Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Nicholas Grossman @nicholasgrossman.bsky.social · 24/09/2026Computer crimes are already illegal. I do not think “we knowingly deployed software we can’t control” is a legitimate defense against break those laws. 321013161
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/09/2026Malware family identification is hard, especially when samples are packed, encrypted or poorly classified. FlowCarp can help identify the correct malware family and reduce alert overlap. netresec.com?b=2692109netresec.comUnmasking Malware FamiliesIdentifying malware families is hard. Malware samples are often packed, strings encrypted and configurations may only appear after several stages of execution. Even experienced reverse engineers can g... 022
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Saher @saffronsec.bsky.social · 09/09/2026Exploits, zero-days, robots, oh my! New research from @threatinsight.proofpoint.com on multiple China-aligned actors using an exploit chain with Chrome (patch-gap) and Windows zero-days and indicators of AI-assisted development. Meet BlueMoon exploit kit: www.proofpoint.com/us/blog/thre...proofpoint.comOnce in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint USAnalyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. 185
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/09/2026PolarProxy 2.0.2 is out! 🧦 SOCKS proxy tunneling 🅿️ Environment variable support ⌛️ Improved timeouts 📜 SBOM for supply chain transparency netresec.com?b=2692ad6netresec.comPolarProxy 2.0.2 ReleasedA few more handy features have been added to PolarProxy, our TLS inspection proxy. PolarProxy can now tunnel outgoing connections through SOCKS proxies and supports environment variables as an alterna... 032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 31/08/2026OT networks still need monitoring. We examine the Polish CHP plant hack and show how better network security monitoring could have detected the attackers before they carried out destructive actions. netresec.com?b=2686c28netresec.comOT Networks Still Need MonitoringCERT Polska recently published a follow-up report detailing the hack of a Polish combined heat and power (CHP) plant in December 2025. CERT Polskas report concludes with several important recommendati... 042
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/08/2026New blog post: #CNCMachineRMS C2 Protocol We analyze the malware’s binary C2 protocol, DoH usage, related infrastructure and network detection opportunities. netresec.com?b=268ee19netresec.comCNCMachineRMS C2 ProtocolThis post describes the binary command-and-control (C2) protocol used by CNCMachineRMS, a recently identified remote access trojan (RAT). We cover how the protocol was discovered, how its infrastructu... 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/07/2026zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT. netresec.com?b=267e877netresec.comPureLogs, PureRAT and misleading zgRATPlease stop classifying malware as zgRAT. That malware label is confusing. As far as I know, there isnt a proper definition of what zgRAT actually is. Some claim that zgRAT is the same malware family ... 011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 25/06/2026Pivoting on hashes and IPs ➡️ Ping32 RMM and ValleyRAT 👾 d43fdaa1f0ee09d7e5f0f94ee9df7b6c 📡 143.92.37.168:18987 (UDP) 👾 8266b00c4e45d728cef78b3f5a865f68 📡 143.92.37.168:10086 (UDP) netresec.com?b=2666e31netresec.comPing32 RMM and ValleyRATFareed Radzi recently blogged about a malware campaign observed earlier in June by Kasperskys GReAT team. The malware campaign embedded malicious code in VBScripts, which were distributed through What... 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/06/2026Maximizing IOC Impact: Advice on extracting, verifying, and sharing IOCs for fast, broad protection. netresec.com?b=26653f3netresec.comMaximizing IOC ImpactIve been thinking about threat intelligence lately. Specifically: indicators of compromise (IOC), how and where to share them to cause maximum pain to adversaries and help as many organizations as pos... 111
