Sign in

Pulsedive Threat Intelligence

@pulsedive.com
68 followers 1 following 24 posts

Frictionless threat intelligence solutions for growing teams. On-demand searching, scanning & enrichment for the security community. Dive right in at pulsedive.com.

PostsRepliesMedia
Pulsedive Threat Intelligence @pulsedive.com · 29/09/2026
In light of the recent ShinyHunters arrest, we analyzed the massive threat network they operate within: "The Com". We cover who they are, how groups like Scattered Spider and LAPSUS$ operate, and key mitigations for cybersecurity teams. Read now: blog.pulsedive.com/inside-the-c...
blog.pulsedive.com
Inside The Com: Understanding the Ecosystem Behind Scattered Spider, LAPSUS$, ShinyHunters, and FALCON
Analysis and mitigations for "The Com", a decentralized, fluid ecosystem of cybercriminals known to constantly rebrand and run shared playbooks.
011
Pulsedive Threat Intelligence @pulsedive.com · 18/06/2026
We recently created a guide for operationalizing ASN data for threat detection with @feedly.com Check out how, when, and why to track ASNs alongside IOCs here: feedly.com/ti-essential...
011
Pulsedive Threat Intelligence @pulsedive.com · 09/06/2026
Our analysis of SolyxImmortal shows how the Python-based infostealer achieves: browser credential theft, cookie theft, keylogging, targeted screenshots, and Discord-based exfiltration, all in ~10KB. blog.pulsedive.com/solyximmorta...
blog.pulsedive.com
SolyxImmortal - Analysis of a Python-based Information Stealer
Get a detailed technical breakdown with execution flow of SolyxImmortal, a Python-based information stealer.
000
Pulsedive Threat Intelligence @pulsedive.com · 13/08/2025
Our threat research team details KiwiStealer's capabilities and a malware analysis of how it exfiltrates data via HTTP POST requests in our latest blog: blog.pulsedive.com/unpacking-ki...
blog.pulsedive.com
Unpacking KiwiStealer: Diving into BITTER APT’s Malware
Learn about KiwiStealer capabilities and malware analysis of how it exfiltrates data via HTTP POST requests.
000
Pulsedive Threat Intelligence @pulsedive.com · 30/06/2025
Where do IPs and domains have a place in CTI workflows? What can and should you do with them? Here's our take: blog.pulsedive.com/collection-t...
blog.pulsedive.com
Collection through Correlation: Operationalizing IP and Domain Indicators of Compromise
IP addresses and domains aren’t just for blocklists; when analyzed with the right tools, they can be operationalized to enrich alerts, support threat hunting, and uncover risk.
000
Pulsedive Threat Intelligence @pulsedive.com · 09/06/2025
Community Resource Share: "Ransomch(.)at" ransomch.at A collection of real-world ransomware negotiations in support of analysis, data-driven insights, and industry collaboration. The existing collection of chats from 23 ransomware brands so far include: Akira BlackBasta Conti Hive Lockbit REvil
ransomch.at
Ransomch.at - a dive into ransomware negotiations
010
Pulsedive Threat Intelligence @pulsedive.com · 16/05/2025
Newest threat research blog out now: Albabat 2.0.0 Decoded We dig into Albabat's config file, executed ransomware commands, and ransom note. Read: blog.pulsedive.com/albabat-2-0-...
blog.pulsedive.com
Albabat 2.0.0 Decoded: A Config-Driven Design
This blog analyzes Albabat ransomware, exploring its config file, executed ransomware commands, and ransom note.
000
Pulsedive Threat Intelligence @pulsedive.com · 12/05/2025
Just added 1.4K+ IOCs related to phishing kit Oriental Gudgeon, primarily targeting Japanese financial services cos. Investigate shared properties & attributes: pulsedive.com/threat/Orien... Explore IOCs: pulsedive.com/explore/?q=t... Credit to the urlscan team: urlscan.io/blog/2025/05...
000
Pulsedive Threat Intelligence @pulsedive.com · 31/03/2025
In March, the US DOJ unsealed an indictment against 12 Chinese nationals for involvement in global espionage operations, including 8 i-Soon employees. Operations were related to and some attacks attributed to Earth Lusca, also known as FishMonger and Aquatic Panda, amongst other aliases.
