy

29:00 Governance and Trust

38:02 Presentations and News from Diyar

Transcript

Manoj Tandon:
Hello everyone, this is your host Manoj Tandon. Welcome to another episode of Dark Rhiino Security Confidential. Today we have a really cool guest from another part of the world. He is a cybersecurity expert, very familiar with cybercrime, SOC operations, and malware analysis. But before I introduce him, I have to ask you guys to hit the like and subscribe button, because that’s what allows us to bring this content to you. So show us some love. Please hit the like and subscribe buttons.

Now, without further ado, I’d love to introduce Diyar Saadi. Diyar is a cybersecurity professional specializing in cybercrime investigation, SOC operations, and malware analysis. He is a contributor to the MITRE ATT&CK framework, and he has strengthened global threat intelligence efforts and defensive strategies. He regularly speaks at international cybersecurity conferences, including Arab Cybersecurity, DeepSec, GISEC, and Black Hat, helping advance the knowledge and understanding of cybersecurity for all of us.

Thank you, Diyar, for joining us. I know it’s late in your part of the world. Thank you for being here.

Diyar Saadi:
Thank you. It’s my pleasure.

Manoj Tandon:
So you’ve got to give us a little bit about your background because we’ve gotten a little familiar with your work. How did you start off in this? Or how did you land here?

Diyar Saadi:
First of all, thanks for having me today. It’s a real pleasure as well. I am Diyar Saadi from Iraq. I’m 24 years old. My history in cybersecurity goes back 11 to 12 years ago, when my mindset was curious about how stuff works, how these devices operate behind the scenes.

That made me dive into computers and the security field. In the beginning, I didn’t know how to shut down a computer correctly, but step by step, after connecting to the internet, meeting some friends, joining forums, and watching videos on YouTube, I started focusing on forensics and SOC operations, then writing articles and sharing insights into the threat actor mindset in different international magazines and journals to help protect security infrastructures and users from digital threats.

Manoj Tandon:
Wow. And at such a young age, you’ve accomplished so much. So the question is, for our audience that’s listening, especially being in Iraq, people in the United States have this image of Iraq. It’s quite an accomplishment to learn something in a high-tech field, just from the mindset people have.

What would you suggest to other listeners if they want to really get into cyber? What should they be doing? What would be your recommended path, now that you’ve done it?

Diyar Saadi:
Actually, in Iraq in the past, especially 10 years ago, there were fewer resources and fewer articles to dive into because we had some problems with language. Our native language is Arabic, and the articles were in English. That was quite an issue for beginners at that time.

But nowadays there are translators and AI. You can ask a question and get an answer. My recommendation for everyone—beginners, intermediate, and advanced people—is to have familiarity and a good foundation in six areas. One of them is operating system internals. The second one is Windows internals. The third one is cryptography, because maybe you face encryption blobs or encrypted patterns. The fourth is the foundations of programming, especially C or C++, or basic assembly, because it can help a lot. The fifth is networking knowledge. If you don’t know what DNS is, what HTTP is, what FTP is, then you don’t understand the full picture. The sixth is curiosity—having that drive to understand how stuff works.

If you have system knowledge, Windows internals knowledge, programming knowledge, cryptography knowledge, and networking knowledge, that helps you a lot. For example, when you capture packets in Wireshark, if you don’t know what DNS is or what HTTP is, you won’t understand the full picture and maybe you will be bypassed in a few minutes. Those are very important things, and I always suggest them to everyone who asks me.

Manoj Tandon:
One of those is super interesting to me because it brings me back to when I was a young person, and that is you suggested learning assembly and C. In university, that was something that was taught in my era. I don’t think that’s even taught anymore. So how does one get that knowledge?

Diyar Saadi:
As you mentioned, most people nowadays jump into Python, Go, or Rust because they can automate very easily. But actually, if someone starts learning with Visual Basic at the beginning of programming, then jumps to C#, because if you learn Visual Basic, you will learn C# very easily since there are only some different syntaxes like semicolons or Console.WriteLine and other things, then you can jump to C or C++ or basic assembly to understand the full picture.

Because actually, when you compile a C binary in IDA or Ghidra, there is no Python, no Go, no Rust. There is only pseudo-code of C, and you have to understand what is going on behind the scenes of the program.

