Aaron Jornet

792 posts

Aaron Jornet banner
Aaron Jornet

Aaron Jornet

@RexorVc0

Threat Researcher at @socradar | Malware Researcher | Threat Hunter | CTI ¦ Former @ElevenPaths @Panda_Security

เข้าร่วม Aralık 2020
400 กำลังติดตาม4.5K ผู้ติดตาม
luu
luu@AUZombie·
@RexorVc0 Nice!! Any chance I could purchase a PDF version? Going to cost a mint to have it shipped to where I live lol
English
1
0
1
42
Aaron Jornet
Aaron Jornet@RexorVc0·
🚨 Big news: New TH Book 🏹 After years in Threat Hunting, I wrote the book I always wanted when I started. The Art of Threat Hunting, practical, technical, no fluff. ⚡Hypothesis generation, queries & adaptation stuff, CTI-driven programs, documentation, team alignment. The full lifecycle. 🦖Full breakdown on the blog: rexorvc0.com 🔗Available on Amazon: amazon.com/Art-Threat-Hun… #ThreatHunting #BlueTeam #Cybersecurity #Research #CTI #Malware #threat
Aaron Jornet tweet media
English
11
69
318
16.7K
Aaron Jornet
Aaron Jornet@RexorVc0·
@FAMASoon Thanks mate!!, yep, it’ll be available on Kindle in the future 🙇
English
1
0
1
66
FAMASoon
FAMASoon@FAMASoon·
@RexorVc0 Great work! I have one question. Do you plan to publish on Kindle? I live in Japan. I’m trying to decide whether to import it or buy it on Kindle.
English
1
0
1
100
i4
i4@0x401229933·
@RexorVc0 Congrats! I'll grab a copy🔥
English
1
0
0
214
Aaron Jornet
Aaron Jornet@RexorVc0·
@fr0gger_ Thanks a lot, mate!!! I really appreciate it 🙇🙇
English
0
0
2
496
Greenplan
Greenplan@greenplan_it·
@RexorVc0 Such great news!! already added to my cart :D
English
1
0
1
261
xiu
xiu@osint_barbie·
pupupu! let me tell you who actually did this and thank all of them!!! @moonlock_lab & @moonlock_com for being the dream team! I would not be here without you guys! @MacPaw for being the rare workplace that actually inspires to do better work! @patrickwardle my macOS journey started with your book. everything after that is your fault a little bit 😜 @g0njxa & @birchb0y for being here when macOS stealers were a niche obsession and helping prove it was never just about AMOS and this entire community: researchers, friends, people I've met in conference hallways and in my DMs at 2am.. the last few years have been the best journey I could've imagined! thank you, MY PEOPLE! this one's ours🖤💜🩷
Moonlock by MacPaw@moonlock_com

Kseniia Yamburh @osint_barbie has been named “Cybersecurity Woman of the Year” at the 2026 Cybersecurity Excellence Awards! As a Malware Research Engineer at Moonlock by MacPaw, Kseniia spends her days hunting down macOS threats and sharing her intelligence with the broader community. Seeing her daily dedication recognized on a global stage is a big moment for all of us. Here is what @HolgerSchulze, founder of Cybersecurity Insiders, had to say about the win: “We congratulate Kseniia Yamburh for outstanding achievements in the ‘Cybersecurity Woman of the Year’ category of the 2026 Cybersecurity Excellence Awards. Selected by an independent jury of cybersecurity practitioners, analysts, and CISOs, this recognition highlights meaningful contributions that strengthen cybersecurity across organizations worldwide.” We couldn't agree more. Huge congrats, Kseniia — thank you for everything you do to keep Mac users safe.

