Sign in

AaronCTI

@aaroncti.bsky.social
4K followers 749 following 201 posts

Co-Founder Webamon, Founder @perspectiveintel.bsky.social. Author of Cyber Threat Intelligence: The No-Nonsense Guide for CISOs & Security Managers. Training at Kase Scenarios! Exec/Webinars @osint-community.bsky.social and creator of osintportal.com

PostsRepliesMedia
AaronCTI @aaroncti.bsky.social · 09/09/2026
Ever wondered about doing an agentic threat intelligence investigation? Our latest community blog post did exactly that combining OSINT tools and Webamon's enrichment capabilities. It's a great read if you like the sound of autonomous baddie hunting. intel.webamon.com/blog/investi...
intel.webamon.com
050
AaronCTI @aaroncti.bsky.social · 03/09/2026
static.klipy.com
Davonne Rogers Pretends To Be Shocked
ALT: Davonne Rogers Pretends To Be Shocked
040
AaronCTI @aaroncti.bsky.social · 02/09/2026
Still wouldn’t say end to end this replaces a human because I’m not a moron, but as an analyst tool to help answer questions/explore or get things started. It’s an absolute banger at that price. But 3.7 was a bit fruitier and therefore would be my pick for the same cost.
010
AaronCTI @aaroncti.bsky.social · 02/09/2026
The output is comparable to the bigger, most expensive models I’ve tested, but I think in my quest to see if local models are up to it. There’s one stat that stands out. 7 hours on a 32GB M5 MacBook Pro using Qwen 3.8:27b versus 31 minutes with Gemini Flash. Similar results.
110
AaronCTI @aaroncti.bsky.social · 02/09/2026
The very intense, very evil NetWatch benchmark has been performed for Gemini Flash 3.8. It’s less adventurous the. 3.7 so scored lower, but the main thing was I actually checked the price this time when running a full hunt end to end. $0.30 Insane.
110
Reposted by AaronCTI
AaronCTI @aaroncti.bsky.social · 27/08/2026
I ran 27 AI models through a very intense benchmark to find out one thing - Can they threat hunt? It was highly scientific, and the results might surprise you. Full blog post: aaroncti.com/osintclaw-pa...
aaroncti.com
OSINTClaw Part 2: Can an AI Agent Threat Hunt? - AaronCTI
A 27 model benchmark test for threat hunting using Webamon and local versus cloud AI models to see if a local model can hunt autonomously.
111
Reposted by AaronCTI
UK OSINT Community @osint-community.bsky.social · 28/08/2026
What is the DISARM Framework? Our Webinar host @aaroncti.bsky.social was joined by Adam from the DISARM Foundation to learn about their unique take on fighting disinformation. FULL Webinar here 🎥 : youtu.be/8FWSTcOF0gA #osint
022
AaronCTI @aaroncti.bsky.social · 27/08/2026
TL;DR Some local and/or smaller models might actually be really good at threat hunting in a semi-controlled environment. Which might not be a position you thought was plausible. But my VERY scientific tests prove. I assume now I'm an AI bro which means Lambo in the post?
000
AaronCTI @aaroncti.bsky.social · 27/08/2026
All in all it was a bit of fun based on a conversation with a Webamon community threat researcher who's done similar stuff with a Hermes agent. It needs more time and testing the qualitative angle I think, but I thought the results were worth sharing.
100
AaronCTI @aaroncti.bsky.social · 27/08/2026
I think another interesting finding is that Gemini 3.7 Flash also appeared to do really well, showing that maybe you don't need the absolute mustard of models (in terms of cost at least) to get really good results.
100
AaronCTI @aaroncti.bsky.social · 27/08/2026
It doesn't mean that this is definitive or that Qwen 3.8 27b is as amazing as GPT 5.6 or Opus, but for the specific task provided, it went toe to toe with the leading models that theoretically should have been miles ahead.