100
Pulsedive Threat Intelligence @pulsedive.com · 24/03/2025
Related Threats: Hellcat & Morpheus pulsedive.com/threat/Hellc... pulsedive.com/threat/Morph... - Recent growth in activity for both RaaS brands - Identical payloads suggest shared codebase - Differing victims and contact details
000
Pulsedive Threat Intelligence @pulsedive.com · 21/03/2025
New analysis of Rilide delivery methods and intrusion chain out now: blog.pulsedive.com/rilide-an-in... First reported in April 2023, Rilide is an information stealer masquerading as a browser extension targeting Chromium-based browsers.
blog.pulsedive.com
Rilide: An Information Stealing Browser Extension
Learn about the information stealing browser extension Rilide, its delivery methods, and intrusion chain.
100
Pulsedive Threat Intelligence @pulsedive.com · 07/03/2025
Community Share: "Black Basta Chat Leak - Organization & Infrastructure" by Cyber_0leg / Cybercrime Diaries www.cybercrimediaries.com/post/black-b... This blog examines exposed details of Black Basta, including its leadership hierarchies, business model, and technical infrastructure.
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
000
Pulsedive Threat Intelligence @pulsedive.com · 05/03/2025
New research on the PolarEdge botnet: - Targeting edge devices (Cisco, QNAP, Synology, ASUS) - Active since at least Q4 2023 - Compromised 2K+ unique IP addresses - Report and analysis by Sekoia.io: lnkd.in/g4Wfi2Vt - Pulsedive profile: pulsedive.com/threat/Polar...
000
Pulsedive Threat Intelligence @pulsedive.com · 25/02/2025
Browser extensions are commonly used, but present a significant security risk as a growing threat vector. Our newest blog looks at examples from January 2025, including Cyberhaven and GraphQL Network Inspector, to discuss how threat actors compromise extensions. blog.pulsedive.com/compromised-...
blog.pulsedive.com
Compromised Browser Extensions - Jan 2025 | Pulsedive Blog
Learn how threat actors leverage browser extensions as an attack vector, including examples for Cyberhaven and GraphQL Network Inspector.
011
Pulsedive Threat Intelligence @pulsedive.com · 07/01/2025
Just published a 101 guide on how to use Assemblyline, the open-source malware triage tool created by the Canadian Centre for Cyber Security. Read: blog.pulsedive.com/assemblyline...
blog.pulsedive.com
Assemblyline for Open Source Malware Triage | Tool Guide
Learn how to install and use Assemblyline, the open-source malware triage tool. This 101 includes an overview, deployment walkthrough, example use case, and resources.
100
Pulsedive Threat Intelligence @pulsedive.com · 30/12/2024
Our recap of 2024: - Key exploited vulnerabilities - Top malware - Outages - Law enforcement actions - Looking ahead to 2025 Read: blog.pulsedive.com/2024-in-revi...
blog.pulsedive.com
Pulsedive Blog | 2024 In Review
A rewind of the year across the threat landscape and at Pulsedive.
111
Reposted by Pulsedive Threat Intelligence
netbroom @netbroom.bsky.social · 10/12/2024
just pushed an update to @pulsedive.com, should improve scan performance and Analyze bulk scan hangs.
022
Pulsedive Threat Intelligence @pulsedive.com · 09/12/2024
With 3 weeks left in 2024, we wanted to thank you for all you do in the security community. So we're hosting a year-end sticker giveaway through Dec. 21- no purchase necessary. To participate: - Like this post 👍 - Fill out: forms.gle/nxLQQxNtRahS...
032
Pulsedive Threat Intelligence @pulsedive.com · 29/11/2024
Places to find infosec Black Friday deals: "The Big List for Infosec" github.com/0x90n/InfoSe... "For Security Professionals and Developers" github.com/davidalex89/... "Tagged, Searchable, and All Year Round" training.dfirdiva.com/current-disc...
github.com
GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
All the deals for InfoSec related software/tools this Black Friday - 0x90n/InfoSec-Black-Friday
054