Click here to download all references as Bib-File.•
| 2024-09-03
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Advanced Cyberchef Techniques - Defeating Nanocore Obfuscation With Math and Flow Control Nanocore RAT | 
| 2024-08-04
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Decoding a Cobalt Strike Downloader Script With CyberChef Cobalt Strike | 
| 2024-05-23
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Tracking APT SideWinder With DNS Records SideWinder | 
| 2024-05-21
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Tweets on decoding a Latrodectus loader Latrodectus | 
| 2024-05-15
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Revealing Spammer Infrastructure With Passive DNS - 226 Toll-Themed Domains Targeting Australia | 
| 2024-04-11
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Tracking Malicious Infrastructure With DNS Records - Vultur Banking Trojan Vultur | 
| 2024-04-04
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ TLS Certificate For Threat Intelligence - Identifying MatanBuchus Domains Through Hardcoded Certificate Values Matanbuchus | 
| 2024-04-01
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Passive DNS For Phishing Link Analysis - Identifying 36 Latrodectus Domains With Historical Records and 302 Redirects Latrodectus | 
| 2024-03-30
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Uncovering APT Infrastructure with Passive DNS Pivoting | 
| 2024-03-27
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Uncovering Malicious Infrastructure with DNS Pivoting LokiBot XWorm | 
| 2024-02-26
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Advanced CyberChef Techniques for Configuration Extraction - Detailed Walkthrough and Examples NetSupportManager RAT | 
| 2023-12-20
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Defeating Obfuscated Malware Scripts - Cobalt Strike Cobalt Strike | 
| 2023-12-19
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Free Ghidra Tutorials for Beginners Cobalt Strike DarkGate | 
| 2023-12-08
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Ghidra Basics - Manual Shellcode Analysis and C2 Extraction Cobalt Strike | 
| 2023-12-06
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Ghidra Basics - Identifying, Decoding and Fixing Encrypted Strings Vidar | 
| 2023-11-30
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Advanced Threat Intel Queries - Catching 83 Qakbot Servers with Regex, Censys and TLS Certificates QakBot | 
| 2023-11-27
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Building Threat Intel Queries Utilising Regex and TLS Certificates - (BianLian) BianLian | 
| 2023-11-26
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Identifying Suspected PrivateLoader Servers with Censys PrivateLoader | 
| 2023-11-22
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Practical Queries for Malware Infrastructure - Part 3 (Advanced Examples) BianLian Xtreme RAT NjRAT QakBot RedLine Stealer Remcos | 
| 2023-11-19
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Combining Pivot Points to Identify Malware Infrastructure - Redline, Smokeloader and Cobalt Strike Amadey Cobalt Strike RedLine Stealer SmokeLoader |