Manoj Tandon:
That is very cool. So you’ve contributed to the MITRE ATT&CK framework. Is that the total knowledge we have about cyberattacks and how they occur, or are there a lot of things that are not on the MITRE ATT&CK framework?

Diyar Saadi:
MITRE ATT&CK contains a lot of knowledge for someone who wants to understand the threat landscape on the internet or in the digital space. But actually, there are still some underground techniques that haven’t been revealed in the MITRE framework.

My own technique is called URL masking. It’s about how a threat actor masks a URL to infiltrate the mindset of users. For example, HR or a human resources team might receive an email or document. In this case, the threat actor can do file masking or URL masking to infiltrate the psychology of the user and get them to click on the link.

There are a lot of other techniques that nowadays red teamers and security engineers publish on LinkedIn, GitHub, or in conference talks that are not yet included in the MITRE framework or in other models. Cybersecurity, or cyberwarfare, is always like a cat-and-mouse game.

Manoj Tandon:
That’s fascinating because when you listen to a lot of the pundits out there, they stick to well-established frameworks and approaches. But you’ve said something that departs from what those pundits say, and you’ve used the word “mindset” a few times. Whether that is the mindset of the user to get them to click on the link, or the mindset of a hacker, that is a subject that is not taught. Without it, how do you create a good defensive posture? How do you acquire that knowledge? How does a hacker think? What’s your secret?

Diyar Saadi:
Actually, it requires some kind of biological and psychological understanding, not very deep, but fundamental. For example, when your friend sends you a link, your friend is a trusted sender. Your decision-making brain says, “Okay, it’s a trusted person. No worries, click the link.” But you don’t know that your friend may be compromised.

That’s quite interesting because there are a lot of cases where threat actors compromise CEO emails, HR team emails, and send malicious documents to other teams, and they click on them because the attacker infiltrates the decision-making part of the brain of the person opening the document.

The secret is to understand the threat actor mindset. Every human has two sides: the evil one and the angel one. Every person has both. You have to put yourself in the evil shoes and ask how they are thinking. That’s very important.

Every human has two sides. It’s like a knife. You can use it to make a salad, but you can use it to harm someone.

Manoj Tandon:
Absolutely. But when you think about the things you mentioned—understanding internals, understanding C, understanding Windows, understanding networking—that is a lot of disciplines. And you look at how, for example, Russia infiltrated Ukraine early on. To get inside that mindset, you’d have to get inside the mindset of hundreds of people because they had teams looking at this.

People are going to say, “I’m just going to throw up my hands. I can’t do anything. I’m just going to do basic cybersecurity because I can’t fight a threat like that.” What do you do to counter something like that?

Diyar Saadi:
In a large-scale attack, there is not only one person. Maybe there is one person for reconnaissance, passive and active. Maybe another person is only for phishing campaigns. Another one may handle delivery. Another one may develop malware in a different language. So a large-scale attack usually is not the work of one person.

Even on the defense side, we have to be one team in blue teaming, and also have the red team mindset. That’s why red teaming came to play in this area. Red teaming simulates APTs and real threats against the blue team. The blue team is the defenders.

In this case, the blue team has to put themselves into the red team mindset. For example, maybe we have Bitsadmin or certutil or utilities used to fetch content from the internet. Blue teams can use those utilities for legitimate purposes, but red teams may abuse Bitsadmin or PowerShell or other utilities to download and execute malicious payloads.

I think in the security community we have great people and smart people, but what we miss in most cases is mindset. There are a lot of vulnerabilities every day, a lot of CVEs every day assigned into databases. But there are many vulnerabilities still unknown, even to the vendors.

Manoj Tandon:
One thing the red team cannot simulate is motivation. If I’m on the red team, I’m not really playing to cause real harm. But if I’m a bad actor, I’m motivated very differently. That’s a tough one to simulate.

Diyar Saadi:
Actually, every human action has motivation. This podcast between me and you has motivation. Our motive is to share knowledge on the internet and to protect critical infrastructure and users from digital threats.