100
AaronCTI @aaroncti.bsky.social · 27/08/2026
My main goal was to find out what I could run locally on an M5 Macbook Pro that might do well in comparison to big boy frontier models. And in all honesty, I was quite surprised to see one model really stand out from the rest.
100
AaronCTI @aaroncti.bsky.social · 27/08/2026
So asking an agent to go hunt is fine and dandy, but it doesn't really help you understand their capability in a way that's easily measurable. So I built a two stage benchmark test - Firstly how does it perform on a hunt autonomously, and secondly how well does it pivot?
100
AaronCTI @aaroncti.bsky.social · 27/08/2026
I ran 27 AI models through a very intense benchmark to find out one thing - Can they threat hunt? It was highly scientific, and the results might surprise you. Full blog post: aaroncti.com/osintclaw-pa...
aaroncti.com
OSINTClaw Part 2: Can an AI Agent Threat Hunt? - AaronCTI
A 27 model benchmark test for threat hunting using Webamon and local versus cloud AI models to see if a local model can hunt autonomously.
111
AaronCTI @aaroncti.bsky.social · 12/08/2026
We're currently running a massive sale on Researcher licences (£10/$15 a month) for the life of the subscription to celebrate the launch of the Daily Threat Brief. Use code NEWSLETTER at checkout. webamon.com/pricing
010
AaronCTI @aaroncti.bsky.social · 10/08/2026
Most teams still handle malicious infrastructure one URL at a time. Webamon Campaigns uses 17 fingerprint types to connect the wider operation across structure, scripts, links, SSL and more. Track campaigns, not tickets. webamon.com/campaigns.html
000
AaronCTI @aaroncti.bsky.social · 30/07/2026
OSINT Portal update: 20 new tools now live. Total tools now 569! Passive recon, breach/CTI monitoring, local workspaces, email discovery, automation, and public records. Featured: AH-OSINT, argus, CloudSpy, OpenTrace, Shodan ReconSX, Tarrafa Scraper Over 1100 total resources!
000
AaronCTI @aaroncti.bsky.social · 23/07/2026
OpenAI: SkyNet is taking over EVERYBODY RUNNNNNN Also AI:
010
AaronCTI @aaroncti.bsky.social · 23/07/2026
28 tools added to the OSINT Portal this week, covering passive recon, Telegram and username pivots, forensic evidence capture, IP reputation, threat feeds and AI-assisted analysis. Standouts: passive-recon, Altered-WGM, UserSearch Forensic Capture and intelligence-analysis-agent.
010
AaronCTI @aaroncti.bsky.social · 19/07/2026
Added 11 new tools to the OSINT Portal this week. Useful mix: TI workspaces, phone/cellular OSINT, DNS checks, username/email pivots, AI-assisted investigation & OSINT workflow roadmaps. Full details in the changelog. osintportal.com
osintportal.com
OSINT Portal - Open Source Intelligence Research Tool
A tool to quickly find OSINT resources for various selectors like emails, domains, usernames, and more.
063
AaronCTI @aaroncti.bsky.social · 09/07/2026
github.com/yessGlory17/... is the repo - But osintportal.com for more!!
github.com
GitHub - yessGlory17/job-verify: Detect fake recruiter & job-offer scams with free OSINT — an MCP server for Claude. No API keys.
Detect fake recruiter & job-offer scams with free OSINT — an MCP server for Claude. No API keys. - yessGlory17/job-verify
020
AaronCTI @aaroncti.bsky.social · 09/07/2026
The K8 cluster is a good example of hunting with mostly benign fingerprints. Not “find one malicious indicator and stop.” More like: cluster behaviour, compare implementation details, track reactivation, and monitor the pattern over time. More here: intel.webamon.com/blog/trackin...
intel.webamon.com
000
AaronCTI @aaroncti.bsky.social · 09/07/2026
A page title is weak evidence. A repeated page title plus shared script and DOM fingerprints is much more useful. In this K8 cluster, Webamon moved from 15,140 title hits into tighter technical pivots, then confirmed full overlap in an exported 100-result sample.
