Sign in

Pulsedive Threat Intelligence

@pulsedive.com
68 followers 1 following 24 posts

Frictionless threat intelligence solutions for growing teams. On-demand searching, scanning & enrichment for the security community. Dive right in at pulsedive.com.

PostsRepliesMedia
Pulsedive Threat Intelligence @pulsedive.com · 29/09/2026
In light of the recent ShinyHunters arrest, we analyzed the massive threat network they operate within: "The Com". We cover who they are, how groups like Scattered Spider and LAPSUS$ operate, and key mitigations for cybersecurity teams. Read now: blog.pulsedive.com/inside-the-c...
blog.pulsedive.com
Inside The Com: Understanding the Ecosystem Behind Scattered Spider, LAPSUS$, ShinyHunters, and FALCON
Analysis and mitigations for "The Com", a decentralized, fluid ecosystem of cybercriminals known to constantly rebrand and run shared playbooks.
011
Pulsedive Threat Intelligence @pulsedive.com · 18/06/2026
We recently created a guide for operationalizing ASN data for threat detection with @feedly.com Check out how, when, and why to track ASNs alongside IOCs here: feedly.com/ti-essential...
011
Pulsedive Threat Intelligence @pulsedive.com · 09/06/2026
Our analysis of SolyxImmortal shows how the Python-based infostealer achieves: browser credential theft, cookie theft, keylogging, targeted screenshots, and Discord-based exfiltration, all in ~10KB. blog.pulsedive.com/solyximmorta...
blog.pulsedive.com
SolyxImmortal - Analysis of a Python-based Information Stealer
Get a detailed technical breakdown with execution flow of SolyxImmortal, a Python-based information stealer.
000
Pulsedive Threat Intelligence @pulsedive.com · 13/08/2025
Our threat research team details KiwiStealer's capabilities and a malware analysis of how it exfiltrates data via HTTP POST requests in our latest blog: blog.pulsedive.com/unpacking-ki...
blog.pulsedive.com
Unpacking KiwiStealer: Diving into BITTER APT’s Malware
Learn about KiwiStealer capabilities and malware analysis of how it exfiltrates data via HTTP POST requests.
000
Pulsedive Threat Intelligence @pulsedive.com · 30/06/2025
Where do IPs and domains have a place in CTI workflows? What can and should you do with them? Here's our take: blog.pulsedive.com/collection-t...
blog.pulsedive.com
Collection through Correlation: Operationalizing IP and Domain Indicators of Compromise
IP addresses and domains aren’t just for blocklists; when analyzed with the right tools, they can be operationalized to enrich alerts, support threat hunting, and uncover risk.
000
Pulsedive Threat Intelligence @pulsedive.com · 09/06/2025
Community Resource Share: "Ransomch(.)at" ransomch.at A collection of real-world ransomware negotiations in support of analysis, data-driven insights, and industry collaboration. The existing collection of chats from 23 ransomware brands so far include: Akira BlackBasta Conti Hive Lockbit REvil
ransomch.at
Ransomch.at - a dive into ransomware negotiations
010
Pulsedive Threat Intelligence @pulsedive.com · 16/05/2025
Newest threat research blog out now: Albabat 2.0.0 Decoded We dig into Albabat's config file, executed ransomware commands, and ransom note. Read: blog.pulsedive.com/albabat-2-0-...
blog.pulsedive.com
Albabat 2.0.0 Decoded: A Config-Driven Design
This blog analyzes Albabat ransomware, exploring its config file, executed ransomware commands, and ransom note.
000
Pulsedive Threat Intelligence @pulsedive.com · 12/05/2025
Just added 1.4K+ IOCs related to phishing kit Oriental Gudgeon, primarily targeting Japanese financial services cos. Investigate shared properties & attributes: pulsedive.com/threat/Orien... Explore IOCs: pulsedive.com/explore/?q=t... Credit to the urlscan team: urlscan.io/blog/2025/05...
000
Pulsedive Threat Intelligence @pulsedive.com · 31/03/2025
Learn more: US DOJ Release: www.justice.gov/opa/pr/justi... Threat Profile: pulsedive.com/threat/Earth...
000
Pulsedive Threat Intelligence @pulsedive.com · 31/03/2025
In March, the US DOJ unsealed an indictment against 12 Chinese nationals for involvement in global espionage operations, including 8 i-Soon employees. Operations were related to and some attacks attributed to Earth Lusca, also known as FishMonger and Aquatic Panda, amongst other aliases.
100
Pulsedive Threat Intelligence @pulsedive.com · 24/03/2025
Related Threats: Hellcat & Morpheus pulsedive.com/threat/Hellc... pulsedive.com/threat/Morph... - Recent growth in activity for both RaaS brands - Identical payloads suggest shared codebase - Differing victims and contact details