It is hard to put yourself in the attacker’s shoes, but sometimes we have to make that sacrifice to understand the full picture. One quote I like is that you don’t learn swimming by reading about water. You have to jump into it. No one learns swimming by reading how water works. You have to jump into the water to understand the full picture.

So red teamers sometimes put themselves into the attacker’s shoes with a motive in the lab or environment in order to understand the full picture, because every attacker has motivation.

Manoj Tandon:
Very much so. And you chose one of the hardest areas—after the attack is done—to investigate these cybercrimes and do malware analysis. In that instance, attribution, as we know in this industry, is very, very difficult. So why go into cybercrime? Why go into the hardest part of this thing?

Diyar Saadi:
Because actually, if someone wants to be great in life, he or she has to face bad situations. In that case, they gain experience. That’s a key point.

It’s true that attribution is one of the hardest challenges in this area, and I blame the defenders in some cases. People may ask why. Because defenders make attribution harder. Look at the MITRE framework as an example: they have lists of threat actor groups, software, TTPs, and other methods. In this case, one group can simulate and copy another group’s techniques into its own operation.

So when a security researcher comes in, they may think this attack was done by one APT while it was actually done by another. That is the main issue. Nowadays, because of the MITRE framework and other models, threat actors or groups can copy and clone the techniques and methods of other groups into their own operation. That makes attribution very hard.

We also have ransomware groups trying to steal other groups’ source code, making some edits, and redeploying the ransomware service against companies or governments or institutions. That’s a defender problem in this area. It’s like a knife with two sides.

Manoj Tandon:
Who are the geniuses that are coming up with this malware or the techniques for phishing? These are very technical things. You look at ransomware-as-a-service, and there’s this notion that you can go throw some money on the dark web and in a half hour you’re ready to launch a ransomware attack. But who are the people actually coming up with these technical advancements?

Diyar Saadi:
Threat actors are actually divided into so many parties: nation-states, APTs, script kiddies, and ransomware-as-a-service actors. Some of them are basically script kiddies in some cases.

Nowadays, we are living in the age of AI models. There is Evil GPT, WormGPT, and other offensive AI models that someone can use or jailbreak to produce harmful content like writing exploits or ransomware. So it’s hard to understand who is behind a particular ransomware group because of copycat behavior—copying and cloning the techniques and methods of other groups. Attribution, as you mentioned before, is one of the most challenging things in this area.

Manoj Tandon:
Is it possible to launch an attack and mask your tracks so effectively that you can never be tracked?

Diyar Saadi:
In our culture, we have a quote that the line of a lie is very short. Every crime leaves a trace. Every activity leaves a trace in the physical world and in the digital world. Maybe it will stay anonymous for many years, but finally attackers may make some OPSEC failures and investigators find the person or group behind the attack. It’s just a matter of time.

There is nothing hidden on the internet. Our anonymity is done when we connect to the internet.

Manoj Tandon:
So when you go into an organization that has had an attack take place, where do you begin your investigation?

Diyar Saadi:
There are some questions investigators should ask themselves: what, why, how, and when. That’s key. How did it happen? When did it happen? What happened? Those questions give you the big picture about the full attack flow.

For example, if an organization was infected by ransomware, then how did it happen? Maybe the HR team clicked a malicious document created as a PDF or Word file. Those questions show you the picture.

You look at event logs as well, though they are not always available because attackers use anti-forensics techniques like wiping logs or timestomping. But the first question I ask when I face an incident in an organization or for an individual is: how did it happen? What did you do? Did you open a link? Did you open a document? Did you receive a malicious file?

Cyberattacks and cyber incidents are like a puzzle. You have to connect each dot together to give a full sentence about what happened.

Manoj Tandon:
Absolutely. When you look at malware development, what advances are you seeing in that arena that give you real concern?

Diyar Saadi:
Malware development is quite an interesting topic because it helps us understand the threat actor mindset. Actually, the final drop in almost every attack is malware. For example, they send you a malicious script. Why? To download malware. They send you a malicious document—PDF, DOC, Excel file, PowerPoint—to install malware.

It is very important for malware researchers to understand how malware works, which techniques are used, and which methods are used to deploy attacks. Maybe one attacker researches and investigates vulnerable drivers, libraries, or files in Windows and uses them for exploitation. Another person may just craft Metasploit or Cobalt Strike shellcode, put it into C code, and deploy it using PowerShell or Python or a shell script.

