Sign in

malmoeb.bsky.social

@malmoeb.bsky.social
701 followers 1K following 622 posts

Head of Investigations at InfoGuard AG - dfir.ch

PostsRepliesMedia
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
MacSync's iCloud Calendar trick is pretty cool. One MacSync downloader analyzed by Securelist contains a URL such as: caldav.icloud[.]com/published... It retrieves a public .ics calendar, creates an anonymous pipe, launches zsh -s, sets the pipe as stdin, and feeds it into it line by line.
100
malmoeb.bsky.social @malmoeb.bsky.social · 24/09/2026
For the love of the (macOS) game. My new blog post covers a macOS DFIR blind spot: zsh startup files such as .zshrc, .zprofile, and .zshenv can have compiled .zwc counterparts. The full blog post here: dfir.ch/posts/compil...
110
malmoeb.bsky.social @malmoeb.bsky.social · 16/09/2026
New blog post: Living Inside the Shell: zsh Modules on macOS zsh is much more than a command interpreter. Through its module system, the shell can perform operations that defenders often associate with separate binaries dfir.ch/posts/zsh_mo...
010
malmoeb.bsky.social @malmoeb.bsky.social · 14/09/2026
Microsoft recommends the following mitigations to reduce the impact of this threat: Block web pages from automatically running Flash plugins. 😂 Source: microsoft.com/en-us/securi...
000
malmoeb.bsky.social @malmoeb.bsky.social · 14/09/2026
My new "field note" shows how a seemingly generic Microsoft Defender alert can lead to a much more useful forensic finding when correlated with filesystem artifacts. Full article here: dfir.ch/posts/field_...
022
malmoeb.bsky.social @malmoeb.bsky.social · 11/09/2026
Someone at BSides Frankfurt asked me this week if I could share the slides from my talk. Of course - and not just those. 🙂 All my conference presentations are available here: github.com/malmoeb/pres...
031
malmoeb.bsky.social @malmoeb.bsky.social · 11/09/2026
If you're at BSides Tallinn, come join our anti-forensics workshop. I'm offering a 4-hour hands-on training session packed with lessons from years of incident-response work. Techniques you can apply directly in your own investigations.
020
malmoeb.bsky.social @malmoeb.bsky.social · 07/09/2026
After a fantastic first session at BruCON Spring Training earlier this year, we’re very happy to teach our Anti-Forensics course again - this time at DeepSec in Vienna. Really looking forward to teaching this one again - and to a full classroom! :) More information here: deepsec.net/schedule.html
010
malmoeb.bsky.social @malmoeb.bsky.social · 23/08/2026
After a bit of tinkering, I was able to replicate the Google Docs attack vector described in the Huntress blog post [1] Attackers can use Google’s “App Scripts” feature (in Docs) to create a clever pretext. Essentially, the attack works as follows:
130
malmoeb.bsky.social @malmoeb.bsky.social · 17/06/2026
Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes:
100
malmoeb.bsky.social @malmoeb.bsky.social · 04/06/2026
One of our pentesters was tasked with assessing a customer's perimeter and found an exposed FTP server. They queried the server's FQDN on a specialized service and (surprisingly?) found leaked login credentials.
100
malmoeb.bsky.social @malmoeb.bsky.social · 01/06/2026
On a recent Linux-based Incident Response case, we found a dropped GSocket binary as a persistence mechanism [1]. The threat actor planted the dropped binaries under user-space directories to blend in, masquerading as legitimate system processes: ./.config/dbus/php-fpm ./.config/htop/defunct
150
malmoeb.bsky.social @malmoeb.bsky.social · 13/01/2026
In the Metasploit Wrap-Up from last week, a new Python Site-Specific Hook Persistence module was released. [1] I wrote a detailed blog about this persistence, which I think is pretty cool. [2] If you have never heard of this technique, you might want to read up on it.
110
malmoeb.bsky.social @malmoeb.bsky.social · 28/12/2025
I recently thought about the different pop-ups I receive every day on my Mac, AND how malware does the same to trick people into entering their password.. and I wondered if I could tell a legitimate prompt from a malicious one. I found a good article, depicting exactly this topic:
110
malmoeb.bsky.social @malmoeb.bsky.social · 27/12/2025
As last time, the TA brought infected files into the compromised network, helping spread the infection. The file and registry paths have not changed in our case and are still the same as in my old X post.
100
malmoeb.bsky.social @malmoeb.bsky.social · 26/12/2025
The company, for whatever reason, turned off logging for Logons, as a quick check with auditpol revealed (see image). However, "Logon and Logoff" auditing is enabled by default. [1] You might want to consider checking your audit policy settings before writing yet another playbook 🤓
120
malmoeb.bsky.social @malmoeb.bsky.social · 25/12/2025
Adversaries can exploit these files to maintain persistence by injecting malicious code." [1] Path: C:\ProgramData\cp49s\Lib\sitecustomize[.]py Content: See the image below.
