Sign in

IntelCorgi

@intelcorgi.bsky.social
212 followers 522 following 46 posts

cyber threat intelligence, OSINT, and corgi hair. Thoughts are my own, RT/Like != Endorsement. (He/Him) Blog: intelcorgi.com

PostsRepliesMedia
IntelCorgi @intelcorgi.bsky.social · 25/09/2026
My first ever in-person cybersecurity conference was @bsidesorl.bsky.social back in 2019. So I am really pumped to be giving my talk "OSINT Wins: A Celebration of Poor Threat Actor OPSEC" at the conference tomorrow!
Talk bannerTalk description: OSINT is challenging. Analysts frequently run into frustrating dead-ends over the course of months-long investigations into organizations or individuals. But sometimes the subject will slip up and reveal a piece of information that lets the analyst connect the remaining dots or open up a new avenue of investigation. During this presentation, we will thoroughly dissect a social-media scam and explore how the threat actor's lackluster operational security (OPSEC) allow us to piece together the multiple scams the actor has been running throughout the years. Attendees will learn examples of OPSEC mistakes to look for during investigations and see first hand how exploiting threat actor
010
IntelCorgi @intelcorgi.bsky.social · 08/06/2026
Idk if I was a foreign intel operator trawling LinkedIn and I saw someone’s dad made a sponsored post advertising his sons name, job in the military, and clearance level I might splurge a bit on lunch that day #opsecawareness
Screenshot showing a LinkedIn post where a dad advertised his sons active TS Clearance
000
IntelCorgi @intelcorgi.bsky.social · 24/03/2026
I handed my son this book and he started crying
000
IntelCorgi @intelcorgi.bsky.social · 14/10/2025
Shot / chaser
010
IntelCorgi @intelcorgi.bsky.social · 22/06/2025
Honestly surprised we got “legalize asbestos” before “legalize smoking in restaurants”
010
IntelCorgi @intelcorgi.bsky.social · 23/02/2025
Postponing PMRP prep with my second rule for #100DaysOfYARA. This one focuses on finding the B64 decoding routine seen in the final stages of the Coyote Banking Trojan. www.fortinet.com/blog/threat-...
My YARA rule for detecting the b64 routine seen in the Coyote Banking TrojanThe entire infection chain for Coyote https://www.fortinet.com/blog/threat-research/coyote-banking-trojan-a-stealthy-attack-via-lnk-files
021
IntelCorgi @intelcorgi.bsky.social · 07/02/2025
I guess the AI profile pictures are going with a “mugshot” theme now
010
IntelCorgi @intelcorgi.bsky.social · 03/02/2025
Idk I guess I don't understand the point of advertising a job as being in one city and then saying you have to relocate to a different city in a different state.
120
IntelCorgi @intelcorgi.bsky.social · 01/02/2025
The Attribution Understanders have logged on
120
IntelCorgi @intelcorgi.bsky.social · 25/01/2025
Time to buy my first paper Magic cards in years
000
IntelCorgi @intelcorgi.bsky.social · 22/01/2025
I finally got around to making my first contribution to #100DaysofYARA 2025 with two YARA rules. My first rule looks to detect Qbit Stealer, a Golang stealer which never really took off. My second rule is designed to hunt various "calling cards" the developer left, which might find related malware.
my first yara rule for 100daysofyara 2025, designed to detect qbit stealer.Second qbit rule, designed to detect calling cards from the developer.
132
IntelCorgi @intelcorgi.bsky.social · 22/12/2024
Threat research in 2024
a google search operator for the term "skibidi stealer"
074
IntelCorgi @intelcorgi.bsky.social · 17/12/2024
020
IntelCorgi @intelcorgi.bsky.social · 21/11/2024
Got my setup ready to stream @cyberwarcon.bsky.social tomorrow!
120
IntelCorgi @intelcorgi.bsky.social · 16/11/2024
Hey if you're a corporate brand social media account migrating to bsky I'd recommend using your domain as your handle.
100