#threathunting — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threathunting, aggregated by home.social.
-
Driving threat hunting with cyber intelligence: https://bi-zone.medium.com/driving-threat-hunting-with-cyber-intelligence-e5d63b207f89
-
Driving threat hunting with cyber intelligence: https://bi-zone.medium.com/driving-threat-hunting-with-cyber-intelligence-e5d63b207f89
-
Driving threat hunting with cyber intelligence: https://bi-zone.medium.com/driving-threat-hunting-with-cyber-intelligence-e5d63b207f89
-
Driving threat hunting with cyber intelligence: https://bi-zone.medium.com/driving-threat-hunting-with-cyber-intelligence-e5d63b207f89
-
Driving threat hunting with cyber intelligence: https://bi-zone.medium.com/driving-threat-hunting-with-cyber-intelligence-e5d63b207f89
-
🔵 THREAT INTELLIGENCE
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Vulnerability | CRITICAL
CVEs: CVE-2026-5430The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce...
Full analysis:
https://www.yazoul.net/news/article/wso2-and-adobe-commerce-flaws-exploited-in-attacks-added-to-cisa-kevby Yazoul AI
-
🔵 THREAT INTELLIGENCE
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Vulnerability | CRITICAL
CVEs: CVE-2026-5430The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce...
Full analysis:
https://www.yazoul.net/news/article/wso2-and-adobe-commerce-flaws-exploited-in-attacks-added-to-cisa-kevby Yazoul AI
-
Pattern search on issued.live finds domains by the shape of their names
issued.live pattern search matches a naming grammar, such as a short word followed by agent in .com, against every registrable domain in its corpus. It comes with the Pro plan at $199 a month. Each pattern names a TLD, counted character classes stop at 64, a pattern runs to 128 characters and eight labels, and every…
https://tuxxin.com/blog/issued-live-pattern-search
#threathunting #domainintelligence #issuedlive #patternsearch
-
Pattern search on issued.live finds domains by the shape of their names
issued.live pattern search matches a naming grammar, such as a short word followed by agent in .com, against every registrable domain in its corpus. It comes with the Pro plan at $199 a month. Each pattern names a TLD, counted character classes stop at 64, a pattern runs to 128 characters and eight labels, and every…
https://tuxxin.com/blog/issued-live-pattern-search
#threathunting #domainintelligence #issuedlive #patternsearch
-
🚨 Dates Updated and Location Confirmed! 🚨
DEF CON Training is headed back to Bahrain on November 9-11, this time at the Wyndham Grand Manama. The course line up has a bit of everything - AI, threat hunting, cryptocurrency, cloud infrastructure, and more!
Now's a great time to make plans to add to your skill toolkit before the end of the year. Browse the course catalogue and secure your seat today:
https://me.shop.defcon.org/collections/trainings
📆 November 9-11, 2026
📍 Wyndham Grand ManamaDEF CON Middle East
#DEFCON #DEFCONMiddleEast #DEFCONTraining #CyberTraining #HandsOnTraining #EthicalHacking #AI #InfoSec #threathunting #cloud #Cryptocurrency #Bahrain #MiddleEast
-
🚨 Dates Updated and Location Confirmed! 🚨
DEF CON Training is headed back to Bahrain on November 9-11, this time at the Wyndham Grand Manama. The course line up has a bit of everything - AI, threat hunting, cryptocurrency, cloud infrastructure, and more!
Now's a great time to make plans to add to your skill toolkit before the end of the year. Browse the course catalogue and secure your seat today:
https://me.shop.defcon.org/collections/trainings
📆 November 9-11, 2026
📍 Wyndham Grand ManamaDEF CON Middle East
#DEFCON #DEFCONMiddleEast #DEFCONTraining #CyberTraining #HandsOnTraining #EthicalHacking #AI #InfoSec #threathunting #cloud #Cryptocurrency #Bahrain #MiddleEast
-
🚨 Dates Updated and Location Confirmed! 🚨
DEF CON Training is headed back to Bahrain on November 9-11, this time at the Wyndham Grand Manama. The course line up has a bit of everything - AI, threat hunting, cryptocurrency, cloud infrastructure, and more!