120
malmoeb.bsky.social @malmoeb.bsky.social · 14/12/2025
My team colleague, Yann Malherbe, worked on a case where the attacker used Everything [1] (locate files and folders by name instantly) to search for password files on the beachhead.
110
malmoeb.bsky.social @malmoeb.bsky.social · 13/12/2025
The picture below depicts a (malicious) Inbox Rule. I slightly modified this Inbox Rule to protect our customer, but the gist is that it filters incoming mail from a specific bank employee, moves it to the RSS Folder, and marks it as read.
121
malmoeb.bsky.social @malmoeb.bsky.social · 12/12/2025
For a new project, I started to dig into older threat reports, like for example, "The ProjectSauron APT" from 2016. [1] The interesting thing about these old reports is that you see techniques mentioned before that are still used 10 years later.
110
malmoeb.bsky.social @malmoeb.bsky.social · 11/12/2025
We are familiar with eMClient and axios, so let me introduce Trufflehog, the new kid on the block. Trufflehog made headlines during the recent "Shai-Hulud" campaign, in which threat actors used it to search for passwords and sensitive information. [1] According to the Trufflehog GitHub page:
112
malmoeb.bsky.social @malmoeb.bsky.social · 07/12/2025
I was playing around with bincrypter from THC (The Hackers Choice) [1]. The interesting points, as you can see in the screenshot below, are that the binary is encrypted, obfuscated, and 100% in memory. No temporary files, etc.
200
malmoeb.bsky.social @malmoeb.bsky.social · 30/11/2025
Look at my tweet from February 2022. As simple as putting NG into the country field. Guess what I found in this week's Business E-Mail Compromise? Successful logins from NG. Oh well..
100
malmoeb.bsky.social @malmoeb.bsky.social · 25/11/2025
I was reading an older report from CrowdStrike the other day: "CrowdStrike was able to reconstruct the PowerShell script from the PowerShell Operational event log as the script’s execution was logged automatically due to the use of specific keywords." [1]
140
malmoeb.bsky.social @malmoeb.bsky.social · 24/11/2025
A customer sent malware over. The file magic was CART.. What's that? Turns out, something pretty cool. "This is where CaRT (which stands for Compressed and RC4 Transport) comes in. CaRT is used to store and transfer malware, as well as its metadata.
110
malmoeb.bsky.social @malmoeb.bsky.social · 17/11/2025
I analyzed and recreated (a simpler version) of a PHP backdoor we detected in a recent Incident Response engagement. I used the backdoor to install an RMM agent on the compromised machine; the installed EDR did not raise a single alert.
110
malmoeb.bsky.social @malmoeb.bsky.social · 15/11/2025
I love reading Incident Response reports from my colleagues. This one here from Matthieu Chatelan: "Note that over 1700 lines (of risky sign-ins) were generated for this user account over the last 3 months.
210
malmoeb.bsky.social @malmoeb.bsky.social · 12/11/2025
taskhostw.exe writes a PE file (see the classic TVqQAAMAAAA sequence there) inside the UCPD\DR registry key? Microsoft implemented a driver-based protection to block changes to http/https and .pdf associations by 3rd party utilities, the so-called UCPD driver (UserChoice Protection Drive).
130
malmoeb.bsky.social @malmoeb.bsky.social · 11/11/2025
This slide also didn't make the cut. Yes, anyone who has spent more than five minutes on a Hack The Box machine will know pspy, but what about my blue-team colleagues?
120
malmoeb.bsky.social @malmoeb.bsky.social · 10/11/2025
The following slide hasn't made it into my "Fantastic cleartext password" talk, however, it's still a good one to share 🤓 "This simple tool logs usernames and passwords from authentication attempts against an OpenSSH server you control.
100
malmoeb.bsky.social @malmoeb.bsky.social · 02/11/2025
Dropping ngrok in a ZIP file onto disk results in the file being removed and an alert being raised, but installing ngrok via winget works just fine? 🤔🤷‍♂️
020
malmoeb.bsky.social @malmoeb.bsky.social · 01/11/2025
This one here is a goodie! A customer called us because they had several incidents where the system time "magically" jumped days, sometimes even months, back and forth (see screenshot). You can imagine the issues inflicted by this behavior. So the question was.. Cyber? Attacker? Misconfiguration?
121
malmoeb.bsky.social @malmoeb.bsky.social · 24/10/2025
Coming back to Maester! Do you know about the awesome Conditional Access What-If tests? [1] The first image is from the official documentation and shows how easily you can build your own test scenario. The second image shows the results from a tenant where I ran the test.
