Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Nicholas Grossman @nicholasgrossman.bsky.social · 24/09/2026Computer crimes are already illegal. I do not think “we knowingly deployed software we can’t control” is a legitimate defense against break those laws. 321013161
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/09/2026Malware family identification is hard, especially when samples are packed, encrypted or poorly classified. FlowCarp can help identify the correct malware family and reduce alert overlap. netresec.com?b=2692109netresec.comUnmasking Malware FamiliesIdentifying malware families is hard. Malware samples are often packed, strings encrypted and configurations may only appear after several stages of execution. Even experienced reverse engineers can g... 022
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Saher @saffronsec.bsky.social · 09/09/2026Exploits, zero-days, robots, oh my! New research from @threatinsight.proofpoint.com on multiple China-aligned actors using an exploit chain with Chrome (patch-gap) and Windows zero-days and indicators of AI-assisted development. Meet BlueMoon exploit kit: www.proofpoint.com/us/blog/thre...proofpoint.comOnce in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint USAnalyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. 185
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/09/2026PolarProxy 2.0.2 is out! 🧦 SOCKS proxy tunneling 🅿️ Environment variable support ⌛️ Improved timeouts 📜 SBOM for supply chain transparency netresec.com?b=2692ad6netresec.comPolarProxy 2.0.2 ReleasedA few more handy features have been added to PolarProxy, our TLS inspection proxy. PolarProxy can now tunnel outgoing connections through SOCKS proxies and supports environment variables as an alterna... 032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 31/08/2026OT networks still need monitoring. We examine the Polish CHP plant hack and show how better network security monitoring could have detected the attackers before they carried out destructive actions. netresec.com?b=2686c28netresec.comOT Networks Still Need MonitoringCERT Polska recently published a follow-up report detailing the hack of a Polish combined heat and power (CHP) plant in December 2025. CERT Polskas report concludes with several important recommendati... 042
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/08/2026New blog post: #CNCMachineRMS C2 Protocol We analyze the malware’s binary C2 protocol, DoH usage, related infrastructure and network detection opportunities. netresec.com?b=268ee19netresec.comCNCMachineRMS C2 ProtocolThis post describes the binary command-and-control (C2) protocol used by CNCMachineRMS, a recently identified remote access trojan (RAT). We cover how the protocol was discovered, how its infrastructu... 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/07/2026zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT. netresec.com?b=267e877netresec.comPureLogs, PureRAT and misleading zgRATPlease stop classifying malware as zgRAT. That malware label is confusing. As far as I know, there isnt a proper definition of what zgRAT actually is. Some claim that zgRAT is the same malware family ... 011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 25/06/2026Pivoting on hashes and IPs ➡️ Ping32 RMM and ValleyRAT 👾 d43fdaa1f0ee09d7e5f0f94ee9df7b6c 📡 143.92.37.168:18987 (UDP) 👾 8266b00c4e45d728cef78b3f5a865f68 📡 143.92.37.168:10086 (UDP) netresec.com?b=2666e31netresec.comPing32 RMM and ValleyRATFareed Radzi recently blogged about a malware campaign observed earlier in June by Kasperskys GReAT team. The malware campaign embedded malicious code in VBScripts, which were distributed through What... 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/06/2026Maximizing IOC Impact: Advice on extracting, verifying, and sharing IOCs for fast, broad protection. netresec.com?b=26653f3netresec.comMaximizing IOC ImpactIve been thinking about threat intelligence lately. Specifically: indicators of compromise (IOC), how and where to share them to cause maximum pain to adversaries and help as many organizations as pos... 111
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/06/2026PolarProxy 2.0.1 Released 🐻❄️ 💨 Improved performance 🐞 Bug fixes ⚖️ Prioritizes PCAP output over throughput netresec.com?b=266dc11netresec.comPolarProxy 2.0.1 ReleasedOur TLS inspection proxy PolarProxy has been updated with bug fixes, improved performance and more reliable PCAP output. The recent PolarProxy 2.0 release added musl/Alpine compatibility and support f... 031
