| QUASAR RAT | 
| 2019-09-25 | Brad Duncan | Malspam pushing Quasar RAT | 
| QUASAR | 
| 2025-06-11/a> | Xavier Mertens | Quasar RAT Delivered Through Bat Files | 
| 2023-11-18/a> | Xavier Mertens | Quasar RAT Delivered Through Updated SharpLoader | 
| 2023-06-16/a> | Xavier Mertens | Another RAT Delivered Through VBS | 
| 2022-03-11/a> | Xavier Mertens | Keep an Eye on WebSockets | 
| 2019-09-25/a> | Brad Duncan | Malspam pushing Quasar RAT | 
| RAT | 
| 2025-10-23/a> | Xavier Mertens | Infostealer Targeting Android Devices | 
| 2025-10-15/a> | Xavier Mertens | Clipboard Pictures Exfiltration in Python Infostealer | 
| 2025-10-08/a> | Xavier Mertens | Polymorphic Python Malware | 
| 2025-06-11/a> | Xavier Mertens | Quasar RAT Delivered Through Bat Files | 
| 2025-06-05/a> | Xavier Mertens | Be Careful With Fake Zoom Client Downloads | 
| 2025-05-19/a> | Xavier Mertens | RAT Dropped By Two Layers of AutoIT Code | 
| 2025-02-27/a> | Xavier Mertens | Njrat Campaign Using Microsoft Dev Tunnels | 
| 2025-01-03/a> | Xavier Mertens | SwaetRAT Delivery Through Python | 
| 2024-12-17/a> | Xavier Mertens | Python Delivering AnyDesk Client as RAT | 
| 2024-11-05/a> | Xavier Mertens | Python RAT with a Nice Screensharing Feature | 
| 2024-08-14/a> | Xavier Mertens | Multiple Malware Dropped Through MSI Package | 
| 2024-06-17/a> | Xavier Mertens | New NetSupport Campaign Delivered Through MSIX Packages | 
| 2024-05-31/a> | Xavier Mertens | "K1w1" InfoStealer Uses gofile.io for Exfiltration | 
| 2024-03-28/a> | Xavier Mertens | From JavaScript to AsyncRAT | 
| 2023-12-23/a> | Xavier Mertens | Python Keylogger Using Mailtrap.io | 
| 2023-12-20/a> | Guy Bruneau | How to Protect your Webserver from Directory Enumeration Attack ? Apache2 [Guest Diary] | 
| 2023-11-18/a> | Xavier Mertens | Quasar RAT Delivered Through Updated SharpLoader | 
| 2023-08-20/a> | Guy Bruneau | SystemBC Malware Activity | 
| 2023-08-18/a> | Xavier Mertens | From a Zalando Phishing to a RAT | 
| 2023-08-11/a> | Xavier Mertens | Show me All Your Windows! | 
| 2023-06-29/a> | Brad Duncan | GuLoader- or DBatLoader/ModiLoader-style infection for Remcos RAT | 
| 2023-06-16/a> | Xavier Mertens | Another RAT Delivered Through VBS | 
| 2023-05-30/a> | Brad Duncan | Malspam pushes ModiLoader (DBatLoader) infection for Remcos RAT | 
| 2023-05-20/a> | Xavier Mertens | Phishing Kit Collecting Victim's IP Address | 
| 2023-05-19/a> | Xavier Mertens | When the Phisher Messes Up With Encoding | 
| 2023-05-14/a> | Guy Bruneau | VMware Aria Operations addresses multiple Local Privilege Escalations and a Deserialization issue | 
| 2023-05-07/a> | Didier Stevens | Quickly Finding Encoded Payloads in Office Documents | 
| 2023-05-03/a> | Xavier Mertens | Increased Number of Configuration File Scans | 
| 2023-03-12/a> | Guy Bruneau | AsynRAT Trojan - Bill Payment (Pago de la factura) | 
| 2023-03-11/a> | Xavier Mertens | Overview of a Mirai Payload Generator | 
| 2022-10-21/a> | Brad Duncan | sczriptzzbn inject pushes malware for NetSupport RAT | 
