| At Triangle Wave Security we wanted to automatically hook our spreadsheet of doom into IOC feeds and sandbox results as the incident unfolded. Bulk copy-and-paste just didn’t have the juice and there are already enough dedicated year-old but abandoned tools. So we built Apipheny to handle the scheduling, full REST + OAuth, and plug directly into Google Sheets. We also added a one-time purchase because we’re tired of endless subscriptions too. As part of the DFIR community, use code 4N64EVA for 80% off. |
| Sponsored by Triangle Wave Security |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Brian Carrier at Cyber Triage
AI in DFIR 101: Why AI isn’t Good for DFIR Collections -
Digital Forensics Myanmar
-
Oleg Afonin at Elcomsoft
Write Blockers in Forensics: What Controls How You Use Them? -
Forensafe
Apple Screen Time -
Kevin Pagano at Stark 4N6
Tracking Timezone Changes in Digital Wellbeing -
Synacktiv
Forensic AWS EKS : sources de données et méthodes d’investigation -
Tim Korver at ‘Thesis Friday’
Thesis Friday #25: Proximity is not causality
Threat hunting/threat intelligence
-
Abnormal Security
-
Any.Run
-
ASEC
-
Ayelen Torello at AttackIQ
Response to CISA Advisory (AA26-222A): #StopRansomware: Gunra Ransomware -
Christine Barry at Barracuda
The Gentlemen ransomware: Inside one of the fastest-growing extortion operations -
Bishop Fox
No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452 -
Martin Zugec at Bitdefender
SilkParasite: Tracking a China-Nexus APT Across Central Asia -
Brad Duncan at Malware Traffic Analysis
2026-08-21: SmartApeSG ClickFix campaign leads to two RATs -
BushidoToken
UK Cybercrime Journal: Carding Tactics & Youth Money Muling -
CERT-AGID
-
Check Point
-
CISA
Defending Against an Active Threat to Siemens S7 Series PLCs -
Cisco’s Talos
-
Joseph Hoggle at Cofense
Phonescams: Casting a Wide Net in an Orchard of Low-Hanging Fruit -
Cyble
Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates -
D3Lab
-
Zander Mackie at Datadog Security Labs
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled “go-titan,” and how to hunt for it -
Dream
The Intelligence Factory: How AI Is Replacing the Nation-State Back Office -
Erik Hjelmvik at Netresec
CNCMachineRMS C2 Protocol -
Esentire
Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra – Killing Your EDR Since 2025 -
Andréanne Bergeron at Flare
1 in 20 Stealer Log Victims are Threat Actors -
Flashpoint
Insider Threat Report: Dark Web Recruitment & Access Trends -
Google Cloud Threat Intelligence
-
Group-IB
-
Justin Timothy at GuidePoint Security
Beware the Ransomware Rescuer: Ransom Busters -
Hudson Rock
-
Hunt IO
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia -
Huntress
-
Keith McCammon
Intrusion observations mid-2026 -
Serhii Melnyk and Timmy Lister at LevelBlue SpiderLabs
Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking -
Stefan Dasic at Malwarebytes
41 deceptive download sites show a real link, then send you somewhere else -
Ax Sharma and Cody Nash at Manifold Security
What to think about curl | bash now that AI agents run it -
Aayush Tyagi at McAfee Labs
WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware -
Microsoft Security
Hunting MacSync Stealer infrastructure through behavioral pivots -
Nebulock
-
Oleg Skulkin at ‘Know Your Adversary’
-
Bill Batchelor at Palo Alto Networks
Identity Abuse Through Trusted Communication Channels -
Practical Security Analytics
How to Build Threat Emulation Workflows -
Dani [Varys] Z, Ellis Stannard, Eric Taylor, and Nick Smart at Ransom-ISAC
Infrastructure Destruction Squad / BLACKNET-00: Ransomware, Firebase and ICS Tooling -
Anna Širokova and Jan Recinsky at Rapid7
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline -
Recorded Future
CopyCop Targets AI Investment in Armenia -
Red Canary
Intelligence Insights: August 2026 -
John Dilgen and Connor Short at ReliaQuest
Clop Returns with Custom Implant in Mass-Extortion Campaign -
SANS Internet Storm Center
- Wireshark 4.6.8 Released, (Sun, Aug 16th)
- Apple Patches iOS and macOS, (Mon, Aug 17th)
- Apple Screen Sharing Security, (Mon, Aug 17th)
- Using Microsoft Graph and Powershell to Mine for Information – Stale Accounts and Licenses, (Thu, Aug 20th)
- Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)
- Using Microsoft Graph and Powershell – Risk Detection Commands, (Thu, Aug 20th)
- Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
- Even MOAR Powershell, looking at Entra logins – the good, the bad and the password sprays, (Fri, Aug 21st)
-
Dmitry Kalinin at Securelist
The invisible passenger in your car -
Silent Push
New Research: How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else’s Product -
Tarek Mostafa
Payload Ransom Group Profiling -
The Hunter’s Ledger
Enough to Be Dangerous: The Mechanics of an LLM-Assisted Intrusion Campaign -
The Raven File
VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims -
ThreatFabric
