Sign in

Tony/Humpty (CJ)

@c-b.io
185 followers 545 following 59 posts

Lead SOC analyst | Malware enjoyer | Horrible dev

PostsRepliesMedia
Tony/Humpty (CJ) @c-b.io · 05/04/2026
Ayo nerds, working less has been the best thing to happen to me in a while. MORE RESEARCH. c-b.io/cases/ransom...
c-b.io
Cloudy With A Chance Of Compromise: How A Skid Ransoms Your Buckets
Encrypting 250GB of S3 data with basic app permissions and barely leaving a trace. The skid approach to cloud ransomware and why your SOC probably wouldn't catch it.
010
Tony/Humpty (CJ) @c-b.io · 30/03/2026
Hey nerds, I'm still alive! Dropped a new blogpost today c-b.io/cases/s3-squ... An unnamed company probably won't be happy I mentioned this lol
031
Tony/Humpty (CJ) @c-b.io · 26/01/2026
New blogpost is out! This time we're getting SaaSy 💅 c-b.io/getting-saas...
c-b.io
Getting SaaSy with SIEMs - Introduction - Humpty's Blog
A field guide for SOC analysts drowning in SaaS audit logs. Learn how to turn nested JSON chaos into usable detections: normalization, stacking, common SaaS logging pitfalls, and how to avoid the clas...
010
Tony/Humpty (CJ) @c-b.io · 25/10/2025
Yo! Kinda forgot to post here but I created irchaos.club. I'll let yall discover it :)
irchaos.club
Incident Response Chaos Club
Incident Response Chaos Club - embracing the chaos of cybersecurity through DFIR, incident response, and security research.
065
Tony/Humpty (CJ) @c-b.io · 06/10/2025
Extremely grateful to have had the opportunity to not only give my first talk today but to do so alongside Josh Reynolds from @invokereversing.bsky.social In case you missed it, you can find our slides on GitHub here github.com/CoveoSec/tal...
021
Reposted by Tony/Humpty (CJ)
Invoke RE @invokereversing.bsky.social · 05/10/2025
Had a fantastic turnout for our talk at BSides Toronto about the scavenger malware today! Huge thanks to @c-b.io for co-presenting and thank you to everyone for attending!
151
Reposted by Tony/Humpty (CJ)
Invoke RE @invokereversing.bsky.social · 29/09/2025
A reminder that @c-b.io and Joshua Reynolds will be speaking at BSides Toronto this Sunday (Oct 5th) at 11:45AM about the Scavenger NPM supply chain attack. See you there!
012
Reposted by Tony/Humpty (CJ)
Invoke RE @invokereversing.bsky.social · 17/09/2025
We are excited to announce that our founder Joshua Reynolds and @c-b.io have been accepted to speak at BSides Toronto with their talk titled "When Prettier Gets Ugly: The Scavenger Supply Chain Campaign" more info here: pretalx.com/bsides-toron...
011
Tony/Humpty (CJ) @c-b.io · 28/07/2025
IT HAPPENED AGAIN invokere.com/posts/2025/0... @invokereversing.bsky.social is on FIRE
invokere.com
Scavenger Malware Distributed via num2words PyPI Supply Chain Compromise
Technical blog detailing the num2words v0.5.15 PyPI supply chain compromise used to distribute Scavenger malware
011
Reposted by Tony/Humpty (CJ)
Invoke RE @invokereversing.bsky.social · 21/07/2025
We did a full technical blog on the NPM eslint-config-prettier supply chain compromise that was used to distribute the Scavenger malware with @c-b.io check it out! invokere.com/posts/2025/0...
invokere.com
Scavenger Malware Distributed via eslint-config-prettier NPM Package Supply Chain Compromise
Technical blog detailing the eslint-config-prettier supply chain compromise used to distribute Scavenger malware
011
Tony/Humpty (CJ) @c-b.io · 30/06/2025
Hey folks! Here's my first technical deep-dive into a PE malware sample that touches on why including more information/proofs in threat intelligence reports is important. c-b.io/2025-06-29+-...
c-b.io
2025-06-29 - Supper is served - Tony/Humpty's RE blog
Recommend song to listen to while reading: If you find something off with what I say, please let me know. I'll gladly amend my content and credit you for the fix. Some thanks in alphabetical order
022
Tony/Humpty (CJ) @c-b.io · 07/06/2025
Yo nerds, if you're thinking about deploying canaries please read this deceptiq.com/blog/rethink...
deceptiq.com
Rethinking Deception: Why We're Moving from Product to Enablement
After years of building deception technology and watching SOC teams struggle with yet another dashboard, we've made a fundamental shift in how we deliver cyber deception.
000
Reposted by Tony/Humpty (CJ)
Sam (ABeardedPanda) @abeardedpanda.bsky.social · 07/04/2025
YOU DID WHAT?
The so-called Department of Government Efficiency: We saved $1M per year by converting 14,000 magnetic tapes (70 year old technology for information storage) to permanent modern digital records
3065111994
Reposted by Tony/Humpty (CJ)
LegalEagle @legaleagle.tv · 03/04/2025
In sum: an economically illiterate "conservative" institutes the biggest tax hike in history in an effort to revive the policies that led to the Great Depression. Cool.
19952137
Tony/Humpty (CJ) @c-b.io · 27/03/2025
000
Tony/Humpty (CJ) @c-b.io · 23/03/2025
Got a new family added to malpedia nerds malpedia.caad.fkie.fraunhofer.de/details/py.r...
malpedia.caad.fkie.fraunhofer.de
RedTiger Stealer (Malware Family)
Details for the RedTiger Stealer malware family including references, samples and yara signatures.
