Advertisement Β· 728 Γ— 90

Posts by mthcht

Preview
GitHub - Nehboro/nehboro: Browser extension blocking scam and phishing pages Browser extension blocking scam and phishing pages - Nehboro/nehboro

github.com/Nehboro/nehb...

2 days ago 0 0 0 0
Nehboro - Community Threat Intelligence Community-powered browser extension with 97 dynamic detections, static IOC feeds, and optional Claude AI analysis. Protection against phishing, ClickFix, and malware.

Nehboro, a browser extension blocking phishing attempts on page load

nehboro.github.io

⚑️ Dedicated IOCs feed - Blocking BAD AS IP ranges, domains & reported urls
πŸ“Š 97 heuristic detections for all kind of scams
πŸ€– AI Analysis on demand

hopefully in the webstore soon

2 days ago 0 0 1 0
Preview
ExtSentry Guard - Chrome Web Store Detects and warns about known malicious browser extensions using the ExtSentry IOC feed.

Automatically block and disable malicious browser extensions with a browser extension!
Perfect for family devices or anyone who just wants simple protection, no GPOs or enterprise setup... now on the Chrome Web Store:
chromewebstore.google.com/detail/extse...

1 week ago 0 1 0 0
Post image

πŸ’  VSXSentry πŸ’ 
vsxsentry.github.io

VS Code Extensions threat intel feeds for multiple platforms, VSIX analyzer, scripts & policy generator, remediation and forensic traces guide

2 weeks ago 0 0 0 0
Post image Post image Post image

πŸ§… TOR archive feed:
tor-archive.github.io

Every IP that has ever been a TOR node!
Searchable with full timeline, exit/guard/middle role, country, ASN, updated hourly since 2024.

3 weeks ago 19 3 2 0
Preview
GitHub - ExtSentry/ExtSentry.github.io: Browser Extension Threat Intelligence feed - extsentry.github.io Browser Extension Threat Intelligence feed - extsentry.github.io - ExtSentry/ExtSentry.github.io

🧩 ExtSentry 🧩
extsentry.github.io

Browser Extensions threat intel feeds for multiple platforms + extension checker, permissions analyzer, policy generator, forensic traces guide, remediation playbook & endpoint inventory scripts

github.com/ExtSentry/Ex...

3 weeks ago 0 0 0 0

LOLC2

Collection of C2 frameworks abusing legitimate services to evade detection

Major update: new projects tested, enriched data, and deeper insights.

lolc2.github.io

1 month ago 2 0 0 0
LOLFSaaS - Living off Free SaaS

LOLFSAAS

Living off Free SaaS

Hundreds of SaaS platformsΒ with free tiers, documenting abuse surface, opsec risks, authent methods, C2 framework mappings, and operational limits.

lolfsaas.github.io

1 month ago 2 2 0 0
LOLEXFIL β€” LOL Exfiltration Reference

LOLEXFIL
Living off the land Data Exfiltration method

lolexfil.github.io

1 month ago 1 1 0 0
Advertisement
Preview
awesome-lists/Lists at main Β· mthcht/awesome-lists Awesome Security lists for SOC/CERT/CTI. Contribute to mthcht/awesome-lists development by creating an account on GitHub.

Hello @yousefnein.bsky.social glad to hear the repos are being useful. If you’d like to contribute or enhance any of the lists in github.com/mthcht/aweso..., contributions are very welcome. I don’t have much time to keep them updated quickly

1 month ago 0 0 0 0
Preview
GitHub - mthcht/Splunk-MCP-Client: Query Splunk in natural language using Claude AI and the Splunk MCP Server. Query Splunk in natural language using Claude AI and the Splunk MCP Server. - mthcht/Splunk-MCP-Client

If you want to experiment with the Splunk MCP Server splunkbase.splunk.com/app/7931, I just published a client to interact with it:
github.com/mthcht/Splun...

it cost around 5 cents per splunk query, an automated case investigation cost an average of 50 cents depending on the complexity.

1 month ago 0 0 0 0
Preview
Lumma Stealer sinkholed domains Lumma Stealer sinkholed domains. GitHub Gist: instantly share code, notes, and snippets.

Lumma Stealer - 995 sinkholed domains by Microsoft
gist.github.com/mthcht/4b16e...

10 months ago 2 0 0 0
Post image

it used to be great...

1 year ago 5 0 1 0

@hexacorn.bsky.social :o someone just sent me your list hexacorn.com/examples/201... this is great thanks!

