Advertisement ยท 728 ร— 90

Posts by Kostas

Post image Post image

This is one of the funniest things Iโ€™ve seen this year ๐Ÿ˜‚ ๐Ÿ˜‚

vibecoded.vc/cooked/

2 weeks ago 2 0 0 0
Preview
macOS EDR Telemetry: A Structured Framework for Evaluating Endpoint Visibility. EDR Telemetry Project - Exploring telemetry capabilities of EDR solutions

๐Ÿ“ข๐Ÿ macOS is now part of the EDR Telemetry Project. After three months of focused work, weโ€™re excited to share a new framework and generator for endpoint visibility on macOS!

Huge thank you to everyone who contributed and helped shape this release. Looking forward to what comes next.

3 weeks ago 2 0 0 0
Post image

Itโ€™s been quiet on the EDR Telemetry side lately while working on something big!

EDR telemetry's goal was always to set the standard for telemetry visibility, and this is what we're planning to do with tomorrow's release...

Keep an eye out for tomorrow's announcement!

3 weeks ago 1 0 0 0
Video

Sometimes the call comes a little too late and you gotta do what you gotta do ๐Ÿ˜‚

1 month ago 3 0 0 0
Preview
Bots: An introduction for developers Bots are small applications that run entirely within the Telegram app. Users interact with bots through flexible interfacesโ€ฆ

๐—›๐˜‚๐—ป๐˜ ๐—ณ๐—ผ๐—ฟ ๐˜๐—ต๐—ถ๐˜€ ๐—ฏ๐˜† ๐—น๐—ผ๐—ผ๐—ธ๐—ถ๐—ป๐—ด ๐—ฎ๐˜:

โ€ข Chrome/Edge running on servers where they shouldn't be
โ€ข Browser profile directory access by non-browser processes
โ€ข Outbound HTTPS to api.telegram.org from unexpected executables
โ€ข Startup persistence under AppData or ProgramData without operational justification

2 months ago 3 0 0 0
Preview
TelePeek - Telegram Bot Investigation Professional tool to securely track and analyze bot interactions

I'm using TelePeek.com to monitor the receiving interface (screenshot shows operator's dashboard). The victim profile is concerning with government employees and enterprise users in high-level organizations...

2 months ago 0 0 1 0
Preview
TelePeek - Telegram Bot Investigation Professional tool to securely track and analyze bot interactions

Exfiltration via Telegram bot API where PhantomStealer packages victim data as JSON and POSTs directly:

โ€ข Browser credentials, cookies, saved passwords
โ€ข System metadata (OS, username, antivirus status)
โ€ข Network reconnaissance (gateway/internal/external IPs)

2 months ago 1 0 1 0
Post image

Phantom Stealer has been prominent across phishing campaigns over the past two weeks. Operationally interesting to me is that itโ€™s not just an infostealer. It also acts as an initial access broker, dropping GuLoader for follow-on activity, and Iโ€™ve seen it deploy crypto miners as well.

2 months ago 5 2 1 0
Preview
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw ### Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...

Worth reading if you're running AI in CI/CD.

github.com/cline/cline/...

2 months ago 0 0 0 0
Advertisement
Preview
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw ### Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...

Clinejection PoC: researcher proved you can compromise a VS Code extension (700k+ weekly users) via prompt injection in GitHub issues.

He was kind enough to install harmless software as a POC. Real attackers won't...

Vendor ignored him for 47 days, fixed it in 30 min after he went public.

2 months ago 1 1 1 0
Preview
HCSEC-2026-01 - Arbitrary code execution in React server-side rendering of untrusted MDX content Bulletin ID: HCSEC-2026-01 Affected Products / Versions: next-mdx-remote from 4.3.0 up to 5.0.0, fixed in 6.0.0. Publication Date: February 11, 2026 Summary The serialize function used to compileโ€ฆ

Upgrade to 6.0.0 especially if other people can write MDX that your server then compiles and renders for them.

CVE with 8.8 score
- discuss.hashicorp.com/t/hcsec-2026...