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/05/2026New release of CapLoader JA3/JA4/SNI extraction from multi-segment TLS handshakes 🚨 Alerts on IOCs from Rösti (rosti.dev) 👀 OSINT lookup on BGP.Tools/IPinfo/Netify/ScanMalware 📦️ Extracts packets from more encapsulation protocols netresec.com?b=265c041netresec.comCapLoader 2.1.0 ReleasedCapLoader has been updated to version 2.1.0. The new release comes with better JA3/JA4 extraction and integration of additional threat-intel and OSINT services. We have also added support for more enc... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 22/05/2026Tell me ChatGPT writes your articles without telling me ChatGPT writes your articles 052
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 18/05/2026PolarProxy 2.0 TLS inspection proxy released 📦️ Single self-contained binary release 🔀 Improved HTTP proxy 🐳 Builds for Linux musl (Alpine) ARM/ARM64 🪄 Simplified deployment netresec.com?b=2658a26netresec.comPolarProxy 2.0 ReleasedA new major release of PolarProxy is out with a self-contained single-file binary, expanded platform support (musl/ARM), and improved container and service plumbing. PolarProxy is a transparent TLS/SS... 012
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/05/2026Viewing #remcos alerts from FlowCarp in @unx.ca's #EveBox netresec.com?b=2659fc0netresec.comRemcos Alerts from FlowCarp in EveBoxThere is a wonderful little web based alert and event front-end called EveBox, which renders Eve JSON formatted data to a graphical user interface. This blog post demonstrates how EveBox can be used t... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 04/05/2026New tool released: FlowCarp 🔍 Identifies protocols without port numbers 🔨 Build protocol detection from example traffic ➡️ Input: PCAP or PcapNG ⬅️ Output: Flows and/or Alerts netresec.com?b=265d268netresec.comFlowCarp Identifies ProtocolsI am thrilled to announce the release of a brand new tool called FlowCarp! FlowCarp is a simple command line tool that performs a very complicated task. It identifies the application layer protocol in... 032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 19/03/2026This "JWT_SESSION" cookie sure looks funky, with base64 encoded data between "metaPrefix" and "metaSuffix"! 🔥 66.234.147.10:8080 031
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 10/03/2026✨ DFRWS EU 2026 Workshops Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations. 📍 Workshop Dates 23–24 March 2026 🧿 Details here: buff.ly/oT8OtbE #MemoryForensics #PCAP #TOR 011
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 05/03/2026✨DFRWS EU 2026 Workshops All DFRWS #Workshops and Social Events are inclusive in Registration. 👍 📍 Workshop Dates 23–24 March 2026 📍 Hybrid • Linköping, Sweden Explore workshop details 👉 buff.ly/Q45nyji Register 👉 buff.ly/lsQrqiZ #NetworkTrafficAnalysis #MemoryForensics #DFIR #TorAnalysis 031
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Europol @europol.europa.eu · 04/03/2026🔐 A major phishing-as-a-service platform disrupted. Tycoon2FA enabled large-scale account compromise by bypassing MFA protections. Through Europol’s Cyber Intelligence Extension Programme, industry intelligence was turned into operational results. Read more here: ow.ly/GECE50YoZIO 084
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Snorre Fagerland @snoffle.bsky.social · 01/03/2026I'm interested in getting in touch with anyone who was involved in the WANK/OILZ worm outbreak at NASA/CERN/DoE in 1989. I've talked to a few folks, but there are still blanks in this story - if you were part of that please ping me. 068
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/02/2026netresec.com?b=26233f4netresec.comCISA mixup of IOC domainsGoogles Threat Intelligence Group (GTIG) and Mandiants recent Disrupting the GRIDTIDE Global Cyber Espionage Campaign report is great and it has lots of good Indicators of Compromise (IOC). Many of th... 001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/02/202621 of the world's best intelligence and security agencies cannot be wrong... right? netresec.com?b=26233f4 121
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 26/02/2026Do CISA analysts type out IOC domains by hand? netresec.com?b=26233f4netresec.comCISA mixup of IOC domainsGoogle's Threat Intelligence Group (GTIG) and Mandiant's recent Disrupting the GRIDTIDE Global Cyber Espionage Campaign report is great and it has lots of good Indicators of Compromise (IOC). ... 001