1 year ago 3 0 1 0

I started another list dedicated to mutex names for detection
github.com/mthcht/aweso...

Help me enhance this list, I still have plenty more to add!

1 year ago 2 0 1 0

Thanks! Glad you like them!

1 year ago 2 0 0 0
Advertisement

THIS WEBSITE HAS BEEN SEIZED

Discover domains tied to sinkhole NS servers at sinkholed.github.io

Filter by TLD or NS, export in JSON/CSV, weekly update!

Search for the known sinkhole Name Servers in DNS query logs and web access to the sinkholed domains to identify potentially compromised hosts!

1 year ago 11 5 1 0

😯 I have 652022 sinkholed domains extracted here github.com/mthcht/aweso...

1 year ago 1 1 0 0
Post image

🎭 #ThreatHunting February updates 🎭
πŸ™ release: github.com/mthcht/Threa...
🌐 Site: mthcht.github.io/ThreatHuntin...
🧬 yara: github.com/mthcht/Threa...
🐾 Specific artifact lists: github.com/mthcht/aweso...

1 year ago 5 2 0 0

Of course! PRs are welcome πŸ™

1 year ago 0 0 1 0
Powershell: after 5 "type .\5\test.txt" calls, the test.txt file is a symlink to win.ini
CMD: A single "type .\6\test.txt" call results in every single file being printed, including the final win.ini symlink

Powershell: after 5 "type .\5\test.txt" calls, the test.txt file is a symlink to win.ini CMD: A single "type .\6\test.txt" call results in every single file being printed, including the final win.ini symlink

From over at the Bad Place:
There's an interesting NTFS symlink attack outlined here:
dfir.ru/2025/02/23/symlink-attac...

Basically, if an NTFS filesystem is corrupted in a way to provide duplicate file names, Windows will […]

[Original post on infosec.exchange]

1 year ago 16 13 1 0
Preview
Confluence Exploit Leads to LockBit Ransomware Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.…

It took just 3 hours:

RCE β†’ Metasploit C2 β†’ Anydesk for remote GUI-access β†’ LockBit ransomware

Interestingly, we observed the threat actor using PDQ Deploy, a patch management tool.

Read the report here:

1 year ago 9 3 1 0

A bookmark of my lists is now automatically generated after each update in my repo github.com/mthcht/aweso...
I'm also looking to automatically add my starred repos lists github.com/mthcht?tab=s... in this bookmark but there doesn’t seem to be a API endpoint for the stars lists πŸ€” ?

1 year ago 7 0 0 0

It's growing! Now at 38 services and 82 projects πŸ™ˆ What's your favorite LoLC2?

1 year ago 2 0 1 0
Post image Post image

Pushed a #KQL for: Successful device code sign-in from an unmanaged device.

Query is available for AADSignInEventsBeta and SigninLogs. Less known is the AADSignInEventsBeta filter for device code:
| where EndpointCall == "Cmsi:Cmsi"

🏹Query: github.com/Bert-JanP/Hu...

1 year ago 5 3 2 0
Advertisement

In case you don't want to do this yourself, I just discovered that you can request access to a complete list of all existing domains across 1131 TLDs on czds.icann.org for free, including NS records! The lists are updated every month, approval is required for each TLD 🌍

1 year ago 3 1 0 1
Preview
Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time | Splunk Explore SDDL in Windows security with our comprehensive guide to help enhance your defensive strategy against privilege escalation attacks.

Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time www.splunk.com/en_us/blog/s....

Thrilled to share my first blog at @splunk! @mhaggis.bsky.social and I take a deep dive into the weird & exciting world of SDDL and ACEs - what they are, how they work, and how attackers can abuse them.

1 year ago 12 5 0 0
Post image Post image

Path masquerading zerosalarium.com/2025/01/path...

Interesting technique, if you're hunting for this, you can directly search the unicode characters in Splunk πŸ₯·

1 year ago 2 0 0 0
Post image Post image

Most SOCs handle hundreds to thousands of detection rules in their SIEM. Proper categorization is essential when creating a new detection, as it helps define criticality, urgency, implementation effort, and verbosity level. Keeping things structured will reducing alert fatigue!

1 year ago 5 1 0 0

I'll keep this updated, let me know if you have any projects to add! some C2 candidates: github.com/lolc2/lolc2....

1 year ago 3 1 0 0