Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Saltmyhash

@saltmyhash@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Blue team. #cti #threat_hunting #ioc #reverseengineering #threatintelligence #soc #malware

0 Followers
344 Following
20 Posts
Joined November 08, 2022
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 4mo ago
686
19
318
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 4mo ago

@bagder@mastodon.social You have a fan at Dairy Queen.

#curl

92
1
21
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
Rosemary Clooney’s Baby #HashTagGames #ClassicMovieStarABook
12
0
5
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
Replying to
@cR0w@infosec.exchange
9
0
3
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
Replying to
@cR0w@infosec.exchange @trojanfoxtrot@infosec.exchange I’ve started submitting applications from behind Astrill VPN infrastructure, at least I know their SOC/CTI shops will see my app when they are investigating DPRK remote IT workers.
5
1
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
Argo Back To Bed #TooSleepyAMovieOrPlay#HashtagGames
4
0
1
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 2mo ago
Replying to
@catsalad@infosec.exchange can’t inhale particulates if you can’t breathe
2
0
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 5mo ago
Replying to
@jerry@infosec.exchange good reminder for all of us to consider donating to our instance admin who could be spending their weekend relaxing instead of patching. Just sent mine. Thanks Jerry.
4
1
1
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 8mo ago
Replying to
@HailsandAles@metalhead.club Submission: Power Trip - Nightmare Logic Honorable Mentions: Wolves in the Throne Room - Thrice Woven Migos - Culture Future Islands - The Far Field War on Drugs - A Deeper Understanding
8
0
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 2mo ago
Die Another Day #BetterLateThanNeverAMovie#HashtagGames
1
0
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
Replying to
@trojanfoxtrot@infosec.exchange Same. Have you rewritten your resume/CV to make it past the applicant tracking system (ATS)/AI bots? I was getting application rejections for job postings that were literally my current job role and decided to rewrite my resume to ensure the formatting wasn’t tripping up their stupid AI software. While I haven’t found a job yet, I HAVE been getting more call-backs post-rewrite. Stay strong, it’s rough out here.
1
2
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
I was trying to carve out an encrypted blob from a PNG file last night using dd and finally triggered the new macOS ClickFix warning in my terminal. It was interesting that it fired because I wasn’t attempting to execute a commonly abused binary like osascript or make an outbound web call. While I haven’t been able to identify what XProtect is flagging on, I’m personally leaning towards either simple pattern matching for risky terms (I did have a suspicious output filename) or literally any pastes from a browser. The latter I have tried numerous times to no avail when this was first released in Tahoe 26.4, so I have no idea. FWIW, this was the offending command: dd if=clik.txt of=encrypted_payload.bin bs=1 skip=27856 status=progress https://9to5mac.com/2026/03/25/macos-26-4-has-new-terminal-popup-warning-when-pasting-commands/ #macos #malware #clickfix
macOS 26.4 has new Terminal popup warning when pasting commands - 9to5Mac
9to5Mac

macOS 26.4 has new Terminal popup warning when pasting commands - 9to5Mac

macOS Tahoe 26.4 users have discovered that the update adds a new Terminal security popup when you first try to paste in commands.

1
1
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 5mo ago
Replying to
@Gargron Soundtrack to Perfect Days is great. The komorebi cinematography is also equally perfect. Excellent film, highly recommend for everyone.
2
0
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 5mo ago

@darfplatypus@infosec.exchange @cR0w@infosec.exchange I took a look at a canonical threat intel job a few months ago, saw the ridiculous requirements involving pre-college transcripts/report cards, laughed, and closed the page.

1
1
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 6mo ago
Replying to
@HailsandAles Immolation sounds like Immolation.
1
0
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 5mo ago

CISA KEV is claiming Copy Fail is under active exploitation but provides zero evidence of how/where. Anyone seeing anything else in public reporting to corroborate these claims?

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

#copyfail #cve_2026_31431

Cybersecurity and Infrastructure Security Agency CISA

Known Exploited Vulnerabilities Catalog | CISA

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Learn more about how to use the KEV catalog in your organization.

0
1
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 5mo ago

@da_667@infosec.exchange relatively weak but something is better than nothing. Might benefit from a GitHub PR if you find something interesting in network/host artifacts.

https://lolrmm.io/tools/nomachine

lolrmm.io
0
0
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
Network defenders should take a look at and hunt for Overlord RAT, a publicly-available and open-source Go-based RAT. Proofpoint recently published a blog post highlighting its adoption by UNK_DeadDrop, a DPRK-nexus threat group which appears to have used a lightly modified version but can still be detected via Shodan, Censys, or FOFA queries. Proofpoint notes minor operational overlaps with Contagious Interview, but UNK_DeadDrop appears to prefer Overlord while Contagious Interview sticks with OtterCookie/InvisibleFerret. Regardless, extraction of TTPs is super easy when the source code is available and great for folks who want an introduction into detection engineering and/or threat hunting. For example, Overlord RAT ships with default self-signed certificates/port configurations. While advanced adversaries will obviously alter these settings, many groups won’t, including UNK_DeadDrop. This makes developing a baseline detection within Censys/Shodan/FOFA trivial for monitoring. The Censys query in the screenshot is rudimentary, but you get the idea. Start with low-hanging fruit and tune your queries to hunt for advanced adversaries who might be using more bespoke Overlord configurations. Once found, ingest and retro-hunt the IOCs in your environment. Overlord clients will establish C2 communications with these servers. https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal https://github.com/vxaboveground/Overlord #overlord #unk_deaddrop #RAT #detectionengineering #threathunting #cti #threatintel
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US
Proofpoint

Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US

By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor

0
0
7
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 3mo ago
Friendly reminder that the first round of DEATHCon tickets go on sale July 7th. I recommend setting a reminder and logging on earlier in the day (like, early morning) to purchase as they will sell out quick. DEATHCon is easily the best bang for your conference buck when it comes to the amount of presentations and available logs to cut your teeth on detection engineering and threat hunting. https://deathcon.io/tickets.html #deathcon #threathunting #detectionengineering #conference
deathcon.io

Tickets - DEATHCon 2026 - Detection Engineering and Threat Hunting

DEATHCon - Detection Engineering and Threat Hunting Workshops

0
0
0
0
Open post
Saltmyhash @saltmyhash@infosec.exchange
· 2mo ago
Replying to
@kajer@infosec.exchange impossible travel is hot garbage.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:42:08 UTC