2 months ago 0 0 0 0
Preview
HCSEC-2026-01 - Arbitrary code execution in React server-side rendering of untrusted MDX content Bulletin ID: HCSEC-2026-01 Affected Products / Versions: next-mdx-remote from 4.3.0 up to 5.0.0, fixed in 6.0.0. Publication Date: February 11, 2026 Summary The serialize function used to compileโ€ฆ

MDX content is awesome, I love it, and I use it whenever I can on my projects. But be careful cause if youโ€™re usingย next-mdx-remoteย (4.3.0โ€“5.x) to serverโ€‘side render untrusted MDX, youโ€™re potentially exposing yourself to RCE via CVEโ€‘2026โ€‘0969...

2 months ago 1 0 1 0
Preview
Why Your EDR Needs a Partner: The Case for Application Control How threat intelligence-aware application control fills the gaps that EDR leaves open

...the missing layer.

Full write-up: www.edr-telemetry.com/blog/Why-You...

3 months ago 0 0 0 0
Preview
Why Your EDR Needs a Partner: The Case for Application Control How threat intelligence-aware application control fills the gaps that EDR leaves open

At EDR Telemetry project, we spend a lot of time measuring what EDRs can see. This article is about what they still cannot safely stop.

From LOLBAS to vulnerable drivers to unauthorized RMMs, I walk through the real-world gaps we keep seeing in telemetry and why application control is...

3 months ago 0 1 1 0

In the screenshot below, you can see an example of this Skill in use (I'm using GPT 5.2-low in Codex)

Link to the skill: github.com/tsale/awesom...

3 months ago 2 0 0 0

We have added a new analysis Skill thanks to @BlueTeamSteve! This skill can be used to quickly and accurately map the MITRE ATT&CK tactic and technique to threat behaviors and indicators you enter in the prompt, saving you a ton of time!

3 months ago 0 0 1 0
Preview
EDR Comparison - Compare Endpoint Detection & Response Solutions Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

Weโ€™ve also expanded ๐—˜๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ options for organizations that need additional flexibility, scale, and support on top of the Advanced tier.

Check out the new tiers now: www.edr-comparison.com/pricing

3 months ago 0 0 0 0
Preview
EDR Comparison - Compare Endpoint Detection & Response Solutions Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

๐—ช๐—ฎ๐˜๐—ฐ๐—ต๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—˜๐——๐—ฅ. Weโ€™ve also introduced ๐—•๐—ฎ๐˜€๐—ถ๐—ฐ ๐—ฎ๐—ป๐—ฑ ๐—”๐—ฑ๐˜ƒ๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐˜๐—ถ๐—ฒ๐—ฟ๐˜€ to better reflect how different users engage with the platform. With the ๐—”๐—ฑ๐˜ƒ๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐˜๐—ถ๐—ฒ๐—ฟ, weโ€™re introducing a deep dive into the technical justification and expert analysis behind every single feature in our comparison.

3 months ago 0 0 1 0
Advertisement

Since launching in November, the platform has already helped hundreds of consultants and enterprises navigate the complexity of EDR selection.

This release pushes things forward with a cleaner comparison UX, deeper evaluation context using MITRE ATT&CK evaluation data, and a new vendor added:

3 months ago 0 0 1 0
Preview
EDR Comparison - Compare Endpoint Detection & Response Solutions Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

๐—˜๐——๐—ฅ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—ฃ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ: ๐—ก๐—ฒ๐˜„ ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—˜๐˜…๐—ฝ๐—ฒ๐—ฟ๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ, ๐— ๐—œ๐—ง๐—ฅ๐—˜ ๐—”๐—ง๐—ง&๐—–๐—ž ๐—œ๐—ป๐˜€๐—ถ๐—ด๐—ต๐˜๐˜€, ๐—ฎ๐—ป๐—ฑ ๐—ช๐—ฎ๐˜๐—ฐ๐—ต๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—˜๐——๐—ฅ

We want to start by thanking everyone who supported us as early adopters.