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/06/2026PolarProxy 2.0.1 Released 🐻❄️ 💨 Improved performance 🐞 Bug fixes ⚖️ Prioritizes PCAP output over throughput netresec.com?b=266dc11netresec.comPolarProxy 2.0.1 ReleasedOur TLS inspection proxy PolarProxy has been updated with bug fixes, improved performance and more reliable PCAP output. The recent PolarProxy 2.0 release added musl/Alpine compatibility and support f... 031
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/05/2026New release of CapLoader JA3/JA4/SNI extraction from multi-segment TLS handshakes 🚨 Alerts on IOCs from Rösti (rosti.dev) 👀 OSINT lookup on BGP.Tools/IPinfo/Netify/ScanMalware 📦️ Extracts packets from more encapsulation protocols netresec.com?b=265c041netresec.comCapLoader 2.1.0 ReleasedCapLoader has been updated to version 2.1.0. The new release comes with better JA3/JA4 extraction and integration of additional threat-intel and OSINT services. We have also added support for more enc... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 22/05/2026Tell me ChatGPT writes your articles without telling me ChatGPT writes your articles 052
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 18/05/2026PolarProxy 2.0 TLS inspection proxy released 📦️ Single self-contained binary release 🔀 Improved HTTP proxy 🐳 Builds for Linux musl (Alpine) ARM/ARM64 🪄 Simplified deployment netresec.com?b=2658a26netresec.comPolarProxy 2.0 ReleasedA new major release of PolarProxy is out with a self-contained single-file binary, expanded platform support (musl/ARM), and improved container and service plumbing. PolarProxy is a transparent TLS/SS... 012
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/05/2026Viewing #remcos alerts from FlowCarp in @unx.ca's #EveBox netresec.com?b=2659fc0netresec.comRemcos Alerts from FlowCarp in EveBoxThere is a wonderful little web based alert and event front-end called EveBox, which renders Eve JSON formatted data to a graphical user interface. This blog post demonstrates how EveBox can be used t... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 04/05/2026New tool released: FlowCarp 🔍 Identifies protocols without port numbers 🔨 Build protocol detection from example traffic ➡️ Input: PCAP or PcapNG ⬅️ Output: Flows and/or Alerts netresec.com?b=265d268netresec.comFlowCarp Identifies ProtocolsI am thrilled to announce the release of a brand new tool called FlowCarp! FlowCarp is a simple command line tool that performs a very complicated task. It identifies the application layer protocol in... 032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 19/03/2026This "JWT_SESSION" cookie sure looks funky, with base64 encoded data between "metaPrefix" and "metaSuffix"! 🔥 66.234.147.10:8080 031
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 10/03/2026✨ DFRWS EU 2026 Workshops Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations. 📍 Workshop Dates 23–24 March 2026 🧿 Details here: buff.ly/oT8OtbE #MemoryForensics #PCAP #TOR 011
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 05/03/2026✨DFRWS EU 2026 Workshops All DFRWS #Workshops and Social Events are inclusive in Registration. 👍 📍 Workshop Dates 23–24 March 2026 📍 Hybrid • Linköping, Sweden Explore workshop details 👉 buff.ly/Q45nyji Register 👉 buff.ly/lsQrqiZ #NetworkTrafficAnalysis #MemoryForensics #DFIR #TorAnalysis 031
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Europol @europol.europa.eu · 04/03/2026🔐 A major phishing-as-a-service platform disrupted. Tycoon2FA enabled large-scale account compromise by bypassing MFA protections. Through Europol’s Cyber Intelligence Extension Programme, industry intelligence was turned into operational results. Read more here: ow.ly/GECE50YoZIO 084
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Snorre Fagerland @snoffle.bsky.social · 01/03/2026I'm interested in getting in touch with anyone who was involved in the WANK/OILZ worm outbreak at NASA/CERN/DoE in 1989. I've talked to a few folks, but there are still blanks in this story - if you were part of that please ping me. 068
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/02/202621 of the world's best intelligence and security agencies cannot be wrong... right? netresec.com?b=26233f4 121
