𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 22/05/2026Tell me ChatGPT writes your articles without telling me ChatGPT writes your articles 052
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 19/03/2026This "JWT_SESSION" cookie sure looks funky, with base64 encoded data between "metaPrefix" and "metaSuffix"! 🔥 66.234.147.10:8080 031
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/02/202621 of the world's best intelligence and security agencies cannot be wrong... right? netresec.com?b=26233f4 121
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/01/2026Thank you for those kind words! 💜 www.linkedin.com/pulse/issue-... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025Keylog of attacker's hands-on keyboard actions from BackConnect VNC session 101
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025Here's one of the screenshots from the BackConnect VNC sessions in the blog post 100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 22/05/2025Thank you CISA, @ncsc.gov.uk, @bsi.bund.de et al. for publishing the advisory on Russian GRU Targeting Western Logistics Entities and Technology Companies. This list of mocking services is great for threat hunting! www.cisa.gov/news-events/... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/05/2025NetworkMiner automatically extracts EML files as well as attachments (here a jpg image) to disk when it parses emails in SMTP, POP3 or IMAP traffic. 010
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 29/01/2025Here's a Wireshark display filter that detects this type of LLMNR (multicast name resolution) spoofing: dns.count.answers > 0 and lower(dns.qry.name) != lower(dns.resp.name) 163
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 17/12/2024APT29 / Midnight Blizzard / Earth Koshchei use RDP relays to gain control of victims’ machines. One RDP config pretends to be for Regeringskansliet (Swedish Gov). Thanks to @feikeh.bsky.social and @sjhilt.hilt.zip for sharing indicators! www.trendmicro.com/en_us/resear... tria.ge/241023-qpfnl... 120
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/12/2024The dropped bot (which?) uses the NKN peer-to-peer network to hide its C2 traffic. 120
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/12/2024Downloaded a fresh pcap from any.run to verify that #CapLoader identifies this traffic as Socks5Systemz backconnect ✅ app.any.run/tasks/c1b2dc... 120
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/12/2024#Socks5Systemz backconnect traffic now uses TCP port 2024 (previously 2023) infosec.exchange/@abuse_ch@io... 121
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 28/11/2024Here's another one with instructions from C2 server to download the next stage DLL. Initial JS: 61dfc228a478f21326908f0231ff553c Dropped DLL: c6ef634779facf10516f0dd6d0d1757c app.any.run/tasks/8831ab... 120
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 28/11/2024Nice malware lab setup using FLARE VM, #PolarProxy and #REMnux to decrypt and inspect TLS traffic. www.koenmolenaar.nl/nl/write-ups... 254
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/02/2024Two new Network Forensics training events! 🇪🇺 PCAP in the Morning Europe, March 4-7 🇺🇸 PCAP in the Morning US, March 25-28 netresec.com?b=23C9979 041