3 months ago 0 0 1 0
GitHub - tsale/awesome-dfir-skills: A curated collection of DFIR skills and workflows for InfoSec practitioners. A curated collection of DFIR skills and workflows for InfoSec practitioners. - tsale/awesome-dfir-skills

Feel free to contribute and use these skills to save a ton of time, like we already do.

github.com/tsale/awesom...

Learn about skills:
- developers.openai.com/codex/skills/
- support.claude.com/en/articles/...

3 months ago 3 0 0 0
GitHub - tsale/awesome-dfir-skills: A curated collection of DFIR skills and workflows for InfoSec practitioners. A curated collection of DFIR skills and workflows for InfoSec practitioners. - tsale/awesome-dfir-skills

๐—๐˜‚๐˜€๐˜ ๐—น๐—ฎ๐˜‚๐—ป๐—ฐ๐—ต๐—ฒ๐—ฑ ๐—ฎ๐˜„๐—ฒ๐˜€๐—ผ๐—บ๐—ฒ-๐—ฑ๐—ณ๐—ถ๐—ฟ-๐˜€๐—ธ๐—ถ๐—น๐—น๐˜€ ๐˜„๐—ถ๐˜๐—ต @fr0gger_ !

Designed to save time during investigations and everyday DFIR tasks

Thomas has built an excellent malware triage skill, and Iโ€™ve added a couple of timeline analysis skills to help you get started.

3 months ago 2 1 1 0

github.com/tsale/EDR-Te...

This is exactly the kind of vendor collaboration the project aims to promote.
PR with full details and artifacts:

github.com/tsale/EDR-Te...

Big thanks to the C-Prot team for setting a strong example for Linux EDR transparency.

3 months ago 0 0 0 0

environment, validated event mappings, and publishedย the raw logs from the evaluation so the community can independently verify everything.

Artifacts included:

โ€ข Real production telemetry logs
โ€ข Some screenshots from the platform

Validation material to reproduce the results can be found under

3 months ago 0 0 1 0
Preview
Add C-Prot telemetry coverage to Linux EDR telemetry matrix by tsale ยท Pull Request #151 ยท tsale/EDR-Telemetry EDR Telemetry Pull Request Contribution Details Adding comprehensive Linux telemetry support for C-Prot EDR, including detailed event mappings, field explanations, and validation artifacts. This co...

Weโ€™ve just added ๐—–-๐—ฃ๐—ฟ๐—ผ๐˜ EDR to the EDR Telemetry Project and it sets a new bar for Linux telemetry!

C-Prot is currently #1 in the Linux EDR table, with exceptional depth and quality of raw telemetry. What really stands out is the level of transparency: we got direct access to a production...

3 months ago 2 0 1 0
Preview
What are Skills? | Claude Help Center Skills are available as a feature preview for users on Pro, Max, Team, and Enterprise plans. This feature preview requires code execution to be enabled. Skills are also available in beta for Claudeโ€ฆ

Be careful what you install and avoid using skills from unknown or unverified libraries.

Read more about skills here:
- support.claude.com/en/articles/...
- developers.openai.com/codex/skills/

3 months ago 0 0 0 0
Advertisement
Preview
What are Skills? | Claude Help Center Skills are available as a feature preview for users on Pro, Max, Team, and Enterprise plans. This feature preview requires code execution to be enabled. Skills are also available in beta for Claudeโ€ฆ

One quick caveat tho, as skills libraries become more popular, where you will be able to search and find the right skill you want to install, weโ€™re likely going to see malicious skills pop up that download and execute malware...

3 months ago 0 0 1 0
Preview
Agent Skills Give Codex new capabilities and expertise

Claude set a strong bar for structured, workflow-driven AI usage, and itโ€™s no surprise weโ€™re now seeing similar ideas across other platforms like OpenAI.

Iโ€™ve built DFIR and quick triage workflows that save me hours every time! The time savings really add up, and itโ€™s completely changed how I work.

3 months ago 3 0 1 1

Pretty ๐Ÿ˜

3 months ago 1 0 0 0
Post image

Merry Christmas everyone! Hope everyoneโ€™s enjoying some downtime ๐ŸŽ„

3 months ago 1 0 1 0