Click here to download all references as Bib-File.•
2024-09-03
⋅
Twitter (@embee_research)
⋅
Advanced Cyberchef Techniques - Defeating Nanocore Obfuscation With Math and Flow Control Nanocore RAT |
2024-08-04
⋅
Twitter (@embee_research)
⋅
Decoding a Cobalt Strike Downloader Script With CyberChef Cobalt Strike |
2024-05-23
⋅
Twitter (@embee_research)
⋅
Tracking APT SideWinder With DNS Records SideWinder |
2024-05-21
⋅
Twitter (@embee_research)
⋅
Tweets on decoding a Latrodectus loader Latrodectus |
2024-05-15
⋅
Twitter (@embee_research)
⋅
Revealing Spammer Infrastructure With Passive DNS - 226 Toll-Themed Domains Targeting Australia |
2024-04-11
⋅
Twitter (@embee_research)
⋅
Tracking Malicious Infrastructure With DNS Records - Vultur Banking Trojan Vultur |
2024-04-04
⋅
Twitter (@embee_research)
⋅
TLS Certificate For Threat Intelligence - Identifying MatanBuchus Domains Through Hardcoded Certificate Values Matanbuchus |
2024-04-01
⋅
Twitter (@embee_research)
⋅
Passive DNS For Phishing Link Analysis - Identifying 36 Latrodectus Domains With Historical Records and 302 Redirects Latrodectus |
2024-03-30
⋅
Twitter (@embee_research)
⋅
Uncovering APT Infrastructure with Passive DNS Pivoting |
2024-03-27
⋅
Twitter (@embee_research)
⋅
Uncovering Malicious Infrastructure with DNS Pivoting LokiBot XWorm |
2024-02-26
⋅
Twitter (@embee_research)
⋅
Advanced CyberChef Techniques for Configuration Extraction - Detailed Walkthrough and Examples NetSupportManager RAT |
2023-12-20
⋅
Twitter (@embee_research)
⋅
Defeating Obfuscated Malware Scripts - Cobalt Strike Cobalt Strike |
2023-12-19
⋅
Twitter (@embee_research)
⋅
Free Ghidra Tutorials for Beginners Cobalt Strike DarkGate |
2023-12-08
⋅
Twitter (@embee_research)
⋅
Ghidra Basics - Manual Shellcode Analysis and C2 Extraction Cobalt Strike |
2023-12-06
⋅
Twitter (@embee_research)
⋅
Ghidra Basics - Identifying, Decoding and Fixing Encrypted Strings Vidar |
2023-11-30
⋅
Twitter (@embee_research)
⋅
Advanced Threat Intel Queries - Catching 83 Qakbot Servers with Regex, Censys and TLS Certificates QakBot |
2023-11-27
⋅
Twitter (@embee_research)
⋅
Building Threat Intel Queries Utilising Regex and TLS Certificates - (BianLian) BianLian |
2023-11-26
⋅
Twitter (@embee_research)
⋅
Identifying Suspected PrivateLoader Servers with Censys PrivateLoader |
2023-11-22
⋅
Twitter (@embee_research)
⋅
Practical Queries for Malware Infrastructure - Part 3 (Advanced Examples) BianLian Xtreme RAT NjRAT QakBot RedLine Stealer Remcos |
2023-11-19
⋅
Twitter (@embee_research)
⋅
Combining Pivot Points to Identify Malware Infrastructure - Redline, Smokeloader and Cobalt Strike Amadey Cobalt Strike RedLine Stealer SmokeLoader |