Sign in

mthcht

@mthcht.bsky.social
934 followers 310 following 69 posts

Threat Hunting - DFIR - Detection Engineering 🐙 github.com/mthcht 🐦 x.com/mthcht 📰 mthcht.medium.com

PostsRepliesMedia
mthcht @mthcht.bsky.social · 06/05/2026
CTI and SOC folks, you’ll like this one! ThreatCheck lets you select IOCs from any web page, bulk-extract and dedupe them, then pivot across 29 threat intel platforms with optional auto API enrichment. chromewebstore.google.com/detail/threa... github.com/mthcht/threa...
000
mthcht @mthcht.bsky.social · 03/04/2026
💠 VSXSentry 💠 vsxsentry.github.io VS Code Extensions threat intel feeds for multiple platforms, VSIX analyzer, scripts & policy generator, remediation and forensic traces guide
021
mthcht @mthcht.bsky.social · 28/03/2026
🧅 TOR archive feed: tor-archive.github.io Every IP that has ever been a TOR node! Searchable with full timeline, exit/guard/middle role, country, ASN, updated hourly since 2024.
1183
mthcht @mthcht.bsky.social · 02/04/2025
it used to be great...
140
mthcht @mthcht.bsky.social · 02/03/2025
🎭 #ThreatHunting February updates 🎭 🐙 release: github.com/mthcht/Threa... 🌐 Site: mthcht.github.io/ThreatHuntin... 🧬 yara: github.com/mthcht/Threa... 🐾 Specific artifact lists: github.com/mthcht/aweso...
052
mthcht @mthcht.bsky.social · 19/02/2025
It's growing! Now at 38 services and 82 projects 🙈 What's your favorite LoLC2?
120
mthcht @mthcht.bsky.social · 13/02/2025
Path masquerading zerosalarium.com/2025/01/path... Interesting technique, if you're hunting for this, you can directly search the unicode characters in Splunk 🥷
020
mthcht @mthcht.bsky.social · 12/02/2025
Most SOCs handle hundreds to thousands of detection rules in their SIEM. Proper categorization is essential when creating a new detection, as it helps define criticality, urgency, implementation effort, and verbosity level. Keeping things structured will reducing alert fatigue!
051
mthcht @mthcht.bsky.social · 09/02/2025
Hexadecimal IP Detection: Identifiy hexadecimal IP addresses format in command lines with a "simple" regex (some default behaviors to exclude)
010
mthcht @mthcht.bsky.social · 09/02/2025
Special Caracters anomaly Detection: This query Extracts common special caracters from the process command line, counts occurrences, calculates ratio, and return commands with more than 20% specials caracters in it, could catch the quote insertions and url transformers techniques
120
mthcht @mthcht.bsky.social · 09/02/2025
#ThreatHunting ideas for detecting command-line obfuscation techniques from github.com/wietze/Invok... with Splunk! (examples with EID 4688) Mixed Case Randomization Detection: This query counts uppercase/lowercase letters and return command lines with a near-equal ratio
151
mthcht @mthcht.bsky.social · 09/02/2025
I have a list of NS used for sinkhole domains and seized servers: raw.githubusercontent.com/mthcht/awesome… I'm searching for the domains, on my server I can resolve a record type for ~400 million domains per day with github.com/blechschmidt/m��� 😃 Massive improvement compared to other solutions!
111
mthcht @mthcht.bsky.social · 29/01/2025
❄️ #ThreatHunting December + January updates ❄️ 🐙 release: github.com/mthcht/Threa... 🌐 Site: mthcht.github.io/ThreatHuntin... 🧬yara: github.com/mthcht/Threa... 🐾Specific artifact lists: github.com/mthcht/aweso...
042
mthcht @mthcht.bsky.social · 28/01/2025
I like these Threat Profiles pages! grab the IOCs, cross-check with your database, kick off a quick hunt 👌 app.validin.com
020
mthcht @mthcht.bsky.social · 04/01/2025
I made a windows #DFIR artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later)
12312
mthcht @mthcht.bsky.social · 18/12/2024
I just pushed a huge update to the project with 5,000 new reports, bringing the total to over 16,000! The next one’s going to be massive too!
062
mthcht @mthcht.bsky.social · 15/12/2024
Pretty sure not many are hunting for VM tool usages. This persistence technique, used by Ragnar Locker ransomware, deserves more attention from defenders: embracethered.com/blog/shadowb...
2122
mthcht @mthcht.bsky.social · 09/12/2024
My intelligence-gathering sheet for planning #ThreatHunting sessions
072
mthcht @mthcht.bsky.social · 09/12/2024
Knowledge is power! Prepare your #ThreatHunting sessions by gathering intelligence reports on specific topics - could be tools, patterns, or threat actor groups 🏛️ mthcht.github.io/ThreatIntel-... Now featuring more than 1,000 search results in over 11,000 Intelligence Reports updated regularly!
2149
mthcht @mthcht.bsky.social · 08/12/2024
On the hunt for all the tools this ransomware group used 🔭
151
mthcht @mthcht.bsky.social · 04/12/2024
Apparently, this is a thing 🤔 the legit Ookla speedtest.exe downloaded and executed by Dagon Locker and Dispossesor ransomware group (as far as i know) for network assessment
020
mthcht @mthcht.bsky.social · 18/11/2024
Great training materials available here: github.com/mthcht/aweso...
174
mthcht @mthcht.bsky.social · 18/11/2024
A regex to hunt for this phishing pattern in the file_path field with Splunk 🔎
000
mthcht @mthcht.bsky.social · 10/11/2024
📑 Detection Lists 📑 github.com/mthcht/awesome… #ThreatHunting #DFIR #SOC
0146