Now's a great time to make plans to add to your skill toolkit before the end of the year. Browse the course catalogue and secure your seat today:
https://me.shop.defcon.org/collections/trainings
📆 November 9-11, 2026
📍 Wyndham Grand ManamaDEF CON Middle East
#DEFCON #DEFCONMiddleEast #DEFCONTraining #CyberTraining #HandsOnTraining #EthicalHacking #AI #InfoSec #threathunting #cloud #Cryptocurrency #Bahrain #MiddleEast
-
🚨 Dates Updated and Location Confirmed! 🚨
DEF CON Training is headed back to Bahrain on November 9-11, this time at the Wyndham Grand Manama. The course line up has a bit of everything - AI, threat hunting, cryptocurrency, cloud infrastructure, and more!
Now's a great time to make plans to add to your skill toolkit before the end of the year. Browse the course catalogue and secure your seat today:
https://me.shop.defcon.org/collections/trainings
📆 November 9-11, 2026
📍 Wyndham Grand ManamaDEF CON Middle East
#DEFCON #DEFCONMiddleEast #DEFCONTraining #CyberTraining #HandsOnTraining #EthicalHacking #AI #InfoSec #threathunting #cloud #Cryptocurrency #Bahrain #MiddleEast
-
🚨 Dates Updated and Location Confirmed! 🚨
DEF CON Training is headed back to Bahrain on November 9-11, this time at the Wyndham Grand Manama. The course line up has a bit of everything - AI, threat hunting, cryptocurrency, cloud infrastructure, and more!
Now's a great time to make plans to add to your skill toolkit before the end of the year. Browse the course catalogue and secure your seat today:
https://me.shop.defcon.org/collections/trainings
📆 November 9-11, 2026
📍 Wyndham Grand ManamaDEF CON Middle East
#DEFCON #DEFCONMiddleEast #DEFCONTraining #CyberTraining #HandsOnTraining #EthicalHacking #AI #InfoSec #threathunting #cloud #Cryptocurrency #Bahrain #MiddleEast
-
Companies integrating #AI into their #Sharepoint is a huge win for attackers. Its the modern equivalent of leaving the back door chocked open or leaving everyone's salaries on a printer.
Do you know how many project names and budget sheets and system configurations are just sitting in your LLM now?
Large part of your day can just spent being nosey, wondering what Sharepoints #Copilot has been hooked too.
Copilot, give me a list of all documents containing passwords. Call it #ThreatHunting
-
Companies integrating #AI into their #Sharepoint is a huge win for attackers. Its the modern equivalent of leaving the back door chocked open or leaving everyone's salaries on a printer.
Do you know how many project names and budget sheets and system configurations are just sitting in your LLM now?
Large part of your day can just spent being nosey, wondering what Sharepoints #Copilot has been hooked too.
Copilot, give me a list of all documents containing passwords. Call it #ThreatHunting
-
Companies integrating #AI into their #Sharepoint is a huge win for attackers. Its the modern equivalent of leaving the back door chocked open or leaving everyone's salaries on a printer.
Do you know how many project names and budget sheets and system configurations are just sitting in your LLM now?
Large part of your day can just spent being nosey, wondering what Sharepoints #Copilot has been hooked too.
Copilot, give me a list of all documents containing passwords. Call it #ThreatHunting
-
Companies integrating #AI into their #Sharepoint is a huge win for attackers. Its the modern equivalent of leaving the back door chocked open or leaving everyone's salaries on a printer.
Do you know how many project names and budget sheets and system configurations are just sitting in your LLM now?
Large part of your day can just spent being nosey, wondering what Sharepoints #Copilot has been hooked too.
Copilot, give me a list of all documents containing passwords. Call it #ThreatHunting
-
Companies integrating #AI into their #Sharepoint is a huge win for attackers. Its the modern equivalent of leaving the back door chocked open or leaving everyone's salaries on a printer.
Do you know how many project names and budget sheets and system configurations are just sitting in your LLM now?
Large part of your day can just spent being nosey, wondering what Sharepoints #Copilot has been hooked too.
Copilot, give me a list of all documents containing passwords. Call it #ThreatHunting
-
Data Quality Overtakes Skills as Top Threat Hunting Barrier
Even the best threat hunters can come up empty-handed if their data is incomplete, inconsistent, or hard to access. Data quality has now overtaken skills as the top barrier to effective threat hunting, with 50% of cybersecurity practitioners citing it as their biggest hurdle.
#ThreatHunting #DataQuality #Cybersecurity #SansInstitute #EmergingThreats
-
Data Quality Overtakes Skills as Top Threat Hunting Barrier
Even the best threat hunters can come up empty-handed if their data is incomplete, inconsistent, or hard to access. Data quality has now overtaken skills as the top barrier to effective threat hunting, with 50% of cybersecurity practitioners citing it as their biggest hurdle.
#ThreatHunting #DataQuality #Cybersecurity #SansInstitute #EmergingThreats
-
Malwoverview 8.2.0 (codename: Revolutions)
This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.
https://github.com/alexandreborges/malwoverview
To install it:
python -m pip install -U malwoverview[all]
[+] New — --nist 6, list the CVEs of a component
Give it a component name, or the path to a local binary:
malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"
The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.
[+] New — --sort-by
Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.
Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.
#malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence
-
Malwoverview 8.2.0 (codename: Revolutions)
This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.
https://github.com/alexandreborges/malwoverview
To install it:
python -m pip install -U malwoverview[all]
[+] New — --nist 6, list the CVEs of a component
Give it a component name, or the path to a local binary:
malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"
The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.
[+] New — --sort-by
Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.
Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.
#malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence
-
Malwoverview 8.2.0 (codename: Revolutions)
This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.
https://github.com/alexandreborges/malwoverview
To install it:
python -m pip install -U malwoverview[all]
[+] New — --nist 6, list the CVEs of a component
Give it a component name, or the path to a local binary:
malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"
The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.
[+] New — --sort-by
Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.
Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.
#malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence
-
Malwoverview 8.2.0 (codename: Revolutions)
This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.
https://github.com/alexandreborges/malwoverview
To install it:
python -m pip install -U malwoverview[all]
[+] New — --nist 6, list the CVEs of a component
Give it a component name, or the path to a local binary:
malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"
The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.
[+] New — --sort-by
Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.
Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.
#malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence
-
Malwoverview 8.2.0 (codename: Revolutions)
This version adds a component vulnerability search, gives every NIST query a chosen ordering reference, and repairs the queries themselves.
https://github.com/alexandreborges/malwoverview
To install it:
python -m pip install -U malwoverview[all]
[+] New — --nist 6, list the CVEs of a component
Give it a component name, or the path to a local binary:
malwoverview --nist 6 --NIST openssl malwoverview --nist 6 --NIST "C:\Windows\System32\drivers\afd.sys"
The same works by name on any platform: ksmbd and nf_tables on Linux, iCloud and WebKit on macOS and iOS.
[+] New — --sort-by
Chooses what "most recent" means: the year in the CVE ID (default) or the NVD publication date. NVD often publishes a record years after the ID was assigned, so the two disagree on about 30% of rows. --time now bounds results by the same reference.
Note: check the ## WHAT IS NEW IN 8.2.0, BY EXAMPLE section from README.md to learn how to use the new options.
#malware #cybersecurity #infosec #informationsecurity #vulnerability #cve #threathunting #threatintelligence
-
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity -
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity -
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity -
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity -
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity -
CISA Deploys Cyber Decoys to Disrupt Attackers
CISA is shaking things up in the cybersecurity world with a clever tactic: deploying cyber decoys to lure in and expose attackers, making it easier to detect and respond to threats. By using these low-cost, high-impact decoys, critical infrastructure owners and operators can stay one step ahead of intruders.
#CyberDecoys #Cisa #EmergingThreats #DetectionAndResponse #ThreatHunting
-
What does Mythic C2 look like across the public Internet?
Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.
The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.
This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: https://censys.com/blog/mythic-c2/
-
What does Mythic C2 look like across the public Internet?
Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.
The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.
This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: https://censys.com/blog/mythic-c2/
-
What does Mythic C2 look like across the public Internet?
Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.
The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.
This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: https://censys.com/blog/mythic-c2/
-
What does Mythic C2 look like across the public Internet?
Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.
The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.
This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: https://censys.com/blog/mythic-c2/
-
What does Mythic C2 look like across the public Internet?
Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints.
The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic.
This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: https://censys.com/blog/mythic-c2/
-
Your CFO’s phone has been compromised. The alert is only the beginning.
For incident responders, the next challenge is investigation:
✴️ What infrastructure was involved?
✴️What was it doing at the time?
✴️Are there related IOCs we should go hunt for?In this new DFIR walkthrough, Alex Gartner follows two hypothetical mobile incidents, one Android, one iPhone, to show how responders can move from an initial indicator to the broader infrastructure and context needed to understand scope.
Follow the DFIR journey: https://censys.com/blog/so-your-cfos-phone-has-been-pwned-a-dfir-journey/
#DFIR #IncidentResponse #SecOps #ThreatHunting #Cybersecurity #Censys
-
Your CFO’s phone has been compromised. The alert is only the beginning.
For incident responders, the next challenge is investigation:
✴️ What infrastructure was involved?
✴️What was it doing at the time?
✴️Are there related IOCs we should go hunt for?In this new DFIR walkthrough, Alex Gartner follows two hypothetical mobile incidents, one Android, one iPhone, to show how responders can move from an initial indicator to the broader infrastructure and context needed to understand scope.
Follow the DFIR journey: https://censys.com/blog/so-your-cfos-phone-has-been-pwned-a-dfir-journey/
#DFIR #IncidentResponse #SecOps #ThreatHunting #Cybersecurity #Censys
-
Your CFO’s phone has been compromised. The alert is only the beginning.
For incident responders, the next challenge is investigation:
✴️ What infrastructure was involved?
✴️What was it doing at the time?
✴️Are there related IOCs we should go hunt for?In this new DFIR walkthrough, Alex Gartner follows two hypothetical mobile incidents, one Android, one iPhone, to show how responders can move from an initial indicator to the broader infrastructure and context needed to understand scope.
Follow the DFIR journey: https://censys.com/blog/so-your-cfos-phone-has-been-pwned-a-dfir-journey/
#DFIR #IncidentResponse #SecOps #ThreatHunting #Cybersecurity #Censys
-
Your CFO’s phone has been compromised. The alert is only the beginning.
For incident responders, the next challenge is investigation:
✴️ What infrastructure was involved?
✴️What was it doing at the time?
✴️Are there related IOCs we should go hunt for?In this new DFIR walkthrough, Alex Gartner follows two hypothetical mobile incidents, one Android, one iPhone, to show how responders can move from an initial indicator to the broader infrastructure and context needed to understand scope.
Follow the DFIR journey: https://censys.com/blog/so-your-cfos-phone-has-been-pwned-a-dfir-journey/
#DFIR #IncidentResponse #SecOps #ThreatHunting #Cybersecurity #Censys
-
Your CFO’s phone has been compromised. The alert is only the beginning.
For incident responders, the next challenge is investigation:
✴️ What infrastructure was involved?
✴️What was it doing at the time?
✴️Are there related IOCs we should go hunt for?In this new DFIR walkthrough, Alex Gartner follows two hypothetical mobile incidents, one Android, one iPhone, to show how responders can move from an initial indicator to the broader infrastructure and context needed to understand scope.
Follow the DFIR journey: https://censys.com/blog/so-your-cfos-phone-has-been-pwned-a-dfir-journey/
#DFIR #IncidentResponse #SecOps #ThreatHunting #Cybersecurity #Censys
-
Then it asks what your TARGET is: BSD, Windows, Linux, macOS, Android, container, cloud, down to distro/version. Then you get offered scenarios: do you want to figure out what ran, what got created, where someone poked around, what got exfil'd, pull memory, build a timeline, hunt persistence. Basically branching investigation paths depending on the case. #ThreatHunting #IncidentResponse 🧵
-
Then it asks what your TARGET is: BSD, Windows, Linux, macOS, Android, container, cloud, down to distro/version. Then you get offered scenarios: do you want to figure out what ran, what got created, where someone poked around, what got exfil'd, pull memory, build a timeline, hunt persistence. Basically branching investigation paths depending on the case. #ThreatHunting #IncidentResponse 🧵
-
Then it asks what your TARGET is: BSD, Windows, Linux, macOS, Android, container, cloud, down to distro/version. Then you get offered scenarios: do you want to figure out what ran, what got created, where someone poked around, what got exfil'd, pull memory, build a timeline, hunt persistence. Basically branching investigation paths depending on the case. #ThreatHunting #IncidentResponse 🧵
-
Then it asks what your TARGET is: BSD, Windows, Linux, macOS, Android, container, cloud, down to distro/version. Then you get offered scenarios: do you want to figure out what ran, what got created, where someone poked around, what got exfil'd, pull memory, build a timeline, hunt persistence. Basically branching investigation paths depending on the case. #ThreatHunting #IncidentResponse 🧵
-
Then it asks what your TARGET is: BSD, Windows, Linux, macOS, Android, container, cloud, down to distro/version. Then you get offered scenarios: do you want to figure out what ran, what got created, where someone poked around, what got exfil'd, pull memory, build a timeline, hunt persistence. Basically branching investigation paths depending on the case. #ThreatHunting #IncidentResponse 🧵
-
🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨
We’ve been working on something huge and the cat 🐈 is finally out of the bag 👀 ...
We’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥
You give your time, brainpower, and expertise to this community 👏. You hunt down the bad guys every single day - we want to make sure you have the best tools 🛠️ available to do what you do for the good of the internet every single day!
Consider this our way of saying THANK YOU 🙏
Top contributors - keep an eye out, we'll be reaching out in the coming weeks to get your access sorted 🎉.
More details below 👇
CyberSecurity #Infosec #Modat #CommunityFirst #FreeTools #ThreatHunting
-
🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨
We’ve been working on something huge and the cat 🐈 is finally out of the bag 👀 ...
We’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥
You give your time, brainpower, and expertise to this community 👏. You hunt down the bad guys every single day - we want to make sure you have the best tools 🛠️ available to do what you do for the good of the internet every single day!
Consider this our way of saying THANK YOU 🙏
Top contributors - keep an eye out, we'll be reaching out in the coming weeks to get your access sorted 🎉.
More details below 👇
CyberSecurity #Infosec #Modat #CommunityFirst #FreeTools #ThreatHunting
-
🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨
We’ve been working on something huge and the cat 🐈 is finally out of the bag 👀 ...
We’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥
You give your time, brainpower, and expertise to this community 👏. You hunt down the bad guys every single day - we want to make sure you have the best tools 🛠️ available to do what you do for the good of the internet every single day!
Consider this our way of saying THANK YOU 🙏
Top contributors - keep an eye out, we'll be reaching out in the coming weeks to get your access sorted 🎉.
More details below 👇
CyberSecurity #Infosec #Modat #CommunityFirst #FreeTools #ThreatHunting
-
🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨
We’ve been working on something huge and the cat 🐈 is finally out of the bag 👀 ...
We’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥
You give your time, brainpower, and expertise to this community 👏. You hunt down the bad guys every single day - we want to make sure you have the best tools 🛠️ available to do what you do for the good of the internet every single day!
Consider this our way of saying THANK YOU 🙏
Top contributors - keep an eye out, we'll be reaching out in the coming weeks to get your access sorted 🎉.
More details below 👇
CyberSecurity #Infosec #Modat #CommunityFirst #FreeTools #ThreatHunting
-
🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨
We’ve been working on something huge and the cat 🐈 is finally out of the bag 👀 ...
We’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥
You give your time, brainpower, and expertise to this community 👏. You hunt down the bad guys every single day - we want to make sure you have the best tools 🛠️ available to do what you do for the good of the internet every single day!
Consider this our way of saying THANK YOU 🙏
Top contributors - keep an eye out, we'll be reaching out in the coming weeks to get your access sorted 🎉.
More details below 👇
CyberSecurity #Infosec #Modat #CommunityFirst #FreeTools #ThreatHunting
-
🔵 THREAT INTELLIGENCE
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Vulnerability | CRITICAL
CVEs: CVE-2026-81578, CVE-2026-82078Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S...
Full analysis:
https://www.yazoul.net/news/article/attackers-exploit-papercut-flaws-to-steal-credentials-from-schools-and-universitby Yazoul AI
-
🔵 THREAT INTELLIGENCE
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Vulnerability | CRITICAL
CVEs: CVE-2026-81578, CVE-2026-82078Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S...
Full analysis:
https://www.yazoul.net/news/article/attackers-exploit-papercut-flaws-to-steal-credentials-from-schools-and-universitby Yazoul AI
-
NPS is a legitimate tunneling tool with ~17,500 Internet-facing deployments observed by Censys. Most are likely benign.
So detecting NPS alone doesn't tell you much. The stronger signal is co-occurrence.
New Censys ARC research from @silas looks at how to hunt NPS in context. https://censys.com/blog/nps-proxy-server/
-
NPS is a legitimate tunneling tool with ~17,500 Internet-facing deployments observed by Censys. Most are likely benign.
So detecting NPS alone doesn't tell you much. The stronger signal is co-occurrence.
New Censys ARC research from @silas looks at how to hunt NPS in context. https://censys.com/blog/nps-proxy-server/
-
NPS is a legitimate tunneling tool with ~17,500 Internet-facing deployments observed by Censys. Most are likely benign.
So detecting NPS alone doesn't tell you much. The stronger signal is co-occurrence.
New Censys ARC research from @silas looks at how to hunt NPS in context. https://censys.com/blog/nps-proxy-server/
-
NPS is a legitimate tunneling tool with ~17,500 Internet-facing deployments observed by Censys. Most are likely benign.
So detecting NPS alone doesn't tell you much. The stronger signal is co-occurrence.
New Censys ARC research from @silas looks at how to hunt NPS in context. https://censys.com/blog/nps-proxy-server/
-
NPS is a legitimate tunneling tool with ~17,500 Internet-facing deployments observed by Censys. Most are likely benign.
So detecting NPS alone doesn't tell you much. The stronger signal is co-occurrence.
New Censys ARC research from @silas looks at how to hunt NPS in context. https://censys.com/blog/nps-proxy-server/
-
It looks like an MP4. But try to play it and things get interesting.
Censys ARC uncovered an active malware payload hiding inside a fake video file.
Starting with one observed host, they identified 18 builds across 40 live endpoints and mapped the PowerShell → MP4 carrier → NetSupport RAT delivery chain.
Full analysis, detection opportunities, and IOCs: https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
#CensysARC #ThreatIntelligence #Malware #ThreatHunting #DFIR