Jean-Marc Albert

23.6K posts

Jean-Marc Albert

Jean-Marc Albert

@WikiJM

GCFA | PGP 2F93D5AF

45.767416,4.833418 انضم Haziran 2009
951 يتبع447 المتابعون
Jean-Marc Albert أُعيد تغريده
Matthew Green 🌻
Matthew Green 🌻@mgreen27·
🚀 One of my colleagues at InfoGuard pointed me to a cool project collating malicious browser extensions, so I wrote a Velociraptor artifact to hunt with the data. 🔗 github.com/mgreen27/Detec… 🔗 extsentry.github.io ExtSentry has some good browser extension investigation info, so it’s worth a bookmark too. #dfir
Matthew Green 🌻 tweet media
English
0
6
19
1K
Jean-Marc Albert أُعيد تغريده
Jean-Marc Albert أُعيد تغريده
Squiblydoo
Squiblydoo@SquiblydooBlog·
The CertGraveyard was created in 2025, but never received a proper introduction. We track abused code-signing certificates. When I created the site, we had 600 entries and now we have 2,250. See the blogpost below for a full overview. 1/3
English
1
9
30
1.9K
Jean-Marc Albert أُعيد تغريده
Mike Hunhoff
Mike Hunhoff@mehunhoff·
🎉 We’ve released capa v9.4 with 26 new rules and various performance improvements. Additionally, the standalone tool now supports Ghidra as a feature extraction backend. Check out the release for more details 👉 github.com/mandiant/capa/…
Mike Hunhoff tweet media
English
0
22
64
6.5K
Jean-Marc Albert أُعيد تغريده
mthcht
mthcht@mthcht2·
💠VSXSentry💠 vsxsentry.github.io VS Code Extensions threat intel feeds for multiple platforms, VSIX analyzer, scripts & policy generator, remediation and forensic traces guide
mthcht tweet media
English
0
16
53
3.5K
Jean-Marc Albert أُعيد تغريده
Threat Hunting Labs
Threat Hunting Labs@ThruntingLabs·
🎉Learning Modules are live on Threat Hunting Labs. Finish an investigation track, unlock a structured breakdown of the real attack chain you just worked. Phase-by-phase, with evidence mapping, real artifacts, and knowledge checks. Six modules live now across all 15 of our labs! Also big updates in Enterprise tiers: team credit budgets, per-member allocation, weekly team brief for managers, and methodology tagging on all investigation questions. 👉 threathuntinglabs.com/threat-hunting
Threat Hunting Labs tweet mediaThreat Hunting Labs tweet media
English
0
9
33
4.1K
Jean-Marc Albert أُعيد تغريده
Mandiant (part of Google Cloud)
Google Threat Intelligence Group is tracking an active supply chain attack 🔎 North Korea-nexus actor UNC1069 compromised the "axios" NPM package (v1.14.1 & 0.30.4), deploying the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux. Learn more: bit.ly/3NZR3Zv
Mandiant (part of Google Cloud) tweet media
English
10
141
397
30.8K
Jean-Marc Albert أُعيد تغريده
Cyber Detective💙💛
Cyber Detective💙💛@cyb_detective·
TOR Node Archive Dataset (you can download it) + online tool (search by IPs/CIDR with filter by activity time range) + stats (Top Autonomous Systems, Top /24 Subnets, Top /16 Ranges, number of active/inactive IPs) tor-archive.github.io Creator @mthcht2
Cyber Detective💙💛 tweet media
English
0
22
106
8.3K
Jean-Marc Albert أُعيد تغريده
Panos Gkatziroulis 🦄
Panos Gkatziroulis 🦄@ipurple·
📢 Recently, I explored how Toast Notifications (these app notifications from Elon Musk below) can be weaponized for social engineering. ✅ToastNotify is released to help practitioners simulate the technique and identify detection opportunities. ✅ If you want to understand the behavior end‑to‑end, you can dive into the article and grab the tool below. ⤵️ 🔗 ipurple.team/2026/03/25/toa… 🔗 github.com/netbiosX/Toast…
Panos Gkatziroulis 🦄 tweet media
Panos Gkatziroulis 🦄@ipurple

🔥 Weaponizing Windows Toast Notifications ✅ Enumeration paths: Start Menu, AppX, Registry ✅ .NET + PowerShell Snippets to craft spoofed toasts ✅ Detection via wpnapps.dll / msxml6.dll image loads ✅ SIGMA + MDE for correlation ✅ Purple Team playbook 🔗 ipurple.team/2026/03/25/toa… #ipurple #purpleteam #threathunting

English
0
19
99
13.5K
Jean-Marc Albert أُعيد تغريده
mthcht
mthcht@mthcht2·
🧅 TOR archive feed: tor-archive.github.io Every IP that has ever been a TOR node! Searchable with full timeline, exit/guard/middle role, country, ASN, updated hourly since 2024.
mthcht tweet mediamthcht tweet mediamthcht tweet media
English
4
102
645
46.4K
Jean-Marc Albert أُعيد تغريده
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨‼️ BREAKING: PyPI package telnyx has been compromised by TeamPCP in yet another supply chain attack. The malware executes immediately upon importing telnyx. It drops a valid WAV audio file and runs an executable embedded within the frames.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
63
550
3K
701.2K
Jean-Marc Albert أُعيد تغريده
Kostas
Kostas@Kostastsale·
During our research, it’s become apparent that EDRs need to do a better job of collecting telemetry from macOS endpoints. Head over to the edr-telemetry.com/macos to checkout the results yourselves. While you’re there, checkout the scores as well to see how they compare. Out of the ~43 total points, the average is 16… and that’s with one EDR bringing up the average 🙂
Kostas@Kostastsale

📢🍏 macOS is now part of the EDR Telemetry Project. After three months of focused work, we’re excited to share a new framework and generator for endpoint visibility on macOS! Huge thank you to everyone who contributed and helped shape this release. Looking forward to what comes next. Read more: edr-telemetry.com/blog/macOS-EDR…

English
2
9
87
11.9K
Jean-Marc Albert أُعيد تغريده
Kostas
Kostas@Kostastsale·
📢🍏 macOS is now part of the EDR Telemetry Project. After three months of focused work, we’re excited to share a new framework and generator for endpoint visibility on macOS! Huge thank you to everyone who contributed and helped shape this release. Looking forward to what comes next. Read more: edr-telemetry.com/blog/macOS-EDR…
English
3
33
112
17K
Jean-Marc Albert أُعيد تغريده
mthcht
mthcht@mthcht2·
new services added to lolfsaas zendesk: #Zendesk" target="_blank" rel="nofollow noopener">lolfsaas.github.io/#Zendesk milanote: #Milanote" target="_blank" rel="nofollow noopener">lolfsaas.github.io/#Milanote
mthcht@mthcht2

LOLFSAAS Living off Free SaaS Hundreds of SaaS platforms with free tiers, documenting abuse surface, opsec risks, authent methods, C2 framework mappings, and operational limits. lolfsaas.github.io

English
0
2
12
1.7K
Jean-Marc Albert أُعيد تغريده
Clandestine
Clandestine@akaclandestine·
LOLFSaaS - Living off Free SaaS lolfsaas.github.io
English
0
30
138
9.6K
Jean-Marc Albert أُعيد تغريده
Ben De St Paer-Gotch
Ben De St Paer-Gotch@Nebuk89·
Two of the top GitHub Actions community requests are now live 1. Timezone support in crons schedule: - cron '30 5 * * 1-5' timezone: "America/New_York" 2. Use environments without auto-deployments environment: name: staging deployment: false
English
8
39
126
37K