Tracking APT SideWinder Domains With Regular Expressions, Whois Records and Domain Registrars
Leveraging Passive DNS to identify APT infrastructure. Building on public intelligence reports.
Advanced CyberChef techniques using Registers, Regex and Flow Control
Leveraging Ghidra to establish context and intent behind suspicious strings.
Manually Reversing a decryption function using Ghidra, ChatGPT and CyberChef.
More interesting and practical queries for identifying malware infrastructure.
Identifying Malware infrastructure by combining weak pivot points.
Extracting C2 configuration using the Garbageman .NET analysis tool
Identifying Simple pivot points in RisePro Stealer Infrastructure using Censys.