
RemcoS
@rsprooten
Followers
239
Following
378
Media
8
Statuses
499
Security Researcher @elasticseclabs
The Netherlands
Joined January 2011
RT @elasticseclabs: Check out this new #Linux research from @rsprooten and @RFGroenewoud! The article from #ElasticSecurityLabs details the….
0
23
0
Check out my new blog post on declawing PUMAKIT, a sneaky #LKM #rootkit targeting Linux systems. Find out how it hides, escalates privileges, and stays under the radar. Don’t miss the deep-dive! #cybersecurity #malwareanalysis #linux.
0
11
21
I had a little fun writing Go Assembly to supercharge the speed of my code. It's not every day I get to play with ARM assembly, let alone Go Assembly—challenging! But the speedup blew my mind. #go #simd #neon #benchmark.
0
1
8
RT @elasticseclabs: Yesterday the CUPS vulnerabilities were disclosed — today, we’re showcasing our analysis of the POC and how Elastic Sec….
0
24
0
RT @elasticseclabs: Today, @RFGroenewoud and @rsprooten are revealing the details to REF6138 — a Linux campaign for mining BitCoin/XMR. Rea….
0
14
0
RT @bsidesbelfast: @rsprooten showing us another way to look at malware code similarly with vector search!. #bsides #bsidesbelfast #bsidesb….
0
1
0
Excited to have presented on code similarity detection using Vector Search at #FirstCTI24 in Berlin! Yesterday, teamed up with @RFGroenewoud for a workshop on Malware Analysis & Event Collection. Amazing audience, incredible insights! #Cybersecurity.
1
3
10
RT @dez_: Not sure what this is but a lot of vt uploads recently with EV cert "REMAX PLUS LLC". PDF icon. Embedded obfuscated string "I am….
0
2
0
Just encountered a case in the #BeaverTail/#InvisibleFerret malware campaign, previously identified by @Unit42_Intel. Our findings: campaign ID NVRlYW05 and C2 server 144[.]172.74.108. It's a reminder of the evolving nature of cyber threats. Stay alert! #CyberSecurity #InfoSec
1
1
4
RT @elasticseclabs: Looking for a deeper dive on the Global Threat Report? Join our webinar next Thursday at 9am PT with @_devonkerr_ and @….
0
2
0
This is the second time I have the pleasure of working together with @RFGroenewoud and thrilled to have co-authored his first blog post for @elasticseclabs.
0
4
15
RT @FFmpeg: There have been several incorrect reports that FFmpeg has been involved in the distribution of malware. FFmpeg only provides s….
0
147
0
Speciale thanks to @dez_ , @DanielStepanic , @_devonkerr_ and @andythevariable for helping me prove once again that sleep is for the weak.
1
1
5
So I did not sleep a lot last night, but it's all worth it when you're working with a great team and kicking some #malware to the curb 🤣.
#ElasticSecurityLabs provides an overview of the recent 3CX supply chain compromise used to distribute SUDDENICON #malware, and provides resources to @elastic security users:
2
0
8
RT @elasticseclabs: Check out the latest research from @jdu2600, a technical analysis that explains LRPC and the limitations of defender vi….
0
33
0
And one more in this series. This time we go into the tools and techniques they used for maintaining persistence. We've seen a shift from custom #malware to #opensource tools and code.
We’re back with another #SIESTAGRAPH update! #ElasticSecurityLabs describes techniques used to maintain persistence in addition to deploying #NAPLISTENER and #SOMNIRECORD:
0
1
3