KoifSec (@koifsec) 's Twitter Profile
KoifSec

@koifsec

Security research/detection, also writing for detect.fyi.
Base64 Enjoyer. Clippy is a threat actor.

ID: 1467068915599790085

linkhttps://koifsec.medium.com/ calendar_today04-12-2021 09:51:07

56 Tweet

51 Takipçi

164 Takip Edilen

Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

New Sigma release r2025-05-21 is available for download. 🌟15 New Rules 🛡️47 Rule updates 🔬13 Rule Fixes Explore the full release -> github.com/SigmaHQ/sigma/… This release focused mainly on updates and tunings of older rules, with newer detections covering NimScan, AdFind,

New Sigma release r2025-05-21 is available for download.

🌟15 New Rules
🛡️47 Rule updates
🔬13 Rule Fixes

Explore the full release -> github.com/SigmaHQ/sigma/…

This release focused mainly on updates and tunings of older rules, with newer detections covering NimScan, AdFind,
KoifSec (@koifsec) 's Twitter Profile Photo

Thanks Zack Allen for featuring my article again in Detection Engineering Weekly no. 114 ! detectionengineering.net/p/det-eng-week…

Thanks Zack Allen for featuring my article again in Detection Engineering Weekly no. 114 !

detectionengineering.net/p/det-eng-week…
KoifSec (@koifsec) 's Twitter Profile Photo

Hello! I will be running an interactive workshop as part of my company's "2025 State of Detection" webinar on June 17th 9am PST/12pm EST primarily focused about immutable artifacts and detection pitfalls. Sign up here: cardinalops.com/birds-eye-view…

Wietze (@wietze) 's Twitter Profile Photo

As June comes to an end, so does #HuntingTipOfTheDay. I hope you enjoyed them! 👉 Find all threat hunting tips here: x.com/search?q=from%…

Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

New Sigma release r2025-10-01 is available for download. 🌟43 New Rules 🛡️34 Rule updates 🔬27 Rule Fixes Explore the full release -> github.com/SigmaHQ/sigma/… This release introduces a bunch of new rules and updates - A bunch of CVE detections including CVE-2025-54309,

New Sigma release r2025-10-01 is available for download.

🌟43 New Rules
🛡️34 Rule updates
🔬27 Rule Fixes

Explore the full release -> github.com/SigmaHQ/sigma/…

This release introduces a bunch of new rules and updates

- A bunch of CVE detections including CVE-2025-54309,
Stephan Berger (@malmoeb) 's Twitter Profile Photo

SentinelOne published their analysis about PhantomCaptch. [1] One of the (many) interesting parts of this report is: "The script also disabled PowerShell command history logging via Set-PSReadlineOption -HistorySaveStyle SaveNothing as a means of evading forensic analysis." I

SentinelOne published their analysis about PhantomCaptch. [1] One of the (many) interesting parts of this report is:

"The script also disabled PowerShell command history logging via Set-PSReadlineOption -HistorySaveStyle SaveNothing as a means of evading forensic analysis."

I
KoifSec (@koifsec) 's Twitter Profile Photo

New post out! "Deconstructing Wmiexec-pro" Technical deep dive into a new post-exploitation framework based on Impacket's wmiexec, including a bunch of new telemetry and detections. Check it out > koifsec.medium.com/deconstructing…