⤷ Title: When the EDR Stays Silent: Hunting FIN7’s Fileless PowerShell Foothold
════════════════════════
𐀪 Author: Myra Moses Gomba
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 12:56:14 GMT
════════════════════════
⌗ Tags: #powershell_scripting #ethical_hacking #cybersecurity #incident_response #programming
════════════════════════
𐀪 Author: Myra Moses Gomba
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 12:56:14 GMT
════════════════════════
⌗ Tags: #powershell_scripting #ethical_hacking #cybersecurity #incident_response #programming
Medium
When the EDR Stays Silent: Hunting FIN7’s Fileless PowerShell Foothold
A threat intelligence feed lit up with a FIN7-linked IP address was actively communicating with the network. The EDR stayed quiet. No…
⤷ Title: The Shadow Chain (Part II): PowerShell, SSL/TLS, and the Art of Bypassing Corporate Firewalls
════════════════════════
𐀪 Author: Frank Mccausland
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 10:11:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #powershell #blue_team #infosec #red_team
════════════════════════
𐀪 Author: Frank Mccausland
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 10:11:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #powershell #blue_team #infosec #red_team
Medium
The Shadow Chain (Part II): PowerShell, SSL/TLS, and the Art of Bypassing Corporate Firewalls
Introduction
⤷ Title: Inside BlueNoroff’s “Self-Reinforcing” Deepfake Meeting Trap
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 08:30:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arctic Wolf #BlueNoroff #ClickFix #crypto security #Deepfakes #DPRK #infosec #Lazarus Group #powershell #social engineering #Web3 #Zoom Typo_squatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 08:30:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arctic Wolf #BlueNoroff #ClickFix #crypto security #Deepfakes #DPRK #infosec #Lazarus Group #powershell #social engineering #Web3 #Zoom Typo_squatting
Daily CyberSecurity
Inside BlueNoroff’s "Self-Reinforcing" Deepfake Meeting Trap
BlueNoroff uses a "self-reinforcing" deepfake pipeline to target crypto CEOs. Fake Zoom meetings and stolen footage lead to a 5-minute system compromise.
⤷ Title: TAMECAT: Iranian APT42 Group New PowerShell Backdoor Targeting Military and Government Officials
════════════════════════
𐀪 Author: Excalibra
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:44:12 GMT
════════════════════════
⌗ Tags: #powershell #malware #hacking #cybersecurity
════════════════════════
𐀪 Author: Excalibra
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:44:12 GMT
════════════════════════
⌗ Tags: #powershell #malware #hacking #cybersecurity
Medium
TAMECAT: APT42’s New PowerShell Backdoor Targeting Military and Government Officials
The Iranian APT42 group is conducting espionage attacks against high-ranking military and government officials using the TAMECAT…
⤷ Title: Earning Their Keep: Audit Your Microsoft Sentinel Log Value with “Log Horizon”
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:23:23 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure Sentinel #Cost Optimization #Defender XDR #FinOps #Infosec Tools #KQL #Log Analytics #Log Horizon #Microsoft Sentinel #PowerShell #Security Operations #SIEM #SoC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:23:23 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure Sentinel #Cost Optimization #Defender XDR #FinOps #Infosec Tools #KQL #Log Analytics #Log Horizon #Microsoft Sentinel #PowerShell #Security Operations #SIEM #SoC
Penetration Testing Tools
Earning Their Keep: Audit Your Microsoft Sentinel Log Value with "Log Horizon"
Stop burning money in your SIEM. Log Horizon analyzes Microsoft Sentinel tables to score security value vs. cost, providing concrete saving recommendations.
⤷ Title: eCPPT Powershell for Pentesters INE’s CTF 1 : A Practical Attack Story
════════════════════════
𐀪 Author: The.Flying.Wolf
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:53:31 GMT
════════════════════════
⌗ Tags: #ethical_hacking_tools #powershell #penetration_testing #hacking #red_team
════════════════════════
𐀪 Author: The.Flying.Wolf
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:53:31 GMT
════════════════════════
⌗ Tags: #ethical_hacking_tools #powershell #penetration_testing #hacking #red_team
Medium
eCPPT Powershell for Pentesters INE’s CTF 1 : A Practical Attack Story
This wasn’t just another lab. It felt like walking into a poorly guarded building, where every unlocked door revealed something more…
⤷ Title: PowerShell for Pentesters Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Sun, 03 May 2026 15:41:33 GMT
════════════════════════
⌗ Tags: #powershell #cybersecurity #tryhackme_walkthrough #tryhackme_writeup #tryhackme
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Sun, 03 May 2026 15:41:33 GMT
════════════════════════
⌗ Tags: #powershell #cybersecurity #tryhackme_walkthrough #tryhackme_writeup #tryhackme
Medium
PowerShell for Pentesters Walkthrough Notes | TryHackMe
Hands-on PowerShell practice for Windows checks and AD tasks.
⤷ Title: Living Off The Registry: Master AD CS Enumeration with the Native LOLBAS Toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:38:36 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD CS #certreq.exe #certutil.exe #Credential Theft #LOLBAS #NET Framework #Pentesting #PowerShell #red teaming #RSAT #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:38:36 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD CS #certreq.exe #certutil.exe #Credential Theft #LOLBAS #NET Framework #Pentesting #PowerShell #red teaming #RSAT #Windows Security
Penetration Testing Tools
Living Off The Registry: Master AD CS Enumeration with the Native LOLBAS Toolkit
Exploit Active Directory Certificate Services using only built-in Windows tools. No 3rd-party binaries—just certreq, certutil, and native PowerShell power.
⤷ Title: PowerShell Commands Every SOC Analyst Should Know
════════════════════════
𐀪 Author: Jagadishtripathy
════════════════════════
ⴵ Time: Wed, 06 May 2026 15:10:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #incident_response #windows_security #powershell #infosec
════════════════════════
𐀪 Author: Jagadishtripathy
════════════════════════
ⴵ Time: Wed, 06 May 2026 15:10:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #incident_response #windows_security #powershell #infosec
Medium
PowerShell Commands Every SOC Analyst Should Know
A practical guide for blue teamers who want to actually understand what they’re looking at
⤷ Title: TryHackMe Walkthrough: Windows PowerShell
════════════════════════
𐀪 Author: Shubham Khirwadkar
════════════════════════
ⴵ Time: Sun, 10 May 2026 15:18:12 GMT
════════════════════════
⌗ Tags: #infosec #powershell #windows #tryhackme #cybersecurity
════════════════════════
𐀪 Author: Shubham Khirwadkar
════════════════════════
ⴵ Time: Sun, 10 May 2026 15:18:12 GMT
════════════════════════
⌗ Tags: #infosec #powershell #windows #tryhackme #cybersecurity
Medium
TryHackMe Walkthrough: Windows PowerShell
A hands-on walkthrough of the Windows PowerShell room on TryHackMe.
⤷ Title: Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 07:01:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AMSI Bypass #ConnectWise #Cyber Security #Cyfirma #infosec #JPEG Exploit #Operation SilentCanvas #PowerShell Malware #ScreenConnect #Trojan #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 07:01:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AMSI Bypass #ConnectWise #Cyber Security #Cyfirma #infosec #JPEG Exploit #Operation SilentCanvas #PowerShell Malware #ScreenConnect #Trojan #UAC bypass
Daily CyberSecurity
Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage
CYFIRMA warns of Operation SilentCanvas: A weaponized JPEG delivers trojanized ScreenConnect, bypassing AMSI and UAC for full-system surveillance. Stay alert!
⤷ Title: PowerShell for Penetration Testers
════════════════════════
𐀪 Author: Mohamed Eid
════════════════════════
ⴵ Time: Thu, 14 May 2026 19:36:16 GMT
════════════════════════
⌗ Tags: #powershell #cybersecurity #ethical_hacking #penetration_testing #red_team
════════════════════════
𐀪 Author: Mohamed Eid
════════════════════════
ⴵ Time: Thu, 14 May 2026 19:36:16 GMT
════════════════════════
⌗ Tags: #powershell #cybersecurity #ethical_hacking #penetration_testing #red_team
Medium
PowerShell for Penetration Testers
PowerShell for Penetration Testers
⤷ Title: Microsoft Explains the New “SecureBoot” Folder in Windows 11 KB5089549 Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:43:42 +0000
════════════════════════
⌗ Tags: #Windows #C:\Windows\SecureBoot #Detect_SecureBootCertUpdateStatus #Device Security #Enterprise Fleet Management #KB5089549 #PowerShell Script #Secure Boot Expiration #Trust Chain Renovation #UEFI CA 2023 #Windows 11 May Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:43:42 +0000
════════════════════════
⌗ Tags: #Windows #C:\Windows\SecureBoot #Detect_SecureBootCertUpdateStatus #Device Security #Enterprise Fleet Management #KB5089549 #PowerShell Script #Secure Boot Expiration #Trust Chain Renovation #UEFI CA 2023 #Windows 11 May Update
Daily CyberSecurity
Microsoft Explains the New "SecureBoot" Folder in Windows 11 KB5089549 Update
Seeing a new SecureBoot folder under C:Windows? Microsoft confirms it is part of an essential KB5089549 update to replace expiring 2011 UEFI certificates.
⤷ Title: In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
Daily CyberSecurity
In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
TrendAI exposes Banana RAT, a fileless banking trojan by SHADOW-WATER-063 that uses in-memory execution and fake UI overlays to hijack Pix-QR transfers.
⤷ Title: Critical FortiClient EMS Exploitation Campaign Spreads New EKZ Infostealer Payload
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 04:25:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #credential stealer #CVE_2026_35616 #EKZ Infostealer #endpoint security #FortiClient EMS #PowerShell Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 04:25:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #credential stealer #CVE_2026_35616 #EKZ Infostealer #endpoint security #FortiClient EMS #PowerShell Malware
Daily CyberSecurity
Critical FortiClient EMS Exploitation Campaign Spreads New EKZ Infostealer Payload
Arctic Wolf warns of a new FortiClient EMS exploitation campaign using CVE-2026-35616 to deploy the stealthy EKZ Infostealer malware.
⤷ Title: The Day I Accidentally Destroyed My Own Evidence
════════════════════════
𐀪 Author: Teachnolen
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 00:36:25 GMT
════════════════════════
⌗ Tags: #powershell #ethical_hacking #digital_forensics #cybersecurity #blue_team
════════════════════════
𐀪 Author: Teachnolen
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 00:36:25 GMT
════════════════════════
⌗ Tags: #powershell #ethical_hacking #digital_forensics #cybersecurity #blue_team
Medium
The Day I Accidentally Destroyed My Own Evidence
By Patrick Nolen
⤷ Title: Windows PowerShell — TryHackMe Answers | by Deepti Gupta
════════════════════════
𐀪 Author: Deepti Gupta
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:20:29 GMT
════════════════════════
⌗ Tags: #windows #tryhackme #tryhackme_walkthrough #powershell #tryhackme_writeup
════════════════════════
𐀪 Author: Deepti Gupta
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:20:29 GMT
════════════════════════
⌗ Tags: #windows #tryhackme #tryhackme_walkthrough #powershell #tryhackme_writeup
Medium
Windows PowerShell — TryHackMe Answers | by Deepti Gupta
Platform: TryHackMe
⤷ Title: Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 06:14:09 +0000
════════════════════════
⌗ Tags: #Malware #Fileless Malware #information stealer #PowerShell Loader #PureLog Stealer #Securonix #Veil#Drop
Daily CyberSecurity
Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
Malware family PureLog Stealer (delivered by the Veil#Drop framework) Threat actor Not attributed by Securonix Targets Windows users; victim count not disclosed Delivery vector Malicious JavaScrip…
⤷ Title: Windows PowerShell: Advanced Object Filtering and Enterprise Automation
════════════════════════
𐀪 Author: Jonathan Sanfer
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 09:56:58 GMT
════════════════════════
⌗ Tags: #infosec #windows #tryhackme #powershell #cybersecurity
════════════════════════
𐀪 Author: Jonathan Sanfer
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 09:56:58 GMT
════════════════════════
⌗ Tags: #infosec #windows #tryhackme #powershell #cybersecurity
Medium
Windows PowerShell: Advanced Object Filtering and Enterprise Automation
Introduction
⤷ Title: ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 06:40:20 +0000
════════════════════════
⌗ Tags: #Malware #ACR Stealer #ClickFix #Credential Theft #EtherHiding #Infostealer #Malware_as_a_Service #Microsoft Defender #powershell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 06:40:20 +0000
════════════════════════
⌗ Tags: #Malware #ACR Stealer #ClickFix #Credential Theft #EtherHiding #Infostealer #Malware_as_a_Service #Microsoft Defender #powershell
Daily CyberSecurity
ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains
At a glance Malware family ACR Stealer (infostealer; linked to a rebrand of Amatera Stealer) Threat actor No named actor; sold via malware-as-a-service (MaaS) Target / victims Enterprise Windows e…