malmoeb.bsky.social
malmoeb.bsky.social
malmoeb.bsky.social
@malmoeb.bsky.social
Head of Investigations at InfoGuard AG - dfir.ch
Companies frequently approach us to discuss their security posture, playbooks, architecture, etc., but I wonder how many of them also regularly check basic configuration settings? An example from a recent case:
December 26, 2025 at 1:48 PM
During a recent engagement, we reviewed the collected AutoRuns data from all endpoints on the network. In that dataset, we identified the following scheduled task:

Name: 523135538
Command Line: C:\programdata\cp49s\pythonw.exe
December 25, 2025 at 9:01 AM
My team colleague, Yann Malherbe, worked on a case where the attacker used Everything [1] (locate files and folders by name instantly) to search for password files on the beachhead.
December 14, 2025 at 7:18 AM
The picture below depicts a (malicious) Inbox Rule. I slightly modified this Inbox Rule to protect our customer, but the gist is that it filters incoming mail from a specific bank employee, moves it to the RSS Folder, and marks it as read.
December 13, 2025 at 9:39 AM
For a new project, I started to dig into older threat reports, like for example, "The ProjectSauron APT" from 2016. [1]

The interesting thing about these old reports is that you see techniques mentioned before that are still used 10 years later.
December 12, 2025 at 9:15 AM
We are familiar with eMClient and axios, so let me introduce Trufflehog, the new kid on the block.

Trufflehog made headlines during the recent "Shai-Hulud" campaign, in which threat actors used it to search for passwords and sensitive information. [1] According to the Trufflehog GitHub page:
December 11, 2025 at 6:08 AM
I was playing around with bincrypter from THC (The Hackers Choice) [1]. The interesting points, as you can see in the screenshot below, are that the binary is encrypted, obfuscated, and 100% in memory. No temporary files, etc.
December 7, 2025 at 10:20 AM
Look at my tweet from February 2022. As simple as putting NG into the country field.

Guess what I found in this week's Business E-Mail Compromise? Successful logins from NG. Oh well..
November 30, 2025 at 4:47 PM
Reading a report from a recent Incident Response case from my teammate, Asger Strunk.

"It was observed that an unknown hostname “DESKTOP-LDIG48N” from the VPN DHCP IP address 192.168.128.149 made multiple failed login attempts using the username “admin” against various hosts within the network."
November 26, 2025 at 6:29 PM
I was reading an older report from CrowdStrike the other day:

"CrowdStrike was able to reconstruct the PowerShell script from the PowerShell Operational event log as the script’s execution was logged automatically due to the use of specific keywords." [1]
November 25, 2025 at 9:40 AM
A customer sent malware over. The file magic was CART.. What's that? Turns out, something pretty cool.

"This is where CaRT (which stands for Compressed and RC4 Transport) comes in. CaRT is used to store and transfer malware, as well as its metadata.
November 24, 2025 at 3:23 PM
I analyzed and recreated (a simpler version) of a PHP backdoor we detected in a recent Incident Response engagement. I used the backdoor to install an RMM agent on the compromised machine; the installed EDR did not raise a single alert.
November 17, 2025 at 8:09 AM
I love reading Incident Response reports from my colleagues. This one here from Matthieu Chatelan:

"Note that over 1700 lines (of risky sign-ins) were generated for this user account over the last 3 months.
November 15, 2025 at 8:33 AM
Craig Rowland never disappoints 🥇

He is showing us cool tricks for finding inconsistencies in the output from different Linux commands, pointing to an active Kernel rootkit.
November 14, 2025 at 1:10 PM
This is wild. From a recent IR engagement led by my teammate Florian Scheiber:

"The investigation showed that the attacker first compromised the Administrator’s personal Gmail account, [email protected]. Those credentials appeared in a combolist leaked on 2 June 2025.
November 14, 2025 at 9:49 AM
taskhostw.exe writes a PE file (see the classic TVqQAAMAAAA sequence there) inside the UCPD\DR registry key?

Microsoft implemented a driver-based protection to block changes to http/https and .pdf associations by 3rd party utilities, the so-called UCPD driver (UserChoice Protection Drive).
November 12, 2025 at 5:33 PM
This slide also didn't make the cut. Yes, anyone who has spent more than five minutes on a Hack The Box machine will know pspy, but what about my blue-team colleagues?
November 11, 2025 at 7:53 AM
The following slide hasn't made it into my "Fantastic cleartext password" talk, however, it's still a good one to share 🤓

"This simple tool logs usernames and passwords from authentication attempts against an OpenSSH server you control.
November 10, 2025 at 2:37 PM
Two of my teammates published artifacts on the Velociraptor Exchange this week 💪

Yann Malherbe released several VHDX artifacts, as described in his detailed blog post. [1]
November 8, 2025 at 9:49 AM
Dropping ngrok in a ZIP file onto disk results in the file being removed and an alert being raised, but installing ngrok via winget works just fine? 🤔🤷‍♂️
November 2, 2025 at 7:12 PM
This one here is a goodie! A customer called us because they had several incidents where the system time "magically" jumped days, sometimes even months, back and forth (see screenshot). You can imagine the issues inflicted by this behavior. So the question was.. Cyber? Attacker? Misconfiguration?
November 1, 2025 at 12:56 PM
So, I wrote about "Behavior:Win32/SuspRclone" before. [1]

"This behavioral monitoring signature gets triggered if the file Rclone.exe has been observed residing in a suspicious folder on a device." [2]
October 31, 2025 at 10:07 AM
Just when you think you know your way around Linux.. binfmt_misc: Hold my beer.

dfir.ch/posts/today_...
Today I learned: binfmt_misc | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
dfir.ch
October 30, 2025 at 11:43 AM
Today I learned: SeManageVolumePrivilege

While reading the HTB write-up for Certificate, I learned about SeManageVolumePrivilege. [1]

A video by Grzegorz Tworek goes into great detail about how to abuse SeManageVolumePrivilege.[2]
October 25, 2025 at 7:32 AM
Coming back to Maester! Do you know about the awesome Conditional Access What-If tests? [1]

The first image is from the official documentation and shows how easily you can build your own test scenario. The second image shows the results from a tenant where I ran the test.
October 24, 2025 at 8:22 AM