PinnedMichael Koczwara·Mar 31, 2022LAPSUS$ TTPsLAPSUSS TTPs & MITRE ATT&CK MappingA response icon1A response icon1
PinnedMichael Koczwara·Sep 1, 2021Cobalt Strike PowerShell Payload AnalysisI have spotted this interesting tweet from Malwar3Ninja and decided to take a look and analyse the Cobalt Strike PowerShell payload.A response icon1A response icon1
PinnedMichael Koczwara·Aug 17, 2021Cobalt Strike Hunting — DLL Hijacking/Attack AnalysisDLL Hijacking via Cobalt Strike
PinnedMichael Koczwara·Aug 5, 2021Cobalt Strike Hunting — Malleable C2 jQuery profile & rundll32 AnalysisMalleable C2 — jQuery profiles.
PinnedMichael Koczwara·Jul 21, 2021Cobalt Strike Hunting — simple PCAP and Beacon AnalysisLegit healthcare company.
InDetect FYIbyMichael Koczwara·Dec 5, 2023Hunting Malicious Infrastructure-Headers and Hardcoded/Static StringsIn my last blog Hunting Malicious Infrastructure using JARM and HTTP ResponseA response icon1A response icon1
Michael Koczwara·Nov 5, 2023Threat Intel-Pivoting using CensysHunting malicious infrastructure: Muddy Water Cyberespionage Threat Actor from Iran 🇮🇷
Michael Koczwara·May 23, 2023APT 29 Initial Access Killchain -MITRE ATT@CK MappingAPT29/Nobelium Initial Access & ATT@CK MappingA response icon1A response icon1
InDetect FYIbyMichael Koczwara·May 16, 2023Hunting Malicious Infrastructure using JARM and HTTP ResponseHunting QBot C2 and Brute Ratel C4 InfrastructureA response icon2A response icon2