mthcht
            
            @mthcht.bsky.social
          
          880 followers
          310 following
          54 posts
        
          Threat Hunting - DFIR - Detection Engineering
🐙 https://github.com/mthcht
🐦 https://x.com/mthcht
📰 https://mthcht.medium.com
            
      
        Posts
        Media
        Videos
        Starter Packs
      
    
        
      Pinned
    
  
          
              mthcht
              @mthcht.bsky.social
          
              · Mar 28
        
        
      
    
          
              mthcht
              @mthcht.bsky.social
          
              · Mar 9
        
        
      
    
          
              mthcht
              @mthcht.bsky.social
          
              · Mar 4
        
        
          
      In case you don't want to do this yourself, I just discovered that you can request access to a complete list of all existing domains across 1131 TLDs on czds.icann.org for free, including NS records! The lists are updated every month, approval is required for each TLD 🌍
    
        
      I have a list of NS used for sinkhole domains and seized servers: raw.githubusercontent.com/mthcht/awesome…
I'm searching for the domains, on my server I can resolve a record type for ~400 million domains per day with github.com/blechschmidt/m��� 😃 Massive improvement compared to other solutions!
  I'm searching for the domains, on my server I can resolve a record type for ~400 million domains per day with github.com/blechschmidt/m��� 😃 Massive improvement compared to other solutions!
          
              mthcht
              @mthcht.bsky.social
          
              · Feb 27
        
        
      
    
        
      Reposted by mthcht
    
  
  
        
      Reposted by mthcht
    
  
          
              Kostas
              @kostastsale.bsky.social
          
              · Feb 24
        
        
        
            Confluence Exploit Leads to LockBit Ransomware
            Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.…
          
            
            thedfirreport.com
          
        
      
    
          
              mthcht
              @mthcht.bsky.social
          
              · Feb 20
        
        
          
        
      Reposted by mthcht
    
  
          
              mthcht
              @mthcht.bsky.social
          
              · Feb 17
        
        
          
      I have a list of NS used for sinkhole domains and seized servers: raw.githubusercontent.com/mthcht/awesome…
I'm searching for the domains, on my server I can resolve a record type for ~400 million domains per day with github.com/blechschmidt/m��� 😃 Massive improvement compared to other solutions!
        I'm searching for the domains, on my server I can resolve a record type for ~400 million domains per day with github.com/blechschmidt/m��� 😃 Massive improvement compared to other solutions!
        
      Reposted by mthcht
    
  
  
          
              mthcht
              @mthcht.bsky.social
          
              · Feb 11
        
        
          
      DFIR specialist Mthcht has released LOLC2, a collection of C2 frameworks that leverage legitimate services to evade detection
lolc2.github.io
        lolc2.github.io
        
      Reposted by mthcht
    
   
        