alden
sr detection engineer @ huntress • malware enjoyer • macOS security
https://alden.io
- finally got around to rewriting the copy as yara binja plugin! 🥰 has a few quality of life improvements (new formats) and address wildcarding is fixed for ARM! (sorry bout that mac homies) ❤️ it's also now available in the plugin repository! 🔥 github.com/ald3ns/copy-...
- Reposted by alden[Not loaded yet]
- pwning my FTP server is a weird way to say you have a Crush on me but okay 🥰 anyways check out our analysis of some CrushFTP CVE-2025-31161 post exploitation activity! www.huntress.com/blog/crushft...
- Reposted by alden[Not loaded yet]
- Reposted by alden[Not loaded yet]
- BREAKING: DOGE has uncovered that the CIA spent $10,000,000 on zyns and has been feeding them to analysts to increase productivity! 😱
- Reposted by alden[Not loaded yet]
- reminder to say happy new years to the russian espionage groups in ur network 🥰🇷🇺 @nosecurething.bsky.social, @laughingmantis.bsky.social, and I just dropped a new blog detailing a series of redcurl intrusions across several huntress customer environments 😳 www.huntress.com/blog/the-hun...
- Reposted by alden[Not loaded yet]
- Reposted by alden[Not loaded yet]
- i gotta step up my whitepaper game smh, my dad is doin numbers
- Reposted by alden[Not loaded yet]
- Reposted by alden[Not loaded yet]
- Reposted by alden[Not loaded yet]
- following the recent cleo ITW exploitation, @huntress.com has released our analysis of the full post exploitation chain 🚀 the final java based implant framework is really neat and includes a custom C2 protocol 🔥 huntress.com/blog/cleo-soft…
- Reposted by alden[Not loaded yet]
- Reposted by alden[Not loaded yet]
- 🍎🤝🔥
- we cookin' for #100DaysofYARA 🤝🔥
- Binary Ninja plugin for copy and pasting bytes into YARA friendly format, courtesy of @re.wtf github.com/ald3ns/copy-... Rumor has it there's a next-generation version in the works that will probably blow your mind.
- Reposted by aldenHow does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...
- Reposted by alden[Not loaded yet]
- Reposted by alden[Not loaded yet]