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 26/02/2026Do CISA analysts type out IOC domains by hand? netresec.com?b=26233f4netresec.comCISA mixup of IOC domainsGoogle's Threat Intelligence Group (GTIG) and Mandiant's recent Disrupting the GRIDTIDE Global Cyber Espionage Campaign report is great and it has lots of good Indicators of Compromise (IOC). ... 001
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 06/02/2026✨ DFRWS EU 2026 Workshops Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations. 📍 Workshop Dates 23–24 March 2026 📍 Details here: 👉 buff.ly/oT8OtbE 011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/02/2026Erik Hjelmvik will run a hands-on network forensic workshop at the upcoming Digital Forensics Research Conference in Sweden. Participants will get the chance to analyze: 🔪 Packets carved from memory dumps 🧅 Unencrypted Tor traffic dfrws.org/dfrws-eu-202...dfrws.orgDFRWS EU 2026 Workshop – Hands-on Analysis of Network Packets Carved from Memory & PCAP Analysis of Unencrypted Tor Traffic - DFRWS 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 02/02/2026Decoding #njRAT C2 traffic to extract screenshots, commands and transferred files netresec.com?b=262adb9netresec.comnjRAT runs MassLoggernjRAT is a remote access trojan that has been around for more than 10 years and still remains one of the most popular RATs among criminal threat actors. This blog post demonstrates how NetworkMiner Pr... 032
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Joe Slowik @pylos.co · 31/01/2026Some initial thoughts on recent disclosures concerning the December 2025 incident targeting the Polish electric sector - with a focus on #CTI elements such as attribution implications and methodology: pylos.co/2026/01/31/a...pylos.coAttributive Questions in High Profile IncidentsOn 30 January 2026, CERT.PL published findings concerning an electric sector attack on Poland in December 2025. This report, presumably the most complete on the incident covering multiple sources a… 172
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/01/2026Thank you for those kind words! 💜 www.linkedin.com/pulse/issue-... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 26/01/2026The early bird discount, for our live online network forensics class, expires by the end of this week. Sign up if you’d like to analyze PCAP files together with Erik Hjelmvik (creator of NetworkMiner and PolarProxy). netresec.com?b=25A2e4fnetresec.comOnline Network Forensics ClassI will teach a live online network forensics training on February 23-26. The full title of the class is Network Forensics for Incident Response, where we will analyze PCAP files containing network tra... 001
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 21/01/2026DFRWS EU 2026 is seeking posters showcasing interesting digital forensics research for presentation in Linköping, Sweden, 24–27th March 2026. 📥 Submit via EasyChair (PDF) - Rolling notification until the program is full! #DFRWSEU2026 #DFRWS #DigitalForensics 001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 20/01/2026🎬 Video: Decoding malware C2 with #CyberChef netresec.com?b=261f535netresec.comDecoding malware C2 with CyberChefThis video tutorial demonstrates how malware C2 traffic can be decoded with CyberChef. The PCAP files with the analyzed network traffic can be downloaded from malware-traffic-analysis.net. CyberChef r... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025Extracting VNC screenshots and keylog data from #Latrodectus 🕷️ BackConnect netresec.com?b=25Cfd08netresec.comLatrodectus BackConnectI recently learned that the great folks from The DFIR Report have done a writeup covering the Latrodectus backdoor. Their report is titled From a Single Click: How Lunar Spider Enabled a Near Two-Mont... 162
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 01/12/2025NetworkMiner 3.1 Released! 🔑 More usernames, passwords and hostnames from #PCAP 💻 Improved user interface 👾 Better details from malware C2 traffic netresec.com?b=25C4039netresec.comNetworkMiner 3.1 ReleasedThis NetworkMiner release brings improved extraction of artifacts like usernames, passwords and hostnames from network traffic. We have also made some updates to the user interface and continued our e... 022
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲StrikeReady Labs @strikereadylabs.com · 20/11/2025CN #APT targeting attendees of a diabetes conference in Singapore in December attd.z23.web.core[.]windows[.]net/ATTD-ASIA-2025.zip (live link, careful!) ATTD-ASIA-2025.lnk a12357ff6c0f7b021f32b0c9cd3d01c4 ATTD-ASIA-2025.zip a8082a80cef9ccee9d7a35f5366e3afb gzv.msi 32e7dcbd26b6455974d5b2c52c3ca421 🐴 231
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲David J. Bianco @davidjbianco.bsky.social · 06/11/2025I love the idea of calculating the decay rate of an IOC. It's not always strictly mathematical, because it also relies on threat actors' choices about how they use the IOCs, but as an estimate and for decision making, this seems promising. Also, I really like @netresec.com's ASCII art Pyramid. 😀 261
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/11/2025Monitoring for too many old indicators not only costs money, it can even inhibit detection of real intrusions. 📆 Include "last seen" date when publishing IOCs ❌ Prune old IOCs 📜 Prioritize long lived IOCs over short lived ones netresec.com?b=25Be9ddnetresec.comOptimizing IOC Retention TimeAre you importing indicators of compromise (IOC) in the form of domain names and IP addresses into your SIEM, NDR or IDS? If so, have you considered for how long you should keep looking for those IOCs... 131
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 24/09/2025🚨 The #DFRWSEU 2026 paper submission deadline has been extended to 10th October 2025 🎉 Submit your paper showcasing cutting-edge digital forensics research. 📤 Submit here: buff.ly/BN8Jlnb ℹ️ Conference details: buff.ly/KOw9Xpr #DFRWS #DigitalForensics #CFP 031
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 24/09/2025Gh0stKCP is a C2 transport protocol based on KCP. It has been used by malware families such as #PseudoManuscrypt and #ValleyRAT. netresec.com?b=259a5afnetresec.comGh0stKCP ProtocolGh0stKCP is a command-and-control (C2) transport protocol based on KCP. It has been used by malware families such as PseudoManuscrypt and ValleyRAT/Winos4.0. @Jane_0sint recently tweeted about ValleyR... 032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/08/2025Video: Detecting #XenoRAT C2 connections using example traffic from known malware sample. 🔥 e0b465d3bd1ec5e95aee016951d55640 🔥 5ab23ac79ede02166d6f5013d89738f9 📡 Huy1612-24727.portmap[.]io:24727 📡 193.161.193.99:24727 📡 147.185.221.30:54661 netresec.com?b=258f641netresec.comDefine Protocol from Traffic (XenoRAT)This video shows how to define a protocol in CapLoader just by providing examples of what the protocol looks like. CapLoader can then identify that protocol in other traffic, regardless of IP address ... 011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 12/08/2025How to identify #PureRAT (aka #ResolverRAT): ⛳️ C2 port is often 56001, 56002 or 56003 🔢 Bot sends 04 00 00 00, then TLS handshake 🔑 Client and server run TLS 1.0 🖊️ X.509 cert is self signed 📅 X.509 cert expires 9999-12-31 netresec.com?b=2589522netresec.comPureRAT = ResolverRAT = PureHVNCPureRAT is a Remote Access Trojan, which can be used by an attacker to remotely control someone else's PC. PureRAT provides the following features to an attacker: See the victims user interfaceInt... 111
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 02/07/2025💧 Dropper connects to legitimate website 📄 Fake PDF is downloaded over HTTPS 💾 Fake PDF is decrypted to a #PureLogs DLL ⚙️ InstallUtil.exe or RegAsm.exe is started 💉 PureLogs DLL is injected into the running process 👾 PureLogs connects to C2 server netresec.com?b=257eeadnetresec.comPureLogs ForensicsI analyzed some PureLogs malware infections this morning and found some interesting behavior and artifacts that I want to share. PureLogs infections sometimes start with a dropper/downloader that retr... 030