English
7
2
48
5K
Aaron Jornet
Aaron Jornet@RexorVc0·
#IOC b57299c00a0991036a96ab4bf5928134 deac8223ed9fc5e0a9adbc01abbe30cb 620221e4c78e8df6f0ce4d489c15dffb 8295b1fac6535f4444a9d477c4225942 96a9321deca6717db13bd5db8d3abba5 ... 🔗VT: virustotal.com/gui/collection…
Aaron Jornet tweet media
HT
0
2
6
846
Aaron Jornet
Aaron Jornet@RexorVc0·
#TTP 📩[T1566] Social Engineering + Telegram distribution 💿[T1204.002] ISO mount 🧩[T1027.013] PowerShell B64 commands 📥[T1105] Download & deploy modules 🔐[T1553.004] Forged root cert import (DemiMurCA.crt) 🛡️[T1562.001] Defender exclusions ⚓️[T1053.005] Persistence in Tasks 👤[T1136.001] Backdoor accounts (Admin, WGUtilityOperator) 🖥️[T1021.001] RDP takeover + Shadow monitoring 🔀[T1572] SSH reverse tunnel (RDP:30054, SSH:20054) 🕷️[T1082] Collect UUID, MachineGuid, hostname, public IP 🗑️[T1070.004] Self delete binaries 🧅[T1090.003] Tor C2 📡[T1071.001] C2
Aaron Jornet tweet mediaAaron Jornet tweet mediaAaron Jornet tweet mediaAaron Jornet tweet media
English
1
2
15
1.2K
Aaron Jornet
Aaron Jornet@RexorVc0·
#TTP 📩[T1566.001] Spear-Phishing 👥[T1036] Fake PDF & double extension 🗂️[T1204.002] LNK 📥[T1105] Download next stage ⚓️[T1053] Persistence over Tasks 🛠️[T1218] Abuse of legit MSBuild & py 🔃 [T1574.001] Dll side load 🧩[T1027.013] Code obfuscated 🕷️[T1082] Get device & user info 📡[T1071] C&C communication 🕵️[T1059] Execute commands from backdoor
Aaron Jornet tweet mediaAaron Jornet tweet mediaAaron Jornet tweet mediaAaron Jornet tweet media
English
1
2
12
1.1K
Aaron Jornet
Aaron Jornet@RexorVc0·
🔍 Operation DoppelBrand🎭 The Threat Research team has covered a massive campaign by GS7, a previously unknown #TA targeting Fortune 500 companies for years. ⛓️ Chain: Creates fake (US/Canada/EU companies) portal > Target #Phishing > Steals credentials via Telegram > Deploys RMM tools for persistent access Full analysis covers: 👁️Initial Discovery 💀Modus operandi & infrastructure 👤Attribution & victimology ⚡️Complete IOC breakdown ➕And more 🔗 Report: socradar.io/resources/whit… 👽 BlogPost: socradar.io/blog/operation… #ThreatIntel #InfoSec #CTI #ThreatResearch #MalwareAnalysis #CyberCrime #malware
Aaron Jornet tweet mediaAaron Jornet tweet mediaAaron Jornet tweet mediaAaron Jornet tweet media
English
5
8
36
4.4K
DebugPrivilege
DebugPrivilege@DebugPrivilege·
Anyone who currently lives in Spain? DM me. I have some questions.
English
4
2
9
4.1K
0x6rss
0x6rss@0x6rss·
meet track2pulse.com track2pulse enables you to monitor, via an interactive map, OSINT-driven intelligence streams aggregated from country-specific telegram channels, covering topics such as geopolitics, information warfare, domestic developments, and strategic shifts. you can track: -APT group activities targeting specific countries -Terror-related fatality data and organizational intelligence -Critical infrastructure across relevant geographic regions -The Interpol wanted persons list -War-related flights and aircraft movements (flight tracking) -International arms trade flows between countries -National intelligence insights and satellite imagery-based data -cybersecurity incidents, including ransomware campaigns and threat reports You can create a personalized profile and follow only the developments that align with your operational interests , all in real time, directly on the map interface.
English
2
93
682
55.4K