RemcoS Profile
RemcoS

@rsprooten

Followers
239
Following
378
Media
8
Statuses
499

Security Researcher @elasticseclabs

The Netherlands
Joined January 2011
Don't wanna be here? Send us removal request.
@rsprooten
RemcoS
3 months
RT @elasticseclabs: Check out this new #Linux research from @rsprooten and @RFGroenewoud! The article from #ElasticSecurityLabs details the….
0
23
0
@rsprooten
RemcoS
7 months
Check out my new blog post on declawing PUMAKIT, a sneaky #LKM #rootkit targeting Linux systems. Find out how it hides, escalates privileges, and stays under the radar. Don’t miss the deep-dive! #cybersecurity #malwareanalysis #linux.
0
11
21
@rsprooten
RemcoS
9 months
I had a little fun writing Go Assembly to supercharge the speed of my code. It's not every day I get to play with ARM assembly, let alone Go Assembly—challenging! But the speedup blew my mind. #go #simd #neon #benchmark.
0
1
8
@rsprooten
RemcoS
9 months
RT @elasticseclabs: Yesterday the CUPS vulnerabilities were disclosed — today, we’re showcasing our analysis of the POC and how Elastic Sec….
0
24
0
@rsprooten
RemcoS
9 months
RT @elasticseclabs: Today, @RFGroenewoud and @rsprooten are revealing the details to REF6138 — a Linux campaign for mining BitCoin/XMR. Rea….
0
14
0
@rsprooten
RemcoS
10 months
RT @bsidesbelfast: @rsprooten showing us another way to look at malware code similarly with vector search!. #bsides #bsidesbelfast #bsidesb….
0
1
0
@rsprooten
RemcoS
1 year
Excited to have presented on code similarity detection using Vector Search at #FirstCTI24 in Berlin! Yesterday, teamed up with @RFGroenewoud for a workshop on Malware Analysis & Event Collection. Amazing audience, incredible insights! #Cybersecurity.
1
3
10
@rsprooten
RemcoS
2 years
RT @dez_: Not sure what this is but a lot of vt uploads recently with EV cert "REMAX PLUS LLC". PDF icon. Embedded obfuscated string "I am….
0
2
0
@rsprooten
RemcoS
2 years
Just encountered a case in the #BeaverTail/#InvisibleFerret malware campaign, previously identified by @Unit42_Intel. Our findings: campaign ID NVRlYW05 and C2 server 144[.]172.74.108. It's a reminder of the evolving nature of cyber threats. Stay alert! #CyberSecurity #InfoSec
Tweet media one
Tweet media two
Tweet media three
1
1
4
@rsprooten
RemcoS
2 years
Yesterday was the launch day for my first #HTB box. Hop you all like it. #HackTheBox
Tweet media one
1
1
18
@rsprooten
RemcoS
2 years
What to do on a "shut it down"-Friday? Exactly, update some system config scripts 😂.#kali #ansible.
0
0
4
@rsprooten
RemcoS
2 years
RT @elasticseclabs: Looking for a deeper dive on the Global Threat Report? Join our webinar next Thursday at 9am PT with @_devonkerr_ and @….
0
2
0
@rsprooten
RemcoS
2 years
This is the second time I have the pleasure of working together with @RFGroenewoud and thrilled to have co-authored his first blog post for @elasticseclabs.
0
4
15
@rsprooten
RemcoS
2 years
RT @FFmpeg: There have been several incorrect reports that FFmpeg has been involved in the distribution of malware. FFmpeg only provides s….
0
147
0
@rsprooten
RemcoS
2 years
In all seriousness, it is very cool to be able to work on these samples. Especially the last stage (the info stealer). Anyone else had a look at that?.
0
0
1
@rsprooten
RemcoS
2 years
Speciale thanks to @dez_ , @DanielStepanic , @_devonkerr_ and @andythevariable for helping me prove once again that sleep is for the weak.
1
1
5
@rsprooten
RemcoS
2 years
So I did not sleep a lot last night, but it's all worth it when you're working with a great team and kicking some #malware to the curb 🤣.
@elasticseclabs
Elastic Security Labs
2 years
#ElasticSecurityLabs provides an overview of the recent 3CX supply chain compromise used to distribute SUDDENICON #malware, and provides resources to @elastic security users:
2
0
8
@rsprooten
RemcoS
2 years
RT @elasticseclabs: Check out the latest research from @jdu2600, a technical analysis that explains LRPC and the limitations of defender vi….
0
33
0
@rsprooten
RemcoS
2 years
And one more in this series. This time we go into the tools and techniques they used for maintaining persistence. We've seen a shift from custom #malware to #opensource tools and code.
@elasticseclabs
Elastic Security Labs
2 years
We’re back with another #SIESTAGRAPH update! #ElasticSecurityLabs describes techniques used to maintain persistence in addition to deploying #NAPLISTENER and #SOMNIRECORD:
0
1
3