000
Pulsedive Threat Intelligence @pulsedive.com · 21/03/2025
This analysis covers the three known mechanisms for delivery (including PPT, Twitter, Google Ads lures) as well as the complete intrusion chain.
000
Pulsedive Threat Intelligence @pulsedive.com · 21/03/2025
New analysis of Rilide delivery methods and intrusion chain out now: blog.pulsedive.com/rilide-an-in... First reported in April 2023, Rilide is an information stealer masquerading as a browser extension targeting Chromium-based browsers.
blog.pulsedive.com
Rilide: An Information Stealing Browser Extension
Learn about the information stealing browser extension Rilide, its delivery methods, and intrusion chain.
100
Pulsedive Threat Intelligence @pulsedive.com · 07/03/2025
Community Share: "Black Basta Chat Leak - Organization & Infrastructure" by Cyber_0leg / Cybercrime Diaries www.cybercrimediaries.com/post/black-b... This blog examines exposed details of Black Basta, including its leadership hierarchies, business model, and technical infrastructure.
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
000
Pulsedive Threat Intelligence @pulsedive.com · 05/03/2025
New research on the PolarEdge botnet: - Targeting edge devices (Cisco, QNAP, Synology, ASUS) - Active since at least Q4 2023 - Compromised 2K+ unique IP addresses - Report and analysis by Sekoia.io: lnkd.in/g4Wfi2Vt - Pulsedive profile: pulsedive.com/threat/Polar...
000
Pulsedive Threat Intelligence @pulsedive.com · 25/02/2025
Browser extensions are commonly used, but present a significant security risk as a growing threat vector. Our newest blog looks at examples from January 2025, including Cyberhaven and GraphQL Network Inspector, to discuss how threat actors compromise extensions. blog.pulsedive.com/compromised-...
blog.pulsedive.com
Compromised Browser Extensions - Jan 2025 | Pulsedive Blog
Learn how threat actors leverage browser extensions as an attack vector, including examples for Cyberhaven and GraphQL Network Inspector.
011
Pulsedive Threat Intelligence @pulsedive.com · 07/01/2025
Our guide includes how to install and use Assemblyline, an example walkthrough, and helpful resources.
000
Pulsedive Threat Intelligence @pulsedive.com · 07/01/2025
The tool is ideal for blue teams, CTI researchers, and IR professionals looking to automate and streamline malware samples processing. It is especially helpful for security teams handling large volumes of malware and seeking a scalable, customizable solution for efficient triage.
100
Pulsedive Threat Intelligence @pulsedive.com · 07/01/2025
Just published a 101 guide on how to use Assemblyline, the open-source malware triage tool created by the Canadian Centre for Cyber Security. Read: blog.pulsedive.com/assemblyline...
blog.pulsedive.com
Assemblyline for Open Source Malware Triage | Tool Guide
Learn how to install and use Assemblyline, the open-source malware triage tool. This 101 includes an overview, deployment walkthrough, example use case, and resources.
100
Pulsedive Threat Intelligence @pulsedive.com · 30/12/2024
000
Pulsedive Threat Intelligence @pulsedive.com · 30/12/2024
Plus, catch a rewind of Pulsedive at the end, including most read blogs and product updates.
110
Pulsedive Threat Intelligence @pulsedive.com · 30/12/2024
Our recap of 2024: - Key exploited vulnerabilities - Top malware - Outages - Law enforcement actions - Looking ahead to 2025 Read: blog.pulsedive.com/2024-in-revi...
blog.pulsedive.com
Pulsedive Blog | 2024 In Review
A rewind of the year across the threat landscape and at Pulsedive.
111
Reposted by Pulsedive Threat Intelligence
netbroom @netbroom.bsky.social · 10/12/2024
just pushed an update to @pulsedive.com, should improve scan performance and Analyze bulk scan hangs.
022
Pulsedive Threat Intelligence @pulsedive.com · 09/12/2024
With 3 weeks left in 2024, we wanted to thank you for all you do in the security community. So we're hosting a year-end sticker giveaway through Dec. 21- no purchase necessary. To participate: - Like this post 👍 - Fill out: forms.gle/nxLQQxNtRahS...
032
Pulsedive Threat Intelligence @pulsedive.com · 29/11/2024
Places to find infosec Black Friday deals: "The Big List for Infosec" github.com/0x90n/InfoSe... "For Security Professionals and Developers" github.com/davidalex89/... "Tagged, Searchable, and All Year Round" training.dfirdiva.com/current-disc...
github.com
GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
All the deals for InfoSec related software/tools this Black Friday - 0x90n/InfoSec-Black-Friday
054