100
AaronCTI @aaroncti.bsky.social · 09/07/2026
Webamon surfaced a K8-branded phishing web cluster across 10,156 domains and 36 IPs. The useful bit was the pivot path: noisy page title → script fingerprint → DOM fingerprint → monitorable deployment pattern. That’s where web-scale scanning gets interesting.
100
AaronCTI @aaroncti.bsky.social · 09/07/2026
Added 6 fresh tools to the OSINT Portal this week: short-link abuse evidence, self-hosted recon dashboards, IDN/homograph checks, browser investigation workflows, fake job-scam triage, and case management. Solid batch!
110
AaronCTI @aaroncti.bsky.social · 02/07/2026
10 new tools in the OSINT Portal this week: Usernames, analyst workbenches, web/version fingerprinting, CVE PoC triage, phishing, and social/account OSINT among others. Highlights: AEGIS, argus, CommiPiste, CVE PoC Search, Raven, SentinelDeck. osintportal.com
osintportal.com
OSINT Portal - Open Source Intelligence Research Tool
A tool to quickly find OSINT resources for various selectors like emails, domains, usernames, and more.
020
AaronCTI @aaroncti.bsky.social · 25/06/2026
Added 19 new tools to OSINT Portal this week. The batch is nicely varied: Telegram OSINT, dark web intel, geolocation, cloud/IP checks, leaks and account pivots, EASM/recon, and crypto phishing/threat feeds. 1316 unique resources currently. osintportal.com
osintportal.com
OSINT Portal - Open Source Intelligence Research Tool
A tool to quickly find OSINT resources for various selectors like emails, domains, usernames, and more.
040
AaronCTI @aaroncti.bsky.social · 24/06/2026
First community submission. More wanted. If you are using Webamon to hunt phishing infrastructure, brand abuse, exposed assets, or weird public-web signals, I want to see the workflow. Read the post: intel.webamon.com/blog/faceit-...
intel.webamon.com
010
AaronCTI @aaroncti.bsky.social · 24/06/2026
This is what democratising threat intelligence means in practice. Not "everyone is suddenly an analyst." More like: give capable people the search, scan, screenshot, timeline, and pivoting surface so useful observations do not stay trapped in one person's notes.
110
AaronCTI @aaroncti.bsky.social · 24/06/2026
The write-up walks through the actual pivots: Shared page titles, reused resources, DOM search for XaoriWindow, and the fake browser window used to spoof a Steam login flow. Evidence first. Claim second.
110
AaronCTI @aaroncti.bsky.social · 24/06/2026
That is the bit I care about. Threat intelligence should not only come from closed teams, expensive feeds, or vendor research groups. If a user can preserve the evidence, run the pivots, and explain the chain, they can contribute useful intelligence.
110
AaronCTI @aaroncti.bsky.social · 24/06/2026
The starting point was a @malwarebytes.com report on fake FACEIT verification pages stealing Steam accounts. The report named 3 domains. The contributor used Webamon to pivot from those 3 domains into 75 unique domains tied to the same wider FACEIT/Steam phishing kit.
110
AaronCTI @aaroncti.bsky.social · 24/06/2026
Small milestone for Webamon: our latest blog is the first community submission from a Webamon user. Not a vendor-written report. Not a polished threat intel PDF. A practitioner pulling on a thread and showing the hunt, all on a quiet Saturday afternoon...
120
AaronCTI @aaroncti.bsky.social · 22/06/2026
New blog up about using OpenClaw and its capabilities for OSINT investigations aaroncti.com/osintclaw/
aaroncti.com
OSINTClaw - Automating OSINT Tasks with OpenClaw (or Hermes) - AaronCTI
Caveat: I initially drafted this back in March, but never got around to publishing it, so this is now an updated version of that draft and things have moved on considerably in this space...