Every person has a different mindset. Even writers have different writing styles. There are very few cases where two actors have exactly the same mechanism for deployment.

Manoj Tandon:
Is AI accelerating the development of malware?

Diyar Saadi:
Yes. It makes it very easy.

Manoj Tandon:
Really? The AI companies say you can’t abuse their systems because there are safeguards.

Diyar Saadi:
That doesn’t make sense. Threat actors or any person with a different mindset can jailbreak AI to do harmful things. There are many things I shouldn’t go into deeply because of policy, but if someone says AI can’t be abused for offensive operations, that simply doesn’t make sense. It can.

Prompt injection, jailbreaks, or even just giving prompts for basic code can lead to keyloggers or info stealers.

Manoj Tandon:
But those are so basic. Keyloggers are ancient technology. That’s like cybersecurity 101.

Diyar Saadi:
I have a different mindset about that. No one talks about how you did it. They care about the outcome. The outcome matters. It’s like a football game. The important question is who won. No matter how skillfully the game was played, the outcome is what matters.

Sometimes a threat actor with a basic keylogger can infiltrate a big organization while another sophisticated group cannot. So in cybersecurity and cyber incidents, the outcome is very important. It’s good to know whether Metasploit or Cobalt Strike was used, but the key point is: was the organization compromised or not?

Manoj Tandon:
I would have figured by now that people would know how to defend against these basic things, but as we know, it’s the basic flaws that create a lot of problems. People still haven’t changed default admin passwords on a lot of systems. What do you do with that?

Diyar Saadi:
That is called misconfiguration. It happens everywhere—in CCTV, IoT devices, and simple environments.

It is very important for security researchers and users to have the basic foundation of Security 101, not only to be security engineers, but to protect themselves from cyber threats. Actually, there are millions of devices nowadays connected to the internet without even the user or organization knowing about it. You can look at Shodan, Netlas, Censys, FOFA, ZoomEye, and many internet-facing threat intelligence platforms.

But I think there is another problem here. We have protection—we have EDR, NDR, XDR, HIDS, IPS, IDS, IAM, MFA, strong passwords—but we don’t have awareness. Awareness is a key point.

Without awareness, protection does not always work.

Let’s make an example. You are working in HR and a threat actor compromises your CEO’s email or your manager’s email. You receive a document from that address. Will you click it or not?

Manoj Tandon:
I probably would click it.

Diyar Saadi:
Why? Because of trust. But when awareness is applied, if I am in your situation, I will call my CEO and ask whether they are actually sending this email or not.

There are other techniques as well. For example, stylometry—the art of writing style. Maybe your CEO usually signs off with “Best of luck,” but this time they use “Break a leg.” You can differentiate whether that is a legitimate email or not by the sentence patterns and writing style, because everyone has a specific writing style in email.

So that’s a good example of how awareness works. If I have awareness about Security 101, I will verify first. In that case, I will not be compromised.

And there is another important thing: attacks and cyber incidents are not always done with malware. Sometimes they happen through initial access brokers, combo lists, info stealer logs from dark web forums, or from third parties. Nowadays threat actors may not do deep research 24/7 to achieve their goal. They just buy your credentials from the dark web or use a third party. That is a game changer.

Manoj Tandon:
We’re seeing big growth in third-party attacks. Is that the biggest mistake companies make in their detection strategies—that they don’t implement them with awareness?

Diyar Saadi:
I have a wide problem with detection, especially when it comes to writing rules.

Let’s make one small example. We know about YARA rules, Sigma, and similar tools. For example, someone writes a rule for malware that uses kernel32.dll or user32.dll to achieve its goal. But if a detection engineer mentions kernel32.dll or user32.dll in the rule, it can cause a lot of false positives, because even legitimate programs use kernel32.dll, user32.dll, or advapi32.dll to access registry features or other advanced system utilities.

There are many false positives in detection engineering. For example, VirusTotal. If you write a small Python script—just a message box or Hello World—and use PyInstaller to compile it into an executable, then upload it to VirusTotal, it may be flagged as malicious.

