Lee Archinal (@archinallee) 's Twitter Profile
Lee Archinal

@archinallee

Log junkie trying to share what I know through training and posts. Privileged to be a #BlackHatUSA trainer!

ID: 1136683983293599744

calendar_today06-06-2019 17:19:14

2,2K Tweet

591 Followers

821 Following

Intel 471 (@intel471inc) 's Twitter Profile Photo

Threat hunting is about focus. Knowing where to spend your time is what sets tactical hunters apart. Join Out of the Woods live tomorrow for an interactive discussion on what drives real results. Our hosts will be engaging in real time on Discord. 🔗 hubs.la/Q03bpV4F0

Threat hunting is about focus. Knowing where to spend your time is what sets tactical hunters apart.

Join Out of the Woods live tomorrow for an interactive discussion on what drives real results. Our hosts will be engaging in real time on Discord.

🔗 hubs.la/Q03bpV4F0
Intel 471 (@intel471inc) 's Twitter Profile Photo

LockBit 4.0 enhances its stealth with PowerShell abuse, security feature bypasses, and obfuscated exfiltration. Intel 471 tracks its evolving tactics, read the full report here: hubs.la/Q03bP3sK0 #emergingthreat #lockbit #threathunting #threatintel

LockBit 4.0 enhances its stealth with PowerShell abuse, security feature bypasses, and obfuscated exfiltration. Intel 471 tracks its evolving tactics, read the full report here: hubs.la/Q03bP3sK0

#emergingthreat #lockbit #threathunting #threatintel
Lee Archinal (@archinallee) 's Twitter Profile Photo

Happy Monday everyone! Here is your #readoftheday! Source: CYFIRMA cyfirma.com/research/apt-p… A nice collection of #TTPs and #behaviors associated with #VoltTyphoon! Enjoy and #HappyHunting Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting

Intel 471 (@intel471inc) 's Twitter Profile Photo

🚨 VanHelsing Ransomware hit 3 victims within weeks of launch. Cross-platform, $500K ransoms, and growing fast. Intel 471 is tracking it, read the full report: hubs.la/Q03fwSjX0 #vanhelsing #ransomware #emergingthreats #threathunting #cybersecurity

🚨 VanHelsing Ransomware hit 3 victims within weeks of launch. Cross-platform, $500K ransoms, and growing fast. Intel 471 is tracking it, read the full report: hubs.la/Q03fwSjX0

#vanhelsing #ransomware #emergingthreats #threathunting #cybersecurity
ShortArm Solutions (@shortarmsas) 's Twitter Profile Photo

#Cybersecurity truly is a collaborative endeavor. We asked Steve Orrin from Intel to share his insights on how the government and commercial sides can work together to stay ahead of #CYBER threats. #informationsecurity

The DFIR Report (@thedfirreport) 's Twitter Profile Photo

“For this case we observed TXT records being utilized for C2 communication rather than MX records. This can be identified by the "type: 16" in the Sysmon logs seen above. Below is a sample list that, while not exhaustive, provides a clear example of the traffic patterns:” 1/2

“For this case we observed TXT records being utilized for C2 communication rather than MX records.

This can be identified by the "type: 16" in the Sysmon logs seen above.   Below is a sample list that, while not exhaustive, provides a clear example of the traffic patterns:”

1/2
The DFIR Report (@thedfirreport) 's Twitter Profile Photo

🌟New report out today!🌟 Navigating Through The Fog Analysis and reporting completed by Angelo Violetti, and reviewed by Zach. Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/04/28/nav…

The DFIR Report (@thedfirreport) 's Twitter Profile Photo

📉DFIR Labs Weekend Discount📉 Use this discount code to receive 10% off all DFIR Labs cases! Discount expires May 5th 04:00 UTC ⏲️Buy now, use anytime over the next 3 months. ➡️Discount code: WeekendDiscount20250502 Access DFIR Labs: store.thedfirreport.com/collections/df…

Intel 471 (@intel471inc) 's Twitter Profile Photo

Join Intel 471's Level 2 Threat Hunting Workshop on Execution tomorrow, May 14 from 12 - 1 PM EDT. Investigate PowerShell abuse, LOLBins, macro payloads, and more using real-world data. Finish the challenge, earn your #threathunting badge. Register now: hubs.la/Q03m5Z1H0

Join Intel 471's Level 2 Threat Hunting Workshop on Execution tomorrow, May 14 from 12 - 1 PM EDT. Investigate PowerShell abuse, LOLBins, macro payloads, and more using real-world data. Finish the challenge, earn your #threathunting badge.

Register now: hubs.la/Q03m5Z1H0
Intel 471 (@intel471inc) 's Twitter Profile Photo

CTI teams are under pressure to mature fast. In this #SANS webcast, Intel 471’s Ashley Jess shares insights on integrating #geopolitics and measuring CTI value using frameworks like CTI-CMM & CU-GIRH. Watch the full discussion: hubs.la/Q03tbg-t0 #CTI #cybersecurity

The DFIR Report (@thedfirreport) 's Twitter Profile Photo

🌟New report out today!🌟 Hide Your RDP: Password Spray Leads to RansomHub Deployment Analysis and reporting completed by [email protected]Aleks and UC2 🔊Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/06/30/hid…

Analyst1 (@analyst1) 's Twitter Profile Photo

🚨 New Threat Actor Profile by Anastasia From the shadows of Conti, Black Basta emerged as one of the most prolific ransomware gangs in recent years—until a massive internal leak exposed everything. 🔍 In our latest profile, we trace the group’s Conti lineage, breakdown

🚨 New Threat Actor Profile by <a href="/intel_anastasia/">Anastasia</a> 

From the shadows of Conti, Black Basta emerged as one of the most prolific ransomware gangs in recent years—until a massive internal leak exposed everything.

🔍 In our latest profile, we trace the group’s Conti lineage, breakdown
780th Military Intelligence Brigade (Cyber) (@780thc) 's Twitter Profile Photo

Intel 471: This post will examine one of the top pro-Russian hacktivist groups, new ones that have entered the scene and the impact of these groups. intel471.com/blog/pro-russi… Intel 471

Intel 471 (@intel471inc) 's Twitter Profile Photo

How do #malware behaviors inform hunt strategy? Find out July 31 in Intel 471’s live, hands-on workshop. Real telemetry, real IOAs, guided by our #threatintel and #threathunting teams. Sign up: hubs.la/Q03w49-h0 #cybersecurity #CTI

How do #malware behaviors inform hunt strategy? Find out July 31 in Intel 471’s live, hands-on workshop. Real telemetry, real IOAs, guided by our #threatintel and #threathunting teams. Sign up: hubs.la/Q03w49-h0

#cybersecurity #CTI
Renzon (@r3nzsec) 's Twitter Profile Photo

Super fun working on this lab with the XINTRA gang!! Enjoy and let us know your feedback! #ScatteredSpider #MuddledLibra #UNC3944