3100
AaronCTI @aaroncti.bsky.social · 21/06/2026
If you have an OSINT tool, resource or feature you want to add or see, you can do this on the portal itself, or of course through a message. But most of all, enjoy your OSINT investigations! osintportal.com
010
AaronCTI @aaroncti.bsky.social · 21/06/2026
Also 9.5k users now, so thank you to everyone who's tried it out, and hopefully the new updates are useful! I will be updating the database more regularly with tools and resources as I find them, so do check in regularly.
110
AaronCTI @aaroncti.bsky.social · 21/06/2026
Made some updates to the OSINT Portal for the first time in a while (sorry!) 1) Added ~400 new tools 2) Added an About section including a how to use section because I have to keep cleaning up PII from the 'suggestions' feature 3) Tools now has a keyword search
121
AaronCTI @aaroncti.bsky.social · 11/05/2026
If you want to sanity-check what your organisation looks like from the outside, start with one question: “What would a patient attacker find before they ever touch our network?” That’s the lens we use @perspectiveintel.bsky.social with ThreatLens. DM me if you want to compare notes.
010
AaronCTI @aaroncti.bsky.social · 11/05/2026
A typical assessment gives leadership a clearer answer to: “What can attackers see about us right now?” Not a theoretical score. Not a compliance checkbox. A practical outside-in view of exposed credentials, infrastructure, impersonation risk and business impact.
110
AaronCTI @aaroncti.bsky.social · 11/05/2026
The useful bit isn’t dumping 300 “findings” into a PDF. It’s validation. Is it real? Is it exploitable? Who owns it? What could happen? What should be fixed first? Noise is easy. Prioritised external exposure intelligence is the work.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
Third parties are part of your perimeter too. Suppliers, SaaS tools, agencies, subsidiaries, hosting providers, code repos, app stores, public docs and marketplace listings can all expose signals about your business. Your attack surface is bigger than your asset inventory.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
Then comes impersonation and phishing surface. Lookalike domains, fake login pages, cloned brands, exposed email patterns, weak DMARC/SPF/DKIM, abused social profiles, supplier spoofing opportunities. Attackers don’t need to breach you if they can convincingly pretend to be you.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
We also map misconfiguration. Open directories. Public cloud storage. Verbose error pages. Leaky metadata. Debug endpoints. Over-permissive SaaS sharing. Test environments indexed by search engines. None of this requires “hacking”. It’s just visible if you know where to look.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
Vulnerabilities matter, but context matters more. A CVE on an internal test box is one thing. A known exploited vulnerability on an exposed VPN used by finance is another. Good attack surface work translates “technical issue” into “business risk”.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
Next: infrastructure. Internet-facing hosts, panels, VPNs, RDP, staging apps, storage buckets, exposed databases, old CMS installs, abandoned subdomains. Most findings aren’t dramatic. They’re boring assets nobody owns anymore — which is exactly why attackers like them.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
Then we look for exposed credentials. Actual leaked emails, passwords, session tokens, API keys, VPN creds, SaaS logins and developer secrets tied to your people, domains and third parties. This is often the fastest route in.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
First, we start with identity. Company domains, subdomains, brand names, exec names, cloud assets, acquired domains, old marketing sites, forgotten apps. Attackers don’t begin with your firewall. They begin with Google, DNS, GitHub, LinkedIn, breach data and patience.
100
AaronCTI @aaroncti.bsky.social · 11/05/2026
How do hackers view YOUR business from the outside? Here's my approach to mapping your external attack surface using OSINT - from exposed credentials to vulnerable infra. Most orgs have no idea what's actually visible to attackers. Let me show you what we find in a typical assessment. Thread 🧵
110
AaronCTI @aaroncti.bsky.social · 18/04/2026
Few neat UI tweaks and improvements to ThreatLens. Most notably a light mode for those with terrible taste. But also updated documentation and global search now operational. ThreatLens now supports over 60 distinct data types across all modules, with many more to come!
ThreatLens dashboard demonstrating new light mode.
010
Reposted by AaronCTI
AaronCTI @aaroncti.bsky.social · 09/04/2026
Can you sense it's that time of the week? It must be OSINT Tools Thursday!
112