Hacker News new | ask | show | jobs
by JamesBarney 1401 days ago
Bad actors know

1. It's detected (because Microsoft told everyone)

2. What was detected and where it was (because they put it there)

Good Actors only know 1.

So by telling someone 2 they are giving bad actors no new information, and good actors valuable information.

2 comments

1 is for domain only.

2, MS only knows some information that shows the site is malicious, it cannot tell if it is a compromise or just a malicious site unless it perhaps looks at reputation but even then the site owner should be able to tell new or malicious files on their webserver withour MS telling them, if they can't even do that they have bigger problems and threat actors do abuse anti-abuse systems like this all the time and they do deploy multiple things on your site as well as use it to attack other sites and monitor the reputation of their infrastructure.

This assumes the bad actor only put one thing there. If they put multiple things there they don't know what was detected unless told.
But if a bad actor wants to know what's detectable they can just put each malware on separate domains.