Sign in

mthcht

@mthcht.bsky.social
929 followers 310 following 69 posts

Threat Hunting - DFIR - Detection Engineering 🐙 github.com/mthcht 🐦 x.com/mthcht 📰 mthcht.medium.com

PostsRepliesMedia
mthcht @mthcht.bsky.social · 22/06/2026
Microsoft Graph Permissions list classified by severity and privileged impact to detect risky OAuth consents, over-privileged apps, consent phishing, apps with dangerous access, and enrich SIEM detections/app reviews. github.com/mthcht/aweso...
github.com
020
mthcht @mthcht.bsky.social · 06/05/2026
CTI and SOC folks, you’ll like this one! ThreatCheck lets you select IOCs from any web page, bulk-extract and dedupe them, then pivot across 29 threat intel platforms with optional auto API enrichment. chromewebstore.google.com/detail/threa... github.com/mthcht/threa...
000
Reposted by mthcht
mthcht @mthcht.bsky.social · 29/04/2026
Launching oauthsentry.github.io Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub). Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit 🦾
oauthsentry.github.io
OAuthSentry - OAuth application intelligence for defenders
Search OAuth Application IDs across Microsoft Entra, Google Workspace and more. Three classification feeds for defenders: compliance, risky, and malicious. Includes investigation playbooks, forensic t...
113
mthcht @mthcht.bsky.social · 05/05/2026
Adding VSXSentry-Guard A VS Code extension that automatically blocks and removes malicious extensions from the VSXSentry feed. No enterprise policy management needed - one click and you're protected. marketplace.visualstudio.com/items?itemNa...
023
mthcht @mthcht.bsky.social · 29/04/2026
Launching oauthsentry.github.io Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub). Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit 🦾
oauthsentry.github.io
OAuthSentry - OAuth application intelligence for defenders
Search OAuth Application IDs across Microsoft Entra, Google Workspace and more. Three classification feeds for defenders: compliance, risky, and malicious. Includes investigation playbooks, forensic t...
113
mthcht @mthcht.bsky.social · 18/04/2026
Nehboro, a browser extension blocking phishing attempts on page load nehboro.github.io ⚡️ Dedicated IOCs feed - Blocking BAD AS IP ranges, domains & reported urls 📊 97 heuristic detections for all kind of scams 🤖 AI Analysis on demand hopefully in the webstore soon
nehboro.github.io
Nehboro - Community Threat Intelligence
Community-powered browser extension with 97 dynamic detections, static IOC feeds, and optional Claude AI analysis. Protection against phishing, ClickFix, and malware.
100
mthcht @mthcht.bsky.social · 12/04/2026
Automatically block and disable malicious browser extensions with a browser extension! Perfect for family devices or anyone who just wants simple protection, no GPOs or enterprise setup... now on the Chrome Web Store: chromewebstore.google.com/detail/extse...
chromewebstore.google.com
ExtSentry Guard - Chrome Web Store
Detects and warns about known malicious browser extensions using the ExtSentry IOC feed.
001
mthcht @mthcht.bsky.social · 03/04/2026
💠 VSXSentry 💠 vsxsentry.github.io VS Code Extensions threat intel feeds for multiple platforms, VSIX analyzer, scripts & policy generator, remediation and forensic traces guide
021
mthcht @mthcht.bsky.social · 28/03/2026
🧅 TOR archive feed: tor-archive.github.io Every IP that has ever been a TOR node! Searchable with full timeline, exit/guard/middle role, country, ASN, updated hourly since 2024.
1183
mthcht @mthcht.bsky.social · 25/03/2026
🧩 ExtSentry 🧩 extsentry.github.io Browser Extensions threat intel feeds for multiple platforms + extension checker, permissions analyzer, policy generator, forensic traces guide, remediation playbook & endpoint inventory scripts github.com/ExtSentry/Ex...
github.com
GitHub - ExtSentry/ExtSentry.github.io: Browser Extension Threat Intelligence feed - extsentry.github.io
Browser Extension Threat Intelligence feed - extsentry.github.io - ExtSentry/ExtSentry.github.io
000
mthcht @mthcht.bsky.social · 20/03/2026
LOLC2 Collection of C2 frameworks abusing legitimate services to evade detection Major update: new projects tested, enriched data, and deeper insights. lolc2.github.io
030
mthcht @mthcht.bsky.social · 18/03/2026
LOLFSAAS Living off Free SaaS Hundreds of SaaS platforms with free tiers, documenting abuse surface, opsec risks, authent methods, C2 framework mappings, and operational limits. lolfsaas.github.io
lolfsaas.github.io
LOLFSaaS - Living off Free SaaS
022
mthcht @mthcht.bsky.social · 15/03/2026
LOLEXFIL Living off the land Data Exfiltration method lolexfil.github.io
lolexfil.github.io
LOLEXFIL — LOL Exfiltration Reference
011
mthcht @mthcht.bsky.social · 09/03/2026
If you want to experiment with the Splunk MCP Server splunkbase.splunk.com/app/7931, I just published a client to interact with it: github.com/mthcht/Splun... it cost around 5 cents per splunk query, an automated case investigation cost an average of 50 cents depending on the complexity.
github.com
GitHub - mthcht/Splunk-MCP-Client: Query Splunk in natural language using Claude AI and the Splunk MCP Server.
Query Splunk in natural language using Claude AI and the Splunk MCP Server. - mthcht/Splunk-MCP-Client
000
mthcht @mthcht.bsky.social · 24/05/2025
Lumma Stealer - 995 sinkholed domains by Microsoft gist.github.com/mthcht/4b16e...
gist.github.com
Lumma Stealer sinkholed domains
Lumma Stealer sinkholed domains. GitHub Gist: instantly share code, notes, and snippets.
010
mthcht @mthcht.bsky.social · 02/04/2025
it used to be great...
140
mthcht @mthcht.bsky.social · 27/03/2025
I started another list dedicated to mutex names for detection github.com/mthcht/aweso... Help me enhance this list, I still have plenty more to add!
github.com
120
mthcht @mthcht.bsky.social · 08/03/2025
THIS WEBSITE HAS BEEN SEIZED Discover domains tied to sinkhole NS servers at sinkholed.github.io Filter by TLD or NS, export in JSON/CSV, weekly update! Search for the known sinkhole Name Servers in DNS query logs and web access to the sinkholed domains to identify potentially compromised hosts!
sinkholed.github.io
1115
mthcht @mthcht.bsky.social · 04/03/2025
😯 I have 652022 sinkholed domains extracted here github.com/mthcht/aweso...
011
mthcht @mthcht.bsky.social · 02/03/2025
🎭 #ThreatHunting February updates 🎭 🐙 release: github.com/mthcht/Threa... 🌐 Site: mthcht.github.io/ThreatHuntin... 🧬 yara: github.com/mthcht/Threa... 🐾 Specific artifact lists: github.com/mthcht/aweso...
052
Reposted by mthcht
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 25/02/2025
From over at the Bad Place: There's an interesting NTFS symlink attack outlined here: dfir.ru/2025/02/23/symlink-attacks-… Basically, if an NTFS filesystem is corrupted in a way to provide duplicate file names, Windows will […] [Original post on infosec.exchange]
Powershell: after 5 "type .\5\test.txt" calls, the test.txt file is a symlink to win.ini
CMD: A single "type .\6\test.txt" call results in every single file being printed, including the final win.ini symlink
11613
Reposted by mthcht
Kostas @kostastsale.bsky.social · 24/02/2025
It took just 3 hours: RCE → Metasploit C2 → Anydesk for remote GUI-access → LockBit ransomware Interestingly, we observed the threat actor using PDQ Deploy, a patch management tool. Read the report here:
thedfirreport.com
Confluence Exploit Leads to LockBit Ransomware
Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.…
173
mthcht @mthcht.bsky.social · 20/02/2025
A bookmark of my lists is now automatically generated after each update in my repo github.com/mthcht/aweso... I'm also looking to automatically add my starred repos lists github.com/mthcht?tab=s... in this bookmark but there doesn’t seem to be a API endpoint for the stars lists 🤔 ?
070
mthcht @mthcht.bsky.social · 19/02/2025
It's growing! Now at 38 services and 82 projects 🙈 What's your favorite LoLC2?
120
Reposted by mthcht
BertJanCyber @bertjancyber.bsky.social · 17/02/2025
Pushed a #KQL for: Successful device code sign-in from an unmanaged device. Query is available for AADSignInEventsBeta and SigninLogs. Less known is the AADSignInEventsBeta filter for device code: | where EndpointCall == "Cmsi:Cmsi" 🏹Query: github.com/Bert-JanP/Hu...
253
mthcht @mthcht.bsky.social · 17/02/2025
In case you don't want to do this yourself, I just discovered that you can request access to a complete list of all existing domains across 1131 TLDs on czds.icann.org for free, including NS records! The lists are updated every month, approval is required for each TLD 🌍
031
Reposted by mthcht
Nasreddine Bencherchali @nasbench.bsky.social · 15/02/2025
Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time www.splunk.com/en_us/blog/s.... Thrilled to share my first blog at @splunk! @mhaggis.bsky.social and I take a deep dive into the weird & exciting world of SDDL and ACEs - what they are, how they work, and how attackers can abuse them.
splunk.com
Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time | Splunk
Explore SDDL in Windows security with our comprehensive guide to help enhance your defensive strategy against privilege escalation attacks.
0125
mthcht @mthcht.bsky.social · 13/02/2025
Path masquerading zerosalarium.com/2025/01/path... Interesting technique, if you're hunting for this, you can directly search the unicode characters in Splunk 🥷
020
mthcht @mthcht.bsky.social · 12/02/2025
Most SOCs handle hundreds to thousands of detection rules in their SIEM. Proper categorization is essential when creating a new detection, as it helps define criticality, urgency, implementation effort, and verbosity level. Keeping things structured will reducing alert fatigue!
051
mthcht @mthcht.bsky.social · 11/02/2025
I'll keep this updated, let me know if you have any projects to add! some C2 candidates: github.com/lolc2/lolc2....
031
Reposted by mthcht
Squiblydoo @squiblydoo.bsky.social · 10/02/2025
Cert Central .org is live! We track and report abused code-signing certs. By submitting to the website, you contribute to the DB of >800 certs—a DB you can access and view. Want to get more involved? Check out the Training and Research pages to learn more. 1/2
1147
mthcht @mthcht.bsky.social · 09/02/2025
#ThreatHunting ideas for detecting command-line obfuscation techniques from github.com/wietze/Invok... with Splunk! (examples with EID 4688) Mixed Case Randomization Detection: This query counts uppercase/lowercase letters and return command lines with a near-equal ratio
151
mthcht @mthcht.bsky.social · 09/02/2025
I have a list of NS used for sinkhole domains and seized servers: raw.githubusercontent.com/mthcht/awesome… I'm searching for the domains, on my server I can resolve a record type for ~400 million domains per day with github.com/blechschmidt/m��� 😃 Massive improvement compared to other solutions!
111
Reposted by mthcht
CyberRaiju @jaiminton.com · 02/02/2025
I frequently get asked is "what skills do I need need to excel as an analyst", so I figure this is a good opportunity to shed some light on what analysis is, and why certifications alone won't make you a good analyst. www.jaiminton.com/high-impact-...
jaiminton.com
HISAC - High Impact Security Analysis and Communication
How to be a well rounded SOC/MDR/Cyber/Information Security Analyst.
084
mthcht @mthcht.bsky.social · 31/01/2025
Say goodnight to the bad GUIDs ! badguids.github.io
186
Reposted by mthcht
beercow.bsky.social @beercow.bsky.social · 28/01/2025
There seemed to be enough interest so I decided to do a write up on what I have found about OneDrive Offline Mode. Hate to burn a forensic artifact but I’m concerned about what Microsoft feels is secure. #DFIR malwaremaloney.blogspot.com/2025/01…
malwaremaloney.blogspot.com
MALoney (It's in the name): OneDrive Offline Mode (Recallish vibes)
Back in April 2024, Microsoft announced a new feature coming to OneDrive for Business called Offline Mode. The feature al...
1105
Reposted by mthcht
Wietze @wietzebeukema.nl · 28/01/2025
#LOLBAS project update: Entries now have placeholders for paths, URLs, and more. This makes it easier to visually see what parts are "variable", and for LOLBAS API users (lolbas-project.github.io/api/) it'll be easier to use with automation. Check it out: ⭐ lolbas-project.github.io
0136
Reposted by mthcht
Hexacorn @hexacorn.bsky.social · 12/01/2024
Adding character(s) to Command Line processing www.hexacorn.com/blog/2024/01... #threathunting
031
mthcht @mthcht.bsky.social · 29/01/2025
❄️ #ThreatHunting December + January updates ❄️ 🐙 release: github.com/mthcht/Threa... 🌐 Site: mthcht.github.io/ThreatHuntin... 🧬yara: github.com/mthcht/Threa... 🐾Specific artifact lists: github.com/mthcht/aweso...
042
mthcht @mthcht.bsky.social · 28/01/2025
I like these Threat Profiles pages! grab the IOCs, cross-check with your database, kick off a quick hunt 👌 app.validin.com
020
mthcht @mthcht.bsky.social · 26/01/2025
LOLC2 - a collection of C2 projects that operate exclusively through legitimate services lolc2.github.io, I'm probably missing some projects let me know ! 🌐 lolc2.github.io 🐙 github.com/lolc2/lolc2....
github.com
GitHub - lolc2/lolc2.github.io: lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection
lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection - lolc2/lolc2.github.io
0117
Reposted by mthcht
Richard Davis @davisrichardg.bsky.social · 06/01/2025
🥳👇
031
mthcht @mthcht.bsky.social · 09/01/2025
Are you hunting for BAD ASN IP ranges? my lists are automatically updated on github github.com/mthcht/aweso... Try searching for these IPs in your successful login logs or outbound network requests 🔎 (consider these as low signal for correlation or threat hunting sessions
github.com
120
mthcht @mthcht.bsky.social · 04/01/2025
I made a windows #DFIR artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later)
12312
Reposted by mthcht
Hexacorn @hexacorn.bsky.social · 31/12/2024
Clean hash set - 12M rows www.hexacorn.com/blog/2024/12...
041
mthcht @mthcht.bsky.social · 18/12/2024
I just pushed a huge update to the project with 5,000 new reports, bringing the total to over 16,000! The next one’s going to be massive too!
062
mthcht @mthcht.bsky.social · 15/12/2024
Stealer repos on GitHub with their topics 😋 Saving this for later analysis: gist.github.com/mthcht/82885...
gist.github.com
Github Stealer repos topics 20241215
GitHub Gist: instantly share code, notes, and snippets.
030
mthcht @mthcht.bsky.social · 15/12/2024
Pretty sure not many are hunting for VM tool usages. This persistence technique, used by Ragnar Locker ransomware, deserves more attention from defenders: embracethered.com/blog/shadowb...
2122
mthcht @mthcht.bsky.social · 09/12/2024
My intelligence-gathering sheet for planning #ThreatHunting sessions
072
mthcht @mthcht.bsky.social · 09/12/2024
🦃 #ThreatHunting November updates 🦃 🐙Project: github.com/mthcht/Threa... 🏹 Site: mthcht.github.io/ThreatHuntin... 🧬 yara: github.com/mthcht/Threa... 🧬Specific artifact lists: github.com/mthcht/aweso...
github.com
Release November 2024 updates · mthcht/ThreatHunting-Keywords
November 2024 updates 62 tools added or updated. 59508 detection patterns Detection patterns for Dispossesor Ransomware group tools have been added. New yara strict ruleset added the yara repo In...
193