Drew

2.4K posts

Drew banner
Drew

Drew

@bugfireIO

malware detection and analysis, hunting and gathering, threat research. Views are my own. https://t.co/efJDIXnaLi

United States Katılım Ağustos 2012
591 Takip Edilen260 Takipçiler
Andrew Hay
Andrew Hay@andrewsmhay·
@HackingDave When I was a kid, my mother handed me a meatball and said "Try this and let me know if you think the meat has gone bad." I've never forgiven her for it.
English
0
0
0
52
Dave Kennedy
Dave Kennedy@HackingDave·
I love how my wife hands me food and asks “try this and let me know if I would like this” 😂😂
English
7
0
51
2.5K
Drew
Drew@bugfireIO·
@craiu Loved hearing the stories about Sergey Mineev. Sounds like he was an amazing person and inspirational to so many. Thank you for sharing.
English
0
0
1
76
Costin Raiu
Costin Raiu@craiu·
A 2.5hr opus, for your weekend earholes. We remember GReAT teammate Sergey Mineev, the legendary malware hunter behind discoveries like Equation Group and Project Sauron (Remsec), including stories about his methods and why he was the best to ever do it. Plus, another in-the-wild iOS exploit kit discovery and a long overdue conversation about Apple's responsibility to hundreds of millions of users on older iOS versions... securityconversations.com/episode/the-gr…
English
5
11
72
7K
Drew retweetledi
Kostas
Kostas@Kostastsale·
Anna gave me the space to do a full walkthrough of the Threat Hunting Labs platform on her channel. Check it out below 👇 Thank you @RussianPanda9xx ❤️ 🙏
RussianPanda 🐼 🇺🇦@RussianPanda9xx

🚨 NEW VIDEO DROP FROM PANDA 🐼 I got a full walkthrough of @ThruntingLabs from @Kostastsale and this platform is different - no simulations. You are investigating REAL intrusions with REAL telemetry - query actual EDR logs in Elastic, Splunk, or Azure Log Analytics. If you're in blue team / SOC / IR or aspiring to be - I highly recommend checking it out 🔗 youtube.com/watch?v=YC-E5D…

English
1
7
41
4.3K
Drew
Drew@bugfireIO·
@0x747863 @REMnux Good feedback, thanks. Definitely an improved workflow incorporating it.
English
0
0
0
7
txc
txc@0x747863·
@bugfireIO @REMnux Unpacking wasn't successful, but config extraction and Python script creation were very good. I think more experienced analysts/researchers can get more value of AI because they know where and for what to look for, allowing them to create better prompts and evaluate the results
English
1
0
1
47
txc
txc@0x747863·
IcedID Config extraction: Writeup for a challenge part of Zero2Auto malware analysis course. txc.gitbook.io/documentation/… Also tried out the @REMnux MCP server to check out, how AI can support my analysis approaches and learning overall
English
1
5
22
1.7K
Drew
Drew@bugfireIO·
@0x6D6172636F That’s crazy. I’m not a fan of really young kids pushing themselves like that in general.
English
1
0
1
28
смех
смех@0x6D6172636F·
Holy shit I just saw an 11yo finish a 100k
English
2
0
3
331
смех
смех@0x6D6172636F·
Wasn't expecting to see NESHTA today 👀
смех tweet media
English
1
1
5
467
Cyber_Racheal
Cyber_Racheal@CyberRacheal·
Chmod 700. Add yours
Cyber_Racheal tweet media
English
890
44
1.2K
115.6K
Drew
Drew@bugfireIO·
@struppigel Yes, this story got way too much play for what it is. If you still need to get a custom loader installed somehow to extract it then you could have just sent the payload to begin with.
English
0
0
2
96
Drew
Drew@bugfireIO·
@blackorbird Saw that and wondered if there’s a detection mechanism
English
0
0
0
339
blackorbird
blackorbird@blackorbird·
ZIP format confusion technique that evades 98% of antivirus engines. Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload. CVE-2026-0866 github.com/bombadil-syste…
blackorbird tweet media
English
7
74
267
19.1K
Drew
Drew@bugfireIO·
@cyb3rops 100% agree. Can use an LLM in your local repo to enforce as well.
English
0
0
0
75
Drew
Drew@bugfireIO·
@0x6D6172636F Yeah, the participation medal is a more reasonable option in this case
English
0
0
0
25
смех
смех@0x6D6172636F·
@bugfireIO Yeah its completely all good. Sometimes its just crazy hot out. Sometimes you don't feel well. A dnf every once in a while just means you put yourself out there. I understand wanting to collect the medal as well. It may be a big travel event. The 18 mi "finish" is weird lol.
English
1
0
1
98
🤖👾Shmuel Gihon 👾🤖
🤖👾Shmuel Gihon 👾🤖@LikelyMalware·
I just didn’t felt like paying on a 20$ app I need for a project so I JUST ASKED #CLAUDE TO DEVELOP MY OWN. Insane.🤯🤯🤯
English
1
0
1
64
Justin Elze
Justin Elze@HackingLZ·
Now that codex security dropped I assume there are no more security issues in openclaw?
English
8
1
37
5.7K
Drew retweetledi
Jai Minton
Jai Minton@CyberRaiju·
I teamed up with Ryan Dowd to investigate a fake OpenClaw installer hosted on GitHub. This was also picked up by Bing's AI and recommended as the correct way to install OpenClaw on Windows. huntress.com/blog/openclaw-…
Jai Minton tweet mediaJai Minton tweet media
English
2
19
69
10.5K
Drew retweetledi
Josh Stroschein | The Cyber Yeti
🎓 I’ve been a virtual learning advocate for decades—from my YouTube channel to developing online PhD programs. But my philosophy was really shaped by a "far from optimal" in-person training experience early in my career. ❌ No lab guides ❌ Just a printout of the slide deck ❌ Deciphering my own hasty, and incomplete, notes for weeks afterward 🗝️ Simply put, I couldn't use the material after I got home. Training has changed. The days of "gatekeeping" material are over. My approach is simple - I want our time spent together learning to have a long shelf life. That's why much of the material I develop (or help deliver) uses: ✅ Detailed lab guides ✅ Source code ✅ Annotated IDBs The real value isn't the PDF; it’s the discussion and real-time problem-solving we do together. Join me virtually next month at @_ringzer0 for a week of virtual learning! ringzer0.training/countermeasure…
English
1
3
25
2.1K
Drew retweetledi
Karsten Hahn
Karsten Hahn@struppigel·
New blog: Using LLMs the right way for malware analysis 💡Tips for building an autonomous AI analysis lab on a 12 yo laptop and getting stuff done faster without loss of accuracy. blog.gdatasoftware.com/2026/03/38381-…
Karsten Hahn tweet media
English
8
129
439
35.9K
Kyle Cucci
Kyle Cucci@d4rksystem·
This is the primary issue with LLM-based reversing I see at the moment. To someone without much RE experience, these AI generated RE reports look like magic. To someone with more experience, the tiny flaws in the diamond begin to show.
Karsten Hahn@struppigel

Don't be fooled by LLM reversing. Yes, they are a great help, but analysis reports are full of tiny and bigger mistakes, even with 5(!) validation passes. Which means you can't trust them. Which means you have to validate everything.

English
2
2
28
2.4K