Manic: Blend between Banking Malware & Spyware -
ThreatMon
Azure Credential Theft Campaign -
Trellix
- When Agents Go Rogue: The OpenClaw Supply Chain Crisis
- Stitching the Kill Chain: Detecting NTDS.dit Exfiltration with Trellix Helix Correlation
- Signed, sealed, injected: The mechanics of DCRat in 2026
- Weaponized AI: The Commoditization of Cybercrime
- Now You See It, Now You Don’t: Inside the Ghost SPN Attack Bypassing Your Security
-
Lior Adar at Varonis
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower -
WeLiveSecurity
How QR-code phishing can slip past corporate security measures -
Wiz
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
AI-Assisted Network Threat Hunting: See It, Enrich It, Ask It-BHIS Webcast -
Cellebrite
Meet Cellebrite Genesis: From Digital Overload to Investigative Clarity
Presentations/podcasts
-
ADF Solutions
-
Anuj Soni
Skip the Disassembly: Malware Analysis Without Reading Every Line of Code -
Black Hat
Black Hat Asia 2026 | Tropic Trooper Reloaded: Unraveling the Invisible Supply Chain Mystery -
Cellebrite
Training Offerings for Cellebrite Genesis -
DEFCON
DefCon 34 – Stalking the Wily Hacker: 40 years later – Cliff Stoll -
Dr Josh Stroschein
Inspecting Packed PE Sections & Entropy | Packing & Obfuscation Lesson 02 -
Dr. Meisam Eslahi at ‘Nothing Cyber’
Cyber Threat Hunt 101: Part 8 – Data Preparation, Scripting, and Visualization! -
Huntress
RMM Guard: Map Every RMM Tool Across Your Endpoints -
InfoSec_Bret
IR – SOC149 – Index Page Changed Unexpectedly -
Monolith Forensics
-
MyDFIR
CyberDefenders SOC Analyst Lab – l337 S4uc3 (PCAP & Memory) -
Off By One Security
Enforcing User-Kernel Separation on Windows SMAP, User Mode Accessors, and more -
Open Source Forensics Lab
Mobile Forensics Certification Overview: ICMDE -
OpenSourceMalware
The OpenSourceMalware Show #18 -
Sygnia
Shai-Hulud in the Wild: What Security and IR Teams Need to Know -
THE Security Insights Show
The AI & Security Insights Show Episode 298 | Julian Kusenberg – Purview, Agents and AI! oooh my! -
Three Buddy Problem
Malware analysis
-
Acronis
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign -
Ilyas Makari at Aikido
Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack -
BI.Zone
Arsenal revamped: Core Werewolf hits Russian organizations with CoreRAT -
Marcus Hutchins at Expel
SynkLoader: when you throw in everything but the kitchen sink -
Joselyn Canuela and Alfed Samonteza at G Data Software
Projextor: Abusing Electron in Trojanized Productivity Applications -
Vojtěch Krejsa at Gen
WordlistLoader Delivering Amatera via ClearFake Campaigns -
Allen Ace at InfoSec Write-ups
Behavioral Malware Analysis: Investigating a Multi-Stage Malware Sample Inside an Isolated Lab -
OpenSourceMalware
-
Priya Patel at Seqrite
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor -
Socket
-
Colin Cowie, Rafe Pilling, and Ryan Westman at Sophos
Fake AI, real malware: Attackers impersonating AI brands -
ZScaler
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
Miscellaneous
-
Anton Chuvakin
-
Elif Kurt at Binalyze
What did the AI actually do? -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 08/17/26 -
Forensic Focus
- AI Image Classification For Forensics – Build Custom Detectors In Seconds | BelkaGPT
- Investigations Don’t Arrive In One Tidy Format
- New DFIR Mental Health Training Webinar (CPD-Accredited)
- £2.4 Million For UK Police Well-Being – What Will It Actually Buy?
- Cellebrite Genesis For Enterprise Now Generally Available, Regional Availability Expands To More Global Markets
- Unmasked: Throughput Is Not Prioritisation
- Digital Forensics Round-Up, August 19 2026
- Impact, Coping And Support – Further Reflections From The DFIR Well-Being Study
- Forensic Focus Digest, August 21 2026
-
Gary Katz and Jason Deyalsingh at Detect FYI
-
Jeffrey Appel
Auditing Microsoft Defender and Intune Configuration Changes -
Keibidrop
Triage a remote machine without a VPN -
Magnet Forensics
-
Matthew Plascencia
Cert Savvy: ICMDE -
N00b_H@ck3r
Extracting System Files (e.g SAM and SYSTEM hives) with 7-Zip -
Steven Folek at UltimaCybr
-
Rena Stern at Sygnia
Incident Response vs. Crisis Management: Why Treating Them as the Same Thing Is Dangerous -
Yacin Nadji at Corelight
Software releases/updates
-
Arkime
v6.7.0 -
Belkasoft
Belkasoft X 2.12: A Sneak Peak -
Brian Maloney
OneDriveExplorer v2026.08.19 -
Crowdstrike
Falconpy Version 1.6.5 -
David Augros
sigwood v0.4.0 -
Digital Sleuth
winfor-salt v2026.12.1 -
Doug Burks
so-crates v4.0.0 -
GCHQ
CyberChef v11.4.0 -
Get-Sybers
DX_DFIR v0.2.0 — dxdfir CLI + get_sybers.dfir collection -
IntelOwl
v6.8.0 -
Joshua Hickman at ‘The Binary Hick’
Timestamped -
LEAPPs
-
Nedim Šabić
fibratus v3.1.1: chore(deps): Bump golang.org/x/net from 0.54.0 to 0.55.0 -
OpenCTI
7.260817.0 -
WithSecure Labs
Chainsaw v2.16.4 -
Yaniv Radunsky
DFIR Companion v0.35.1 — release binaries restored
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.