| 2022-09-22/a> | Xavier Mertens | RAT Delivered Through FODHelper | 
| 2022-07-28/a> | Johannes Ullrich | Exfiltrating Data With Bookmarks | 
| 2022-06-16/a> | Xavier Mertens | Houdini is Back Delivered Through a JavaScript Dropper | 
| 2022-06-04/a> | Guy Bruneau | Spam Email Contains a Very Large ISO file | 
| 2022-05-20/a> | Xavier Mertens | A 'Zip Bomb' to Bypass Security Controls & Sandboxes | 
| 2022-05-05/a> | Brad Duncan | Password-protected Excel spreadsheet pushes Remcos RAT | 
| 2022-05-03/a> | Rob VandenBrink | Finding the Real "Last Patched" Day (Interim Version) | 
| 2022-03-11/a> | Xavier Mertens | Keep an Eye on WebSockets | 
| 2022-03-09/a> | Xavier Mertens | Infostealer in a Batch File | 
| 2022-02-18/a> | Xavier Mertens | Remcos RAT Delivered Through Double Compressed Archive | 
| 2022-02-11/a> | Xavier Mertens | CinaRAT Delivered Through HTML ID Attributes | 
| 2022-01-07/a> | Xavier Mertens | Custom Python RAT Builder | 
| 2021-12-01/a> | Xavier Mertens | Info-Stealer Using webhook.site to Exfiltrate Data | 
| 2021-11-04/a> | Brad Duncan | October 2021 Forensic Contest: Answers and Analysis | 
| 2021-09-01/a> | Brad Duncan | STRRAT: a Java-based RAT that doesn't care if you have Java | 
| 2021-06-21/a> | Rick Wanner | Mitre CWE - Common Weakness Enumeration | 
| 2021-04-09/a> | Xavier Mertens | No Python Interpreter? This Simple RAT Installs Its Own Copy | 
| 2021-03-31/a> | Xavier Mertens | Quick Analysis of a Modular InfoStealer | 
| 2021-03-04/a> | Xavier Mertens | From VBS, PowerShell, C Sharp, Process Hollowing to RAT | 
| 2021-02-24/a> | Brad Duncan | Malspam pushes GuLoader for Remcos RAT | 
| 2021-02-04/a> | Bojan Zdrnja | Abusing Google Chrome extension syncing for data exfiltration and C&C | 
| 2020-10-14/a> | Xavier Mertens | Nicely Obfuscated Python RAT | 
| 2020-09-30/a> | Johannes Ullrich | Scans for FPURL.xml: Reconnaissance or Not? | 
| 2020-09-28/a> | Xavier Mertens | Some Tyler Technologies Customers Targeted with The Installation of a Bomgar Client | 
| 2020-08-25/a> | Xavier Mertens | Keep An Eye on LOLBins | 
| 2020-08-18/a> | Xavier Mertens | Using API's to Track Attackers | 
| 2020-08-10/a> | Bojan Zdrnja | Scoping web application and web service penetration tests | 
| 2020-08-04/a> | Johannes Ullrich | Internet Choke Points: Concentration of Authoritative Name Servers | 
| 2020-05-14/a> | Rob VandenBrink | Patch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe | 
| 2020-04-17/a> | Xavier Mertens | Weaponized RTF Document Generator & Mailer in PowerShell | 
| 2020-02-05/a> | Brad Duncan | Fake browser update pages are "still a thing" | 
| 2020-01-10/a> | Xavier Mertens | More Data Exfiltration | 
| 2019-10-29/a> | Xavier Mertens | Generating PCAP Files from YAML | 
| 2019-09-27/a> | Xavier Mertens | New Scans for Polycom Autoconfiguration Files | 
| 2019-09-25/a> | Brad Duncan | Malspam pushing Quasar RAT | 
| 2019-09-19/a> | Xavier Mertens | Agent Tesla Trojan Abusing Corporate Email Accounts | 
| 2019-09-19/a> | Xavier Mertