Tony Lambert

@forensicitguy.bsky.social

Recovering sysadmin that now chases adversaries instead of uptime. Sr Malware Analyst @redcanary

A fun yearly endeavor for me is contributing to the Red Canary Threat Detection Report, and the 2025 edition is out today! distilled into one report! Get your free copy of our 2025 Threat Detection Report now. ⬇️ #ThreatReport #SecOps #ThreatIntel redcanary.com/threat-detec...

Welcome to the Red Canary Threat Detection Report

Our Threat Detection Report takes a close look at the top techniques, threats, and trends to help security teams focus on what matters most.

redcanary.com

"For what it's worth, the curl by itself is likely safe. It's the chmod and nohup bash after it that are the problem" I saw this on a forum post today, and I swear it's the macOS/Linux version of "it's not the fall that kills, it's the impact"

I am working on a public platform to make it even easier for people to report code-signing certificates. My goal is to continue to raise awareness on the abuse and the impact revocation has on malware distributors. Keep an eye on my socials for more news.

certReport 3.1.4 Bugfix - indicators could be printed in duplicate certReport makes reporting code-signing certs easy. No-one likes spending time reading or writing reports. That is: I just noticed the problem. Maybe someone else did. I don't know. It is gone now.

May 13, 2024 blogpost It is common for malware to be signed with code signing certificates. How is this possible? Impostors receive the cert directly and sign malware. In this blog-post, we look at 100 certs used by #Solarmarker #malware to learn more. squiblydoo.blog/2024/05/13/i...

Impostor Certificates

It is common for malware to be signed with code signing certificates. How is this possible? Impostors receive the cert directly and sign malware. In this blog-post, we look at 100 certs used by Sol…

squiblydoo.blog