grep_security

head of security research • threat research • threat Intelligence • threat hunting • supply-chain security & random stuff

grep_security boosted:
2023-05-04

We're excited to welcome @loginsoft to the Tidal Product Registry! You can now explore their System-41 analytics to detect potential cyber threats in the Tidal Community Edition, and add them to your matrix to check coverage against specific threat actors or groups. Be sure to check them out!

hubs.la/Q01NkXgn0

#tidalproductregistry #threatinformeddefense #threatintel #cybersecurity

2023-04-26

@HcInfosec Mural seems a commercial product but freemium version serves my purpose. Cool thing is that, they offer tagging and searching features

2023-04-26

Hey all, here I created a quick map of resources if you're interested in hunting/tracking
threat actors or malware. You can learn different techniques employed by researchers in our community.

I am not keeping this list to just infostealers, will keep updating with more.

app.mural.co/invitation/mural/

I am using Mural for mindmap which has cool features like search & tagging..

#threatintel #infosec #cybersecurity #malware #threathunting

preview of mindmap tracking adversaries
2023-01-17

This is beyond the Threat Attribution..! Great Post

analyst1.com/ransomware-diarie

#infosec #threatintel

2023-01-08

@rmceoin This is interesting, took some time to investigate. I feel this is an Ad campaign, not a malware campaign. These domains behaves differently on each time you browse. I have observed these redirecting to mcafee, Opera GX products and some lame hentai-porn. On the last run, it redirected to chrome extension market place to download an extension which I could not find it on google neither on CRXcavator. Thought to analyze the extension for crown jewels

here's the analysis, take a look at recording.
tria.ge/230108-nyx8xade24/beha

I think it redirects to google.com if there's no referrer header

urlscan.io/result/b99cf01d-a7e

here's crxcavator giving 404. This is important because they scan the marketplace very frequently and maintain historical data. So logically, I should find this extension if it exists.

crxcavator.io/report/ifidkgmkp

anyone else from #infosec can shed some light :flan_shrug:​

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst