Главная
Study mode:
on
1
Intro
2
What is VoightKampff
3
Joshs Bio
4
Agenda
5
Background
6
Email Addresses
7
Email Reputation API
8
Defining Reputation
9
High Reputation
10
Why now
11
Phishing Defense
12
Examples
13
compromised email addresses
14
technical details
15
inputs
16
data breaches
17
whois
18
DNS
19
Reputation SMTP
20
MX Record Lookup
21
Invalid Email
22
Warnings
23
Domain Reputation
24
Frontend Stack
25
Profiles
26
Information Disclosure
27
Lastfm
28
PayPal
29
Gravatar
30
LinkedIn
31
Web Crawling
32
Experiment
33
Building the Graph
34
Building a Twitter Profile
35
Nodes Connected
36
Cryptographic Hash Functions
37
Perceptual Hash Functions
38
Gravatar Profile
39
Similarities
40
Connections between disparate graphs
41
Reporting
42
Community
43
Phishing
44
Blacklisting
45
Scoring
46
Data
47
Reputation Distribution
48
Russian OpenBSD
49
Abuse
50
South Korea
51
countermeasures
52
TLDR
53
Key Requests
54
Slack Ping
55
Future Stuff
56
Breach Data
57
Live Demo
58
Questions
Description:
Explore the world of email address reputation and its role in identifying spear-phishing and fraud in this conference talk from Shmoocon 2020. Dive into the concept of EmailRep, a system that uses OSINT techniques, crawlers, and data from various sources to predict the risk associated with email addresses. Learn about the technical architecture, implementation, and how both blue and red teams can utilize this tool. Discover the importance of internet history in differentiating legitimate email addresses from attacker personas, and understand the potential shortcomings of this approach. Gain insights into the various data points used, including social media profiles, Github activity, LinkedIn accounts, and credential dumps. Follow along as the speaker demonstrates live queries of EmailRep and discusses its free availability through emailrep.io or API.

Voight-Kampff for Email Addresses

0xdade
Add to list