Sign in

Xavier Mertens 🇧🇪

@eeksme.bsky.social
221 followers 21 following 39 posts

A fork of twitter.com/xme

PostsRepliesMedia
Reposted by Xavier Mertens 🇧🇪
SANS.edu Internet Storm Center @sansisc.bsky.social · 18/03/2025
Python Bot Delivered Through DLL Side-Loading isc.sans.edu/diary/31778
ISC Logo
024
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 15/03/2025
Great talk! 🥳
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 14/03/2025
Good morning from #Insomnihack! I’m here today, ping me if you want to meet!
020
Reposted by Xavier Mertens 🇧🇪
SANS.edu Internet Storm Center @sansisc.bsky.social · 10/03/2025
Shellcode Encoded in UUID's isc.sans.edu/diary/31752
ISC Logo
005
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 27/02/2025
Njrat Campaign Using Microsoft Dev Tunnels isc.sans.edu/diary/31724 #SANSISC
000
Reposted by Xavier Mertens 🇧🇪
Hexacorn @hexacorn.bsky.social · 19/02/2025
Every once in a while you come across interesting PE Section names Hello Guy! www.virustotal.com/gui/file/051...
182
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 19/02/2025
XWorm Cocktail:  A Mix of PE data with PowerShell Code isc.sans.edu/diary/31700 #SANSISC
isc.sans.edu
XWorm Cocktail:� A Mix of PE data with PowerShell Code - SANS Internet Storm Center
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 17/02/2025
Monday morning reading with your 0xC0FFEE: www.elastic.co/security-lab...
elastic.co
You've Got Malware: FINALDRAFT Hides in Your Drafts — Elastic Security Labs
During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and backdoor with many features including using...
001
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 15/02/2025
The Danger of IP Volatility isc.sans.edu/diary/31688 #SANSISC
isc.sans.edu
The Danger of IP Volatility - SANS Internet Storm Center
The Danger of IP Volatility, Author: Xavier Mertens
001
Reposted by Xavier Mertens 🇧🇪
SANS.edu Internet Storm Center @sansisc.bsky.social · 14/02/2025
Fake BSOD Delivered by Malicious Python Script isc.sans.edu/diary/31686
ISC Logo
023
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 06/02/2025
The Unbreakable Multi-Layer Anti-Debugging System isc.sans.edu/diary/31658
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 06/02/2025
Be honest… we all do that… taking screenshots of important information! Be careful and don’t keep them for a long time! #InfoStealer #Malware #OCR t.co/cjI7gNLkW5
t.co
https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/
000
Reposted by Xavier Mertens 🇧🇪
SANS.edu Internet Storm Center @sansisc.bsky.social · 29/01/2025
From PowerShell to a Python Obfuscation Race! isc.sans.edu/diary/31634
ISC Logo
011
Reposted by Xavier Mertens 🇧🇪
SANS.edu Internet Storm Center @sansisc.bsky.social · 28/01/2025
Fileless Python InfoStealer Targeting Exodus isc.sans.edu/diary/31630
ISC Logo
001
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 25/01/2025
Let’s wrap up the week with the malware analysis tournament! Wanna join the fun? My next class is in March in London #FOR610 #SANSEMEA
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 06/01/2025
Make Malware Happy isc.sans.edu/diary/31560 #SANSISC
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 03/01/2025
SwaetRAT Delivery Through Python isc.sans.edu/diary/31554
isc.sans.edu
SwaetRAT Delivery Through Python - SANS Internet Storm Center
SwaetRAT Delivery Through Python, Author: Xavier Mertens
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 24/12/2024
More SSH Fun! isc.sans.edu/diary/31542
isc.sans.edu
More SSH Fun! - SANS Internet Storm Center
More SSH Fun!, Author: Xavier Mertens
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 23/12/2024
Modiloader From Obfuscated Batch File isc.sans.edu/diary/31540
isc.sans.edu
Modiloader From Obfuscated Batch File - SANS Internet Storm Center
Modiloader From Obfuscated Batch File, Author: Xavier Mertens
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 20/12/2024
Christmas "Gift" Delivered Through SSH isc.sans.edu/diary/31538
isc.sans.edu
Christmas
Christmas "Gift" Delivered Through SSH, Author: Xavier Mertens
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 20/12/2024
Interesting read: Windows Server 2022 and MsMpEng.exe www.hexacorn.com/blog/2024/12...
hexacorn.com
011
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 17/12/2024
Python Delivering AnyDesk Client as RAT isc.sans.edu/diary/31524
isc.sans.edu
Python Delivering AnyDesk Client as RAT - SANS Internet Storm Center
Python Delivering AnyDesk Client as RAT, Author: Xavier Mertens
030
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 16/12/2024
Is it me or the price of printer cartridges became really insane? @HP has a business more lucrative than #ransomware gangs! Hey Bad Guys, move to the printer business! 👿
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 13/12/2024
“I see coins everywhere!” 😍
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 12/12/2024
Cyber Defense #Netwars running at full speed in Frankfurt! #SANSEMEA
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 10/12/2024
Full set of Belgian speakers at SANS@Night in Frankfurt tonight! 🇧🇪 The room was full! So exciting! #SANSEMEA
030
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 09/12/2024
My last #FOR610 run for this year! Welcome Frankfurt!
040
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 30/11/2024
From a Regular Infostealer to its Obfuscated Version isc.sans.edu/diary/31484 #SANSISC
isc.sans.edu
From a Regular Infostealer to its Obfuscated Version - SANS Internet Storm Center
From a Regular Infostealer to its Obfuscated Version, Author: Xavier Mertens
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 27/11/2024
Some attackers look like #scriptkiddies and need a GUI 😆 #Ransomware
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 25/11/2024
IT Archeology… I found this today!
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 22/11/2024
Me, writing #Python scripts for #malware analysis..
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 22/11/2024
An Infostealer Searching for « BIP-0039 » Data isc.sans.edu/diary/31464
isc.sans.edu
An Infostealer Searching for « BIP-0039 » Data - SANS Internet Storm Center
063
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 19/11/2024
Best comment ever from one student here in #FOR710: « Although i have been an ida pro believer for 10+ years, i like how #Ghidra makes everything FUN while to IDA Pro you're only a sub :( » #QotD
151
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 19/11/2024
Detecting the Presence of a Debugger in Linux isc.sans.edu/diary/31450
isc.sans.edu
Detecting the Presence of a Debugger in Linux - SANS Internet Storm Center
Detecting the Presence of a Debugger in Linux, Author: Xavier Mertens
011
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 02/01/2024
A nice hunting technique in #Splunk: www.hexacorn.com/blog/2024/01...
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 01/01/2024
Interesting #lolbin: www.hexacorn.com/blog/2023/12...
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 31/12/2023
Dear Followers, Happy 0x7E8!
010
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 23/12/2023
From @sansisc.bsky.social : Python Keylogger Using Mailtrap.io i5c.us/d30512
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 22/12/2023
From @sansisc.bsky.social: Shall We Play a Game? i5c.us/d30510
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 16/12/2023
From @sansisc.bsky.social : An Example of RocketMQ Exploit Scanner i5c.us/d30492
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 15/12/2023
From @sansisc.bsky.social: CSharp Payload Phoning to a CobaltStrike Server i5c.us/d30490
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 13/12/2023
From @sansisc.bsky.social: Malicious Python Script with a TCL/TK GUI i5c.us/d30478
000
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 17/11/2023
When you perform a brute force on a DNS zone, nothing is returned (even a simple 'www'), and you realize that you made a typo in the domain... 🤦 #FridayStory
010
Reposted by Xavier Mertens 🇧🇪
SANS.edu Internet Storm Center @sansisc.bsky.social · 14/11/2023
Microsoft Patch Tuesday November 2023 i5c.us/d30400
051
Xavier Mertens 🇧🇪 @eeksme.bsky.social · 14/11/2023
Finally joined... Hello! \o
080