100
malmoeb.bsky.social @malmoeb.bsky.social · 23/10/2025
What is Maester? [1] Maester is a PowerShell-based test automation framework that helps you stay in control of your Microsoft security configuration. Such a cool tool - test details can be filtered by passed, failed, and skipped. Failed tests come with detailed recommendations on how to do better.
100
malmoeb.bsky.social @malmoeb.bsky.social · 21/10/2025
Lately, I’ve talked about (alternative) forensic artifacts where the retention time might be higher than your classical Security Event Logs, or might not be the first artifact to be deleted in an "anti-forensics" operation by a threat actor.
131
malmoeb.bsky.social @malmoeb.bsky.social · 20/10/2025
In various business email compromise (BEC) cases, we later discovered that although the customer had set up a conditional access (CA) policy to enforce multi-factor authentication, mistakes had been made during the implementation of said policies.
120
malmoeb.bsky.social @malmoeb.bsky.social · 18/10/2025
Second story from a recent coffee break with my pentest colleague. During a retest for a client, they discovered the same ESC1 vulnerability they had reported before. Why is that dangerous and also super critical?
121
malmoeb.bsky.social @malmoeb.bsky.social · 17/10/2025
1/ Coffee break with one of our pentesters. He casually mentioned to me, "The last attack simulation was pretty cool. We used gowitness (a website screenshot utility written in Golang, to generate screenshots of web interfaces) to find internal services [1].
151
malmoeb.bsky.social @malmoeb.bsky.social · 16/10/2025
1/ During a recent engagement, the customer provided us with access to their extensive data collection in Splunk. One thing I checked was Sysmon’s Event ID 13 (Registry - Value Set) for modifications to various keys used for credential stealing (NetworkProvider, Notification- &, Security Packages).
100
malmoeb.bsky.social @malmoeb.bsky.social · 28/09/2025
1/ Love that Minesweeper reference here :) They tried hard to blend in; however, certain metadata about a file is baked into the PE header. Attackers can rename binaries all they want, but fields like original_file_name or inconsistencies in headers often give them away.
130
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2025
1/ In today's BEC (Business E-Mail Compromise) case, I stumbled (again) over the "Set-MailboxJunkEmailConfiguration" operation. I talked about it a while back. [1] The attacker also created a new Inbox rule for moving incoming emails for target personnel to a designated folder.
142
malmoeb.bsky.social @malmoeb.bsky.social · 26/09/2025
1/ My first keynote will be about how we spend billions on (cyber) security but remain insecure. I’ll use a recent case as an example, which my colleague Asger Deleuran Strunk investigated:
100
malmoeb.bsky.social @malmoeb.bsky.social · 25/09/2025
1/ Mandiant mentioned the User Access Logs in their newest report [1]. We use the UAL extensively in our investigations, as this artifact can retain logs for a longer period of time, as outlined by Mandiant (and also covered in my Anti-Forensics presentation).
100
malmoeb.bsky.social @malmoeb.bsky.social · 21/09/2025
1/ PingCastle now highlights when no policy is in place to prevent scripting files (such as .js) from being executed via double-click.
111
malmoeb.bsky.social @malmoeb.bsky.social · 20/09/2025
3/ And indeed, a quick check on Baazar showed no hits for the file ending .pif. Process starts from a ".pif" file might be a good indicator for hunting/detection 🕵️‍♂️ [1] threatresearch.ext.hp.com/wp-content/u...
010
malmoeb.bsky.social @malmoeb.bsky.social · 19/09/2025
1/ XWorm, as described in the latest HP Wolf Security report [1], goes to great lengths to evade security products. .chm file, VBScript, PowerShell, batch file, JavaScript, PowerShell, Steganography (the data from the image is used to reflectively load a .NET assembly).. 😮‍
100
malmoeb.bsky.social @malmoeb.bsky.social · 18/08/2025
1/ Not all web browsers support the passkey (FIDO2) authentication method with Microsoft Entra ID. For instance, FIDO is not supported when using Safari on Windows.
200
malmoeb.bsky.social @malmoeb.bsky.social · 17/08/2025
1/ ASEC has recently discovered the massive distribution of SmartLoader malware through GitHub repositories. Upon searching for keywords such as game hacks, software crack, and automation tool,
110
malmoeb.bsky.social @malmoeb.bsky.social · 15/08/2025
1/ Remove discoverable passwords in Active Directory account attributes A nice feature of Microsoft Defender for Identity is its ability to detect potential credential exposure in Active Directory by analyzing commonly used free-text attributes.
110
malmoeb.bsky.social @malmoeb.bsky.social · 08/08/2025
3/ I was not sure if AutoRuns would cover this persistence, so I quickly tested it on a lab machine, and hooray, it is 🤓🥳 Full blog post here: ics-cert.kaspersky.com/publications...
010