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 01/07/2025CapLoader 2.0.1 Released ⚠️ IP lookup alert 🔎 Better protocol identification 🐛 Bug fixes netresec.com?b=2571527netresec.comCapLoader 2.0.1 ReleasedThis update resolves several minor bugs, but also brings better protocol identification and a new IP lookup alert to CapLoader. Alert for IP lookup using ip-api.com in PCAP from tria.ge Transcript of ... 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 24/06/2025Does anyone know what malware this is? C2 is on 104.16.0.0/13 (CloudFlare). C2 domains: 🔥 event-time-microsoft[.]org 🔥 windows-msgas[.]com 🔥 event-datamicrosoft[.]live 🔥 eventdata-microsoft[.]live PCAP from @malware-traffic-analysis.net infosec.exchange/@netresec/11...infosec.exchange𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 (@netresec@infosec.exchange)Attached: 1 image @malware_traffic There's some unknown but interesting C2 traffic going on to net 104.16.0.0/13 (on CloudFlare). An HTTP POST is sent every 30 seconds (see Gantt chart) with gz compr... 121
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 09/06/2025Video: Detecting #PureLogs C2 traffic with #CapLoader netresec.com?b=256a8c4netresec.comDetecting PureLogs traffic with CapLoaderCapLoader includes a feature for Port Independent Protocol Identification (PIPI), which can detect which protocol is being used inside of TCP and UDP sessions without relying on the port number. In th... 053
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 02/06/2025CapLoader 2.0 released today! 🔎 Identifies over 250 protocols in #PCAP 🎨 Define protocols from example traffic 🇶 Extracts JA3, JA4 and SNI from QUIC 💻 10x faster user interface netresec.com?b=256dbbcnetresec.comCapLoader 2.0 ReleasedI am thrilled to announce the release of CapLoader 2.0 today! This major update includes a lot of new features, such as a QUIC parser, alerts for threat hunting and a feature that allow users to defin... 012
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 22/05/2025Thank you CISA, @ncsc.gov.uk, @bsi.bund.de et al. for publishing the advisory on Russian GRU Targeting Western Logistics Entities and Technology Companies. This list of mocking services is great for threat hunting! www.cisa.gov/news-events/... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/05/2025Comparison of tools that extract files from #PCAP 📖 #Chaosreader ⛏️ #NetworkMiner 🐿️ #Suricata 🌊 #tcpflow 🦈 #Wireshark 👁️ #Zeek netresec.com?b=255329fnetresec.comComparison of tools that extract files from PCAPOne of the premier features in NetworkMiner is the ability to extract files from captured network traffic in PCAP files. NetworkMiner reassembles the file contents by parsing protocols that are used t... 122
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 28/04/2025Did you know that NetworkMiner parses the #njRAT protocol? The following artefacts are extracted from njRAT C2 traffic: 🖥️ Screenshots of victim computer 📁 Transferred files 👾 Commands from C2 server 🤖 Replies from bot 🔑 Stolen credentials/passwords ⌨️ Keylog data netresec.com?b=2541a39netresec.comDecoding njRAT traffic with NetworkMinerI investigate network traffic from a Triage sandbox execution of njRAT in this video. The analysis is performed using NetworkMiner in Linux (REMnux to be specific). About njRAT / Bladabindi njRAT is a... 062
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/04/2025New instructions for installing NetworkMiner on Linux netresec.com?b=2542784netresec.comHow to Install NetworkMiner in LinuxThis guide shows how to install the latest version of NetworkMiner in Linux. To install an older NetworkMiner release, prior to version 3.0, please see our legacy NetworkMiner in Linux guide. STEP 1: ... 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 04/04/2025NetworkMiner 3.0 Released! 🔐 QUIC 🏭 CIP (EtherNet/IP) 🏭 UMAS (over Mobdus) 👾 Remcos RAT 🔍 Improved OS fingerprinting 🐧 Better Linux integration netresec.com?b=254caa9netresec.comNetworkMiner 3.0 ReleasedI am very proud to announce the release of NetworkMiner 3.0 today! This version brings several new protocols as well as user interface improvements to NetworkMiner. We have also made significant chang... 033