010
Tony/Humpty (CJ) @c-b.io · 16/03/2025
Another day, another stealer c-b.io/blog/redtige...
c-b.io
Analyzing the RedTiger Malware Stealer
Analyzing the RedTiger Malware Stealer Today we’ll dive into a fresh malware stealer dubbed RedTiger, a sample targeting personal user data, particularly Discord tokens, browser-stored credentials, an...
010
Tony/Humpty (CJ) @c-b.io · 16/03/2025
CALLING ALL INCIDENT RESPONSE NERDS, MY TEAM IS LOOKING FOR A FRIEND www.coveo.com/en/company/c...
coveo.com
SOC Analyst | Province of Quebec (Canada) | Coveo
Here you'll find jobs in corporate cybersecurity, business law, corporate law, labor law, compliance and others!
000
Tony/Humpty (CJ) @c-b.io · 16/02/2025
Hello fellow nerds, here's my latest blogpost on how BlankGrabber targets Discord by injecting malicious JS to steal credit card info c-b.io/blog/dissect...
c-b.io
Dissecting a fresh BlankGrabber sample
Dissecting a fresh BlankGrabber sample BlankGrabber is nothing new. It’s been documented by multiple companies such as ThreatMon, K7Security and has even had it’s source code disclosed on GitHub. So w...
000
Tony/Humpty (CJ) @c-b.io · 14/01/2025
Does anyone know what's up with these brand spanking new youtube accounts posting bogus seed phrases here? Whats the scheme? 🤔
000
Reposted by Tony/Humpty (CJ)
Steve Syfuhs @syfuhs.net · 25/12/2024
Phooooomp
0111
Tony/Humpty (CJ) @c-b.io · 25/12/2024
Wishing everyday some resting and incident free holidays ❤️
000
Tony/Humpty (CJ) @c-b.io · 17/12/2024
I made it to a cool starter pack, I may now die in peace 🫡
110
Tony/Humpty (CJ) @c-b.io · 07/12/2024
Do I have a ESC/POS nerd here? In desperate need of help to print f*cking nv bit images on a shitty rongta printer that's supposed to emulate the EPSOM ESC/POS spec. I'll pay a beer in exchange (the price of a beer in your country)
100
Tony/Humpty (CJ) @c-b.io · 06/12/2024
Absolutely insane video by @backwoodideas.bsky.social. I have no clue _why_ he would do something but he did and it turned out fucking amazing lol TL;DR: data transmission over a tincan phone. Very Michael Reeves pilled youtu.be/zUqPqg2jjro?...
youtu.be
This Video Was Uploaded Through a Fishing Line
YouTube video by Backwood
120
Reposted by Tony/Humpty (CJ)
Felipe O. Carvalho @felipe.rs · 05/12/2024
C++23 has "first-class UB": you, the language user, can make promises and let the program enter UB if you break them. int f(int x, int y) { [[assume(x == 27)]]; [[assume(x == y)]]; return y + 1; // May be optimised to `return 28`. }
97810
Tony/Humpty (CJ) @c-b.io · 04/12/2024
Part 1 of my blogpost titled "Threat hunting for shits and giggles" is out! This is my very first blogpost of the kind so I'd really appreciate feedback :) Quick shoutout to @hunt.io for their pretty cool tool c-b.io/blog/threat_...
c-b.io
Threat hunting for shits and giggles [Part 1]
Threat hunting for shits and giggles [Part 1] I’ll start by saying this post is not endorsed by hunt.io. I just happen to be a really big fan of what they’re doing. Some hackers suck at OpSec Not all ...
010
Tony/Humpty (CJ) @c-b.io · 30/11/2024
So I most likely botched this but here's the latest decompiled XWorm source code: github.com/cyb3rjerry/x...
github.com
GitHub - cyb3rjerry/xworm-source: Decompiled-ish XWorm source code (most likely uncompilable)
Decompiled-ish XWorm source code (most likely uncompilable) - cyb3rjerry/xworm-source
000
Tony/Humpty (CJ) @c-b.io · 25/11/2024
How's everyones day been?
000
Tony/Humpty (CJ) @c-b.io · 18/11/2024
What am I missing?
000
Tony/Humpty (CJ) @c-b.io · 16/11/2024
British Columbia is absolutely gorgeous
000
Tony/Humpty (CJ) @c-b.io · 15/11/2024
I hope he fails. CISA has done nothing but amazing stuff against dinsinformation.
010
Reposted by Tony/Humpty (CJ)
Brendan Sinclair @brendansinclair.bsky.social · 03/11/2024
Calgary stopped putting flouride in its water in 2011. Then after a decade of seeing dental problems and dental surgery under anesthesia skyrocket in kids, they decided to add it back in but it's taking a lot of time and money. calgary.ctvnews.ca/calgary-s-pl...
calgary.ctvnews.ca
Calgary's plan to reintroduce fluoride into drinking water pushed back to 2025
The City of Calgary’s plan to reintroduce fluoride back into the drinking water supply has been delayed again – and is now set to be ready by 2025.
131009394
Tony/Humpty (CJ) @c-b.io · 29/10/2024
Don't know who's in charge of the msgraph go SDK but if you're reading this I hate you
000
Tony/Humpty (CJ) @c-b.io · 22/10/2024
I swear to god
000
Tony/Humpty (CJ) @c-b.io · 18/10/2024
I guess we all doing this now, 👋, I'm CJ. Ex-welder turned pentester turned Lead SOC analyst (against my will?). I dabble in MalDev, love writing shitty code to do weird things with devices in unintended ways and am a HAM (VA2CJX).
000
Tony/Humpty (CJ) @c-b.io · 18/10/2024
Dog pics for my second post to establish good karma here
Picture of a boston terrier next to a lakePicture of a boston terrier laying in a fluffy dog bed
030
Tony/Humpty (CJ) @c-b.io · 18/10/2024
So uh.. hi
020