Log junkie trying to share what I know through training and posts. Privileged to be a #BlackHatUSA trainer!

Joined June 2019
105 Photos and videos
Lee Archinal retweeted
Happy Skenes Day! REPOST THIS for a chance to win this autographed baseball by Paul Skenes. Presented by @sheetz
143
6,486
3,224
201,906
Lee Archinal retweeted
19 Aug 2025
Super fun working on this lab with the @XintraOrg gang!! Enjoy and let us know your feedback! #ScatteredSpider #MuddledLibra #UNC3944
19 Aug 2025
NEW LAB: Scattered Spider (UNC3944) 🕷️🕸️ Scattered Spider hits indie studio AB Projekt Blue, deploying ransomware and stealing unreleased game code. Test your skills on: 👀 Social Engineering & MFA Fatigue 👀 Credential Theft via OST Files 👀 Bring Your Own Vulnerable Driver (BYOVD) 👀 EDR Manipulation 👀 Custom Ransomware Binary 👀 RMM Exploitation Lab Contributors Adversarial Emulation @q8fawazo Incident Response @r3nzsec Threat Intelligence @CuratedIntel Solve it here 👉 xintra.org @XintraOrg
2
4
39
4,729
Lee Archinal retweeted
REPOST THIS for a chance to win a @NewEraCap Players' Weekend 59FIFTY Cap!
49
1,838
1,087
69,707
Lee Archinal retweeted
How do #malware behaviors inform hunt strategy? Find out July 31 in Intel 471’s live, hands-on workshop. Real telemetry, real IOAs, guided by our #threatintel and #threathunting teams. Sign up: hubs.la/Q03w49-h0 #cybersecurity #CTI
2
4
679
Lee Archinal retweeted
Intel 471: This post will examine one of the top pro-Russian hacktivist groups, new ones that have entered the scene and the impact of these groups. intel471.com/blog/pro-russia… @Intel471Inc

1
24
39
1,585
Lee Archinal retweeted
1 Jul 2025
🚨 New Threat Actor Profile by @intel_anastasia From the shadows of Conti, Black Basta emerged as one of the most prolific ransomware gangs in recent years—until a massive internal leak exposed everything. 🔍 In our latest profile, we trace the group’s Conti lineage, breakdown their TTPs, and analyze the leaked chats that ultimately led to their demise. 💥 578 victims. Triple extortion tactics. Political undertones. Was it just about money, or something more? Swipe through the key takeaways, then dive into the full report. 👉 analyst1.com/threat-actors/b… #ThreatIntel #Cybercrime #BlackBasta #Ransomware #A1ThreatProfiles #CyberSecurity #Analyst1
13
29
2,931
Check out this opportunity to work with an awesome team! #ThreatHunting #ThreatIntel
🔎 We're Hiring: Senior Security Analyst We're looking for a full-time Senior Security Analyst with a passion for dissecting intrusions and translating technical findings into actionable insights. Check out the full job description and apply here 👉 forms.office.com/r/87y8wAp3g…
1
140
Lee Archinal retweeted
25 Jun 2025
CTI teams are under pressure to mature fast. In this #SANS webcast, Intel 471’s Ashley Jess shares insights on integrating #geopolitics and measuring CTI value using frameworks like CTI-CMM & CU-GIRH. Watch the full discussion: hubs.la/Q03tbg-t0 #CTI #cybersecurity
6
26
1,319
Lee Archinal retweeted
🚨Kroger cybersecurity is hiring! Check out the postings here: linkedin.com/posts/activity-… #cyberjobs #hiring

9
33
88
10,718
Lee Archinal retweeted
13 May 2025
Join Intel 471's Level 2 Threat Hunting Workshop on Execution tomorrow, May 14 from 12 - 1 PM EDT. Investigate PowerShell abuse, LOLBins, macro payloads, and more using real-world data. Finish the challenge, earn your #threathunting badge. Register now: hubs.la/Q03m5Z1H0
1
5
629
Lee Archinal retweeted
📉DFIR Labs Weekend Discount📉 Use this discount code to receive 10% off all DFIR Labs cases! Discount expires May 5th 04:00 UTC ⏲️Buy now, use anytime over the next 3 months. ➡️Discount code: WeekendDiscount20250502 Access DFIR Labs: store.thedfirreport.com/coll…
11
35
6,407
Lee Archinal retweeted
“For this case we observed TXT records being utilized for C2 communication rather than MX records. This can be identified by the "type: 16" in the Sysmon logs seen above. Below is a sample list that, while not exhaustive, provides a clear example of the traffic patterns:” 1/2
2
27
131
10,347
Lee Archinal retweeted
#Cybersecurity truly is a collaborative endeavor. We asked Steve Orrin from @intel to share his insights on how the government and commercial sides can work together to stay ahead of #CYBER threats. #informationsecurity
1
1
63
Lee Archinal retweeted
🚨 VanHelsing Ransomware hit 3 victims within weeks of launch. Cross-platform, $500K ransoms, and growing fast. Intel 471 is tracking it, read the full report: hubs.la/Q03fwSjX0 #vanhelsing #ransomware #emergingthreats #threathunting #cybersecurity
3
4
851
Lee Archinal retweeted
13 Mar 2025
LockBit 4.0 enhances its stealth with PowerShell abuse, security feature bypasses, and obfuscated exfiltration. Intel 471 tracks its evolving tactics, read the full report here: hubs.la/Q03bP3sK0 #emergingthreat #lockbit #threathunting #threatintel
6
13
1,428
Lee Archinal retweeted
12 Mar 2025
Threat hunting is about focus. Knowing where to spend your time is what sets tactical hunters apart. Join Out of the Woods live tomorrow for an interactive discussion on what drives real results. Our hosts will be engaging in real time on Discord. 🔗 hubs.la/Q03bpV4F0
2
3
636