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 06/02/2026✨ DFRWS EU 2026 Workshops Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations. 📍 Workshop Dates 23–24 March 2026 📍 Details here: 👉 buff.ly/oT8OtbE 011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/02/2026Erik Hjelmvik will run a hands-on network forensic workshop at the upcoming Digital Forensics Research Conference in Sweden. Participants will get the chance to analyze: 🔪 Packets carved from memory dumps 🧅 Unencrypted Tor traffic dfrws.org/dfrws-eu-202...dfrws.orgDFRWS EU 2026 Workshop – Hands-on Analysis of Network Packets Carved from Memory & PCAP Analysis of Unencrypted Tor Traffic - DFRWS 021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 02/02/2026Decoding #njRAT C2 traffic to extract screenshots, commands and transferred files netresec.com?b=262adb9netresec.comnjRAT runs MassLoggernjRAT is a remote access trojan that has been around for more than 10 years and still remains one of the most popular RATs among criminal threat actors. This blog post demonstrates how NetworkMiner Pr... 032
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲Joe Slowik @pylos.co · 31/01/2026Some initial thoughts on recent disclosures concerning the December 2025 incident targeting the Polish electric sector - with a focus on #CTI elements such as attribution implications and methodology: pylos.co/2026/01/31/a...pylos.coAttributive Questions in High Profile IncidentsOn 30 January 2026, CERT.PL published findings concerning an electric sector attack on Poland in December 2025. This report, presumably the most complete on the incident covering multiple sources a… 172
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/01/2026Thank you for those kind words! 💜 www.linkedin.com/pulse/issue-... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 26/01/2026The early bird discount, for our live online network forensics class, expires by the end of this week. Sign up if you’d like to analyze PCAP files together with Erik Hjelmvik (creator of NetworkMiner and PolarProxy). netresec.com?b=25A2e4fnetresec.comOnline Network Forensics ClassI will teach a live online network forensics training on February 23-26. The full title of the class is Network Forensics for Incident Response, where we will analyze PCAP files containing network tra... 001
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 21/01/2026DFRWS EU 2026 is seeking posters showcasing interesting digital forensics research for presentation in Linköping, Sweden, 24–27th March 2026. 📥 Submit via EasyChair (PDF) - Rolling notification until the program is full! #DFRWSEU2026 #DFRWS #DigitalForensics 001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 20/01/2026🎬 Video: Decoding malware C2 with #CyberChef netresec.com?b=261f535netresec.comDecoding malware C2 with CyberChefThis video tutorial demonstrates how malware C2 traffic can be decoded with CyberChef. The PCAP files with the analyzed network traffic can be downloaded from malware-traffic-analysis.net. CyberChef r... 022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025Big thank you to @thedfirreport.bsky.social for capturing this intrusion traffic! 🎉 010
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025Keylog of attacker's hands-on keyboard actions from BackConnect VNC session 101
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025Here's one of the screenshots from the BackConnect VNC sessions in the blog post 100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025Extracting VNC screenshots and keylog data from #Latrodectus 🕷️ BackConnect netresec.com?b=25Cfd08netresec.comLatrodectus BackConnectI recently learned that the great folks from The DFIR Report have done a writeup covering the Latrodectus backdoor. Their report is titled From a Single Click: How Lunar Spider Enabled a Near Two-Mont... 162
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 01/12/2025NetworkMiner 3.1 Released! 🔑 More usernames, passwords and hostnames from #PCAP 💻 Improved user interface 👾 Better details from malware C2 traffic netresec.com?b=25C4039netresec.comNetworkMiner 3.1 ReleasedThis NetworkMiner release brings improved extraction of artifacts like usernames, passwords and hostnames from network traffic. We have also made some updates to the user interface and continued our e... 022
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲StrikeReady Labs @strikereadylabs.com · 20/11/2025CN #APT targeting attendees of a diabetes conference in Singapore in December attd.z23.web.core[.]windows[.]net/ATTD-ASIA-2025.zip (live link, careful!) ATTD-ASIA-2025.lnk a12357ff6c0f7b021f32b0c9cd3d01c4 ATTD-ASIA-2025.zip a8082a80cef9ccee9d7a35f5366e3afb gzv.msi 32e7dcbd26b6455974d5b2c52c3ca421 🐴 231
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 20/11/2025C2 runs on: 🔥 portabalbufe[.]com 🔥 172.67.212.147:443 Other C2 indicators: 🔥 JA3 a0e9f5d64349fb13191bc781f81f42e1 🔥 JA4 t12d190800_d83cc789557e_7af1ed941c26 🔥 Cert hash 25aa00e75ca12bc66ff475ebe9c6bfbd466e91ed 020
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/11/2025The boring answer is of course "it depends". But most incident responders would probably agree that a C2 IP address can be considered "old" when a couple of weeks have passed since it was last seen active. 100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/11/2025Agreed, real-world IOC decay/score varies depending on TA choices as well as the actions we take as defenders. Fantastic that you like our ASCII Pyramid of Pain 😊 Here's a CC0 licensed copy-paste friendly version: infosec.exchange/@netresec/11...infosec.exchange𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 (@netresec@infosec.exchange)Here's a copy-paste friendly version of our ASCII Pyramid of Pain License: CC0 ``` ,/\ ,´V_-\ IOC Pyramid ,´\/-__-\ of Pain ,´\\/-_--_-\ ,´\\\V_--TTP-_... 000
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲David J. Bianco @davidjbianco.bsky.social · 06/11/2025I love the idea of calculating the decay rate of an IOC. It's not always strictly mathematical, because it also relies on threat actors' choices about how they use the IOCs, but as an estimate and for decision making, this seems promising. Also, I really like @netresec.com's ASCII art Pyramid. 😀 261
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/11/2025Monitoring for too many old indicators not only costs money, it can even inhibit detection of real intrusions. 📆 Include "last seen" date when publishing IOCs ❌ Prune old IOCs 📜 Prioritize long lived IOCs over short lived ones netresec.com?b=25Be9ddnetresec.comOptimizing IOC Retention TimeAre you importing indicators of compromise (IOC) in the form of domain names and IP addresses into your SIEM, NDR or IDS? If so, have you considered for how long you should keep looking for those IOCs... 131
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲DFRWS @dfrws.bsky.social · 24/09/2025🚨 The #DFRWSEU 2026 paper submission deadline has been extended to 10th October 2025 🎉 Submit your paper showcasing cutting-edge digital forensics research. 📤 Submit here: buff.ly/BN8Jlnb ℹ️ Conference details: buff.ly/KOw9Xpr #DFRWS #DigitalForensics #CFP 031
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 24/09/2025Gh0stKCP is a C2 transport protocol based on KCP. It has been used by malware families such as #PseudoManuscrypt and #ValleyRAT. netresec.com?b=259a5afnetresec.comGh0stKCP ProtocolGh0stKCP is a command-and-control (C2) transport protocol based on KCP. It has been used by malware families such as PseudoManuscrypt and ValleyRAT/Winos4.0. @Jane_0sint recently tweeted about ValleyR... 032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/08/2025Video: Detecting #XenoRAT C2 connections using example traffic from known malware sample. 🔥 e0b465d3bd1ec5e95aee016951d55640 🔥 5ab23ac79ede02166d6f5013d89738f9 📡 Huy1612-24727.portmap[.]io:24727 📡 193.161.193.99:24727 📡 147.185.221.30:54661 netresec.com?b=258f641netresec.comDefine Protocol from Traffic (XenoRAT)This video shows how to define a protocol in CapLoader just by providing examples of what the protocol looks like. CapLoader can then identify that protocol in other traffic, regardless of IP address ... 011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 15/08/2025The threat actor then drops #PureRAT on the victim's PC infosec.exchange/@netresec/11...infosec.exchange𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 (@netresec@infosec.exchange)Attached: 1 image @BleepingComputer It then drops #PureRAT aka #ResolverRAT on the victim's PC. 000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 12/08/2025IOCs from the blog post: 🔥 193.26.115.125:8883 🔥 purebase.ddns[.]net:8883 🔥 45.74.10.38:56001 🔥 139.99.83.25:56001 010