Sign in

Sean Koessel

@5ck.bsky.social
86 followers 41 following 4 posts

VP and founding member @Volexity. Incident Response/DFIR/Targeted threat analysis.

PostsRepliesMedia
Reposted by Sean Koessel
Volexity @volexity.com · 09/09/2026
Earlier this month, Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880).   #DFIR #threatintel
volexity.com
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
On September 1, 2026, Volexity’s Network Security Monitoring service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmenta...
1126
Reposted by Sean Koessel
Volexity @volexity.com · 04/12/2025
@volexity.com tracks a variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials, which continue to see success due to creative social engineering. Our latest blog post details Russian threat actor UTA0355’s campaigns impersonating European security events.
volexity.com
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks
In early 2025, Volexity published two blog posts detailing a new trend among Russian threat actors targeting organizations through the abuse of Microsoft 365 OAuth and Device Code authentication workf...
0108
Reposted by Sean Koessel
CYBERWARCON @cyberwarcon.bsky.social · 15/10/2025
@stevenadair.bsky.social is back again! Founder + President of Volexity leading a team of experts that deal w/ complex cyber intrusions from nation-state level intruders. His talk will cover a Chinese APT actor that Volexity tracks as UTA0388. Check out the official agenda: cyberwarcon.com
025
Reposted by Sean Koessel
Volexity @volexity.com · 08/10/2025
APT meets GPT: @volexity.com #threatintel is tracking #threatactor UTA0388's spear phishing campaigns against targets in North America, Europe & Asia, appearing to use LLMs to assist their ops. Letting #AI run your espionage operations? What could go wrong?
volexity.com
APT Meets GPT: Targeted Operations with Untamed LLMs
Starting in June 2025, Volexity detected a series of spear phishing campaigns targeting several customers and their users in North America, Asia, and Europe. The initial observed campaigns were tailor...
033
Reposted by Sean Koessel
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Juan Andrés Guerrero-Saade is presenting “From Threat Hunting to Threat Gathering” in the HUNTER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
014
Reposted by Sean Koessel
Volatility @volatilityfoundation.org · 01/08/2025
We are excited to announce that we are hosting a second training course for #FTSCon week! Join @joegrand.bsky.social as he leads his popular 2-day Hardware Hacking Basics course on Oct. 21-22 in Arlington VA! Registration is now OPEN!
events.humanitix.com
Joe Grand's Hardware Hacking Basics [FTSCon 2025]
This two-day comprehensive course teaches fundamental hardware hacking concepts and techniques used to explore, manipulate, and exploit electronic devices.
145
Reposted by Sean Koessel
Volatility @volatilityfoundation.org · 22/07/2025
The Call For Speakers for #FTSCon closes tomorrow! Make sure to submit your talks before the deadline! This is a great opportunity to share your DFIR open source tools and investigation tales with leading experts in the field.
023
Reposted by Sean Koessel
Volexity @volexity.com · 18/06/2025
@Volexity.com Volcano Server & Volcano One v25.06.12 adds ~600 new YARA rules, new IOCs for fake registered antivirus & hooked Linux kernel functions, as well as support for custom post-processing bash scripts, segmented directory watching & database optimization. [1/2]
The stylized blue, orange and black Volexity Volcano logo is centered, with the Volcano wordmark below it. The words “by Volexity” appear below the Volcano logo. There is a dark blue banner in the upper left with white letters that read “New Release”. The background is a faded gray abstract illustration evoking smoke.
133
Reposted by Sean Koessel
Volatility @volatilityfoundation.org · 05/06/2025
The Call for Presentations for From the Source 2025 is open! Our Makers Track is aimed at developers of open source DFIR tools and the Hunters track covers the best Threat Intel research of the past year. 

 See the full details in our blog post: volatilityfoundation.org/announcing-f...
In the background is an out-of-focus image of attendees listening to presentation at FTSCon. The red, black, white, and gray logo text reads "From the Source, hosted by the Volatility Foundation", and the foreground text reads "CALL FOR SPEAKERS, The Volatility Foundation is now soliciting presentations for FTSCon 2025! The deadline for submission is July 23, 2025."
046
Reposted by Sean Koessel
Andrew Case @attrc.bsky.social · 19/05/2025
I will be showing off Volatility 3 during my talk on Wednesday afternoon at RVASec. Be sure to attend and come say hello if you will be around! rvasec.com/rvasec-14-sp...
rvasec.com
RVAsec 14 Speaker Feature: Andrew Case - RVAsec
Andrew Case is the Director of Research at Volexity and has significant experience in incident response handling, digital forensics, and malware analysis. Case is a core developer of Volatility, the m...
097
Reposted by Sean Koessel
Volatility @volatilityfoundation.org · 23/05/2025
We are excited to announce FTSCon 2025 on October 20, 2025, in Arlington VA! Registration is now OPEN + we have a Call for Speakers. Following FTSCon will be a 4-day Malware & Memory Forensics Training course with Volatility 3. See the full details here: volatilityfoundation.org/announcing-f...
volatilityfoundation.org
Announcing FTSCon 2025 & In-person Malware and Memory Forensics Training!
Mark your calendars for Monday, October 20, 2025! We will again be hosting FTSCon in Arlington, Virginia.You can read more event details here. Registration is now open!
079
Sean Koessel @5ck.bsky.social · 22/04/2025
New research from the team: Involves clever m365 OAuth tricks + phishing via Signal and WhatsApp to compromise accounts. #dfir #threatintel
021
Reposted by Sean Koessel
Andrew Case @attrc.bsky.social · 07/03/2025
I will be speaking at @kernelcon.bsky.social on Fri, Apr 3rd. The talk will cover previously-unreported features of the sedexp Linux malware found in the wild - including loading of a memory-only rootkit! Talk will cover how the rootkit was discovered & how to analyze with @volatilityfoundation.org
kernelcon.org
0129
Reposted by Sean Koessel
Volexity @volexity.com · 05/03/2025
@volexity.com regularly assists customers in combatting advanced threat actors, and we enjoy being able to assist our partners as well, including LE & federal agencies like US DOJ, as we work together to combat these advanced cyber threats. www.justice.gov/opa/pr/justi... #dfir #threatintel
justice.gov
Justice Department Charges 12 Chinese Contract Hackers and Law Enforcement Officers in Global Computer Intrusion Campaigns
The Justice Department, FBI, Naval Criminal Investigative Service, and Departments of State and the Treasury announced today their coordinated efforts to disrupt and deter the malicious cyber activiti...
065
Reposted by Sean Koessel
Volexity @volexity.com · 26/02/2025
@volexity.com Volcano Server & Volcano One v25.02.21 adds 300 new YARA rules; consistent Bash/ZSH history & sessions from Linux/macOS memory and files; and parses Linux systemd journals, macOS unified logs, and Windows USNs (search + timeline for all). [1/2] #dfir #memoryforensics #memoryanalysis
An image of the blue and orange Volexity Volcano logo with a New Release banner to announce the release of Volcano Server & Volcano One v25.02.21
165
Sean Koessel @5ck.bsky.social · 14/02/2025
Check out the new blog: Russian APT adopts a well-known technique of m365 device code phishing. When combined with clever lures this technique proved to be extremely successful. 1/2
153
Reposted by Sean Koessel
Volatility @volatilityfoundation.org · 04/02/2025
As seen in this guidance from NCSC published today, memory forensics continues to play a critical role in modern digital investigations! After almost 20 years, it's encouraging to still see the need for the amazing work by the #Volatility contributors!
065
Reposted by Sean Koessel
Volexity @volexity.com · 04/02/2025
It’s great to see NCSC drawing attention to the ongoing issues with network devices & appliances. Hopefully vendors heed the volatile data collection guidance “Volatile data logging should support collection of… memory both at a kernel and individual process level.” www.ncsc.gov.uk/news/cyber-a...
ncsc.gov.uk
Cyber agencies unveil new guidelines to secure edge devices from increasing threat
New guidelines encourage device manufacturers to include and enable standard logging and forensic features that are robust and secure by default.
177
Reposted by Sean Koessel
Andrew Case @attrc.bsky.social · 01/02/2025
If you will be at @wildwesthackinfest.bsky.social next week then be sure to attend my talk!
064
Reposted by Sean Koessel
Sean Lyngaas @snlyngaas.bsky.social · 23/11/2024
White House officials share intel with telecom executives on alleged Chinese cyber espionage operation #SaltTyphoon www.cnn.com/2024/11/23/p...
cnn.com
National security officials meet with US telecom execs to share intel on Chinese cyber espionage campaign, White House says | CNN Politics
Top telecom executives met with US national security officials Friday as concerns mount over a long-running Chinese cyber-espionage campaign that has targeted some of the most senior US political figu...
21511
Sean Koessel @5ck.bsky.social · 22/11/2024
We presented on this last month at #FTSCon (IYKYK). Steven is also presenting today @CYBERWARCON. Really excited to finally share this research publicly! It's probably one of the more crazy/interesting IR engagements we've ever worked 🤯 #DFIR #ThreatIntel
2124
Reposted by Sean Koessel
Andy Greenberg @agreenberg.bsky.social · 22/11/2024
Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. www.wired.com/story/russia...
wired.com
Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack
In a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street.
12573322
Reposted by Sean Koessel
Volexity @volexity.com · 22/11/2024
@volexity.com’s latest blog post describes in detail how a Russian APT used a new attack technique, the “Nearest Neighbor Attack”, to leverage Wi-Fi networks in close proximity to the intended target while the attacker was halfway around the world.    Read more here: www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
18040