That’s a false positive. The reason is that threat actors use PyInstaller for malicious purposes. But why should my simple script be flagged as malicious when it is just a message box or Hello World?

To understand it properly, analysts have to decompile the file and look at the code. There are platforms that do this, like UnpacMe, to unpack malware and reveal source code, assemblies, registers, and other internals.

Most security engineers don’t understand the detection keywording. For example, when VirusTotal says “generic,” it does not mean the file is definitely malicious. It is a low-confidence generic detection. But if you see Trojan.Win32 family names and so on, then you may have a stronger indication.

There are many failures in detection engineering. You can create a simple program in C# to put your software into RunOnce in the registry or put it in Task Scheduler, and after a few minutes it may be marked as malicious. Why? Because threat actors use Task Scheduler or the registry for persistence.

There is a good book called The Antivirus Hacker’s Handbook. It is very useful for understanding how antivirus and EDR work.

Manoj Tandon:
I’ll tell you what—we are already at the hour. We’re out of time and we didn’t even finish all our questions.

But I want to give you a couple of minutes here to tell our audience about anything you’re going to be involved with—presentations, talks, anything you’d like to plug.

Diyar Saadi:
Again, thanks for having me today. It was a great honor to have this conversation together. It felt like a good TV show—the questions came, the answers flowed, and so on. There are a lot of conferences I will try to attend this year, but because the airspace is closed because of the wars, maybe I will try to join remotely at B-Sides Budapest, B-Sides Bratislava in Slovakia, and B-Sides Dublin in Ireland. Those are three conferences where I will try to present my research remotely because the airspace is closed and there is no way to travel to those countries for now.

I hope that ends as soon as possible because many people have work and flights in other countries. Actually, I love attending conferences a lot, so I will try to apply to as many conferences as I can every year to share new research papers, new methods, and new techniques about malware forensics and protecting users from digital threats.

Manoj Tandon:
We have to get you back on and maybe do a live lab session where you can talk about some of your research or techniques. That would be fantastic to share.

This has been a fascinating conversation, and you do great work. Thank you for being on the show, especially so late in your part of the world. We hope to have you back when you have something new to announce.

Diyar Saadi:
Inshallah. Thanks for having me again. It’s an honor to be with you today.

Manoj Tandon:
Thank you.

Read more about Diyar on his LinkedIn

Check out the vCISO bot we created

Check out the other episodes in Season 19:

Ep. 0 Diyar Saadi – How Hackers Exploit Hidden Vulnerabilities

Ep. 1 Krisztian Kiraly – Who Really Controls Your Algorithm Data?

Ep. 2 Jason Roos – What the U.S.–Saudi Relationship Means for Cybersecurity

Ep. 3 Jasson Casey – Identity Attacks Are the #1 Threat

Ep. 4 Andy Smith – What Good Is Cybersecurity Tech… If It Still Fails?

Ep. 5 Murphy John – The Future of Decentralized Data

Ep. 6 David Linthicum – Artificial Intelligence Mistakes Every Company is Making Right Now

Ep. 7 Bronwen Aker – Treat Artificial Intelligence like a Drunk Intern

Ep. 8 Yagub Rahimov – You Can Get Hacked With Emojis

Ep. 9 David B. Cross – The Future of Cyber Threats

Ep. 10 Mark Kreitzman – The Hidden Cost of Mobile Identity Theft

Diyar Saadi's profile picture for Dark Rhiino Security's Security Confidential podcast

Diyar Saadi Ali is a cybersecurity professional specializing in cybercrime investigations, SOC operations, and malware analysis. As a certified SOC and malware analyst, Diyar focuses on real-time security monitoring and threat detection with precision and discipline.

A contributor to the MITRE ATT&CK framework, Diyar has helped strengthen global threat intelligence efforts and defensive strategies. They are also the discoverer and owner of multiple Common Vulnerabilities and Exposures (CVE-2024-25400 and CVE-2024-25399), demonstrating a commitment to identifying and responsibly disclosing critical security flaws.

Diyar regularly speaks at international cybersecurity conferences, including Arab Cyber Security, DeepSec, GISEC, and SulyCon, contributing to the advancement of the global cyber community.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top