Joined May 2019
232 Photos and videos
APK-47 retweeted
🚀 OhMyPCAP 3.0 is here! The ultimate FOSS web app for PCAP analysis just leveled up big time. New in v3.0: • Suricata automatically extracts files from traffic • Runs YARA on every extracted file - new FILE ALERTS tab • Drag & drop any file for instant YARA scanning Runs in a single Docker/Podman container - perfect for quick testing or air-gapped environments. All your favorite features are still there: rich alerts, Sankey diagrams, transcripts, stream carving, and more! Perfect for malware analysis, incident response, threat hunting and teaching network forensics. Who’s spinning this up? Drop a ❤️ and reply with your main use case (malware? CTFs? real incidents?) cc @lennyzeltser @it_audit @Suricata_IDS @chrissanders88 @sansforensics
3
21
67
7,038
APK-47 retweeted
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100 countries. If you use DAEMON Tools, run a malware scan immediately! [1/7]
23
345
1,082
180,529
APK-47 retweeted
Better understand agentic AI systems and mitigate the cybersecurity risks using a new guide we authored with @ASDGovAu and others. View the joint report. #Cybersecurity #AgenticAI media.defense.gov/2026/Apr/3…

68
232
745
89,956
APK-47 retweeted
Wow! This post blew up! Thanks for all the interest in OhMyPCAP!
Introducing a new PCAP tool - OhMyPCAP OhMyPCAP is a standalone web application for analyzing PCAP files. View security alerts, browse network metadata (DNS, HTTP, TLS, flows), extract ASCII transcripts, and carve individual streams - all from a single-page UI.
6
39
11,643
APK-47 retweeted
Warning: The current HWmonitor download and possibly other PC monitoring applications, may be infected with viruses. More info: reddit.com/r/pcmasterrace/co…
52
272
1,545
236,062
APK-47 retweeted
Apr 8
ok i read the cyber part of the mythos model card. some thoughts. 250 "trials" across 50 crash categories but almost every full exploit is a permutation of the same 2 bugs, rediscovered from different starting points not 250 independent attempts. when you get rid of those 2 bugs out (fig B) and mythos's full-exploit rate drops to 4.4%. so actually across both setups mythos leverages 4 distinct bugs total not 50 as fig A might suggest. 1/n
29
130
1,446
348,615
APK-47 retweeted
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at github.com/mandiant/flare-le…. Launched with: - Malware Analysis Crash Course - Go Reversing Reference - Intro to TTD
6
401
1,257
65,262
APK-47 retweeted
⚠️ Our team at Google is releasing more details on the recent NPM #axios supply chain attack. Notably, we now attribute this activity to #UNC1069, a financially motivated North Korean 🇰🇵 nexus threat actor active since at least 2018.
35
192
1,392
187,908
APK-47 retweeted
This is going to be a big one.
The City of Los Angeles was breached The Los Angeles Metro Transit System has also been breached and is now in shutdown mode 2 Bay Area cities in California are also currently in a states of emergency after separate ransomware attacks 1 hospital breached
6
8
47
12,079
APK-47 retweeted
New blog post: Building a Pipeline for Agentic Malware Analysis Agentic RE malware analysis with custom skills, MCP tooling, and persistent case state to automate intial triage Link: synthesis.to/2026/03/18/agen… Github: github.com/mrphrazer/agentic…
8
159
518
60,236
APK-47 retweeted
🧵 I just reverse-engineered the binaries inside Claude Code's Firecracker MicroVM and found something wild: Anthropic is building their own PaaS platform called "Antspace" (Ants Space). It's a full deployment pipeline — hidden in plain sight inside the environment-runner binary. Here's what I found 👇
67
192
1,583
234,077
APK-47 retweeted
Anthropic just announced Claude Certified Architect exam. Aren't you glad I started my Claude certification course last week? I just knew it my bones, that I had to make one, and now I can just align mine to this.
39
190
2,248
313,548
APK-47 retweeted
Iran-linked Handala Hack (aka Void Manticore, COBALT MYSTIQUE) is a reported vector for an increase in wiper attacks. This Insights blog details proactive recommendations for security teams, from identity management to enhancing security controls. bit.ly/4rrBVlu
1
41
148
21,914
Has anyone seen any work with APK analysis using AI? Seen a lot of focus on PEs and other binaries - did I miss something someone is working on? If not, I might have to dive into this space whole heartedly #infosec #android
1
81
APK-47 retweeted
Today I’m launching Threat Hunting Labs. Over the years I’ve analyzed many real-world intrusions. One thing became obvious: most training platforms don’t resemble how investigations actually happen. So I built something different. Threat Hunting Labs focuses on investigation-driven learning using real telemetry and structured investigative paths. If you want to get better at investigating breaches, you should practice investigating breaches. More details here: threathuntinglabs.com/blog/i…
21
116
583
47,121
APK-47 retweeted
Introducing the new /crawl endpoint - one API call and an entire site crawled. No scripts. No browser management. Just the content in HTML, Markdown, or JSON.
763
1,664
19,723
10,626,835
Why do we need tools like ATT&CK explorer and stuff anymore? I mean honestly #infosec
77
Replying to @HackingLZ
@HackingLZ the next time you're doing an engagement, definitely don't grab these files: C:\Users\Username\AppData\Local\Claude\Logs\*, C:\ProgramData\Claude\Logs\*, C:\Users\Username\AppData\Roaming\Claude\logs\* #ai #infosec
1
2
70
and definitely don't impersonate these named pipes: "cowork-vm-service", "cowork-daemon-console" OR these bins: chrome-native-host.exe, cowork-svc.exe OR this user id: "cowork-vm" -- that would be just awful
33
APK-47 retweeted
🧵 We recently had an incident that involved a MuddyWater hands-on attacker who couldn't spell "administrators" Full timeline breakdown below. 1/
13
73
359
55,837
APK-47 retweeted
we hijacked perplexity comet by sending a weaponized calendar invite then used it to takeover victim's 1p account and exfil their local files call it pleasefix. like clickfix, but instead of social eng'ing a human you just ask their ai real nicely incredible work by @StAJect0r
16
59
290
47,356