David Truman

Cyber Threat Intelligence @Kroll

London, GB
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Oct 2022 — Present

Cyber Threat Intelligence @Kroll

View department →

London, GB

Discovered and documented a new Python-based remote access trojan named Colour-Blind. Reverse-engineered part of Russian nation-state actor Fancy Bear\'s malware and tooling, which was documented for a blog post. Reverse-engineered and documented two new malware variants relating to million-dollar cryptocurrency thefts: “PRELUDE” and “DELPHYS”. Reverse-engineered and jointly documented the newly discovered CACTUS Ransomware. Developed and documented a proof-of-concept for exploiting the Ghostscript vulnerability. Analysed, attributed, and documented a new variant of BabyShark called ToddlerShark to Kimsuky (North Korea). Discovered evidence of a nation-state APT attempting to mislead forensic examiners into believing the case was financially motivated ransomware. Reverse-engineered and documented the SystemBC client and server. Developed a network scanning tool to fingerprint SystemBC servers in the wild. Significantly improved the performance of Kroll\'s MISP by rewriting noise list functionality, writing SQL search queries, and database schema tuning. Helped to architect and rewrite Kroll\'s AWS/MISP IOC distribution pipeline. Developed a tool for large-scale processing of VirusTotal data. Wrote a tool for generating statistics from large sets of OSINT IOCs for internal and external Kroll reporting. Helped Kroll\'s forensics and incident response teams during the MOVEit vulnerability by: reversing the patch and discovering an SQL injection vulnerability before this was public knowledge; developing a tool to enable the decryption of files encrypted via MOVEit to enable identification of stolen files. Wrote a proof-of-concept for a new malware intelligence-gathering pipeline. Uncovered the Carbanak group\'s switch to IDATLOADER for malware distribution. Discovered and documented how threat actors had likely bypassed Google Ads domain spoofing protections to spread VIDAR malware.

SKILLS

PuppetSolarisShell ScriptingUnix Shell ScriptingTomcatJavascriptPerlUnixBashMysqlSqlLinuxCPhpJavaRubyApache

ABOUT DAVID TRUMAN

Cyber Threat Intelligence

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

David Truman — Cyber Threat Intelligence at Kroll in London, GB | Unifers