alden
sr detection engineer @ huntress • malware enjoyer • macOS security
https://alden.io
- finally got around to rewriting the copy as yara binja plugin! 🥰 has a few quality of life improvements (new formats) and address wildcarding is fixed for ARM! (sorry bout that mac homies) ❤️ it's also now available in the plugin repository! 🔥 github.com/ald3ns/copy-...
- pwning my FTP server is a weird way to say you have a Crush on me but okay 🥰 anyways check out our analysis of some CrushFTP CVE-2025-31161 post exploitation activity! www.huntress.com/blog/crushft...
- BREAKING: DOGE has uncovered that the CIA spent $10,000,000 on zyns and has been feeding them to analysts to increase productivity! 😱
- [Not loaded yet]
- 🫶
- reminder to say happy new years to the russian espionage groups in ur network 🥰🇷🇺 @nosecurething.bsky.social, @laughingmantis.bsky.social, and I just dropped a new blog detailing a series of redcurl intrusions across several huntress customer environments 😳 www.huntress.com/blog/the-hun...
- i gotta step up my whitepaper game smh, my dad is doin numbers
- I really enjoyed #EMNLP2024. It was an honor to present our tokenization paper aclanthology.org/2024.emnlp-m.... I’m planning to post about some of my favorite papers soon, but here is a nice write up.
- following the recent cleo ITW exploitation, @huntress.com has released our analysis of the full post exploitation chain 🚀 the final java based implant framework is really neat and includes a custom C2 protocol 🔥 huntress.com/blog/cleo-soft…
- 🍎🤝🔥
- we cookin' for #100DaysofYARA 🤝🔥
- Binary Ninja plugin for copy and pasting bytes into YARA friendly format, courtesy of @re.wtf github.com/ald3ns/copy-... Rumor has it there's a next-generation version in the works that will probably blow your mind.
- some huntress homies cooked a blog on a new ransom group called safepay RE was fun until we realized it was ripped lockbit code 💀😭 imagine not being able to write your own ransomware, true skill issue smh some funny opsec fails too, watch ya status www.huntress.com/blog/its-not...
- [Not loaded yet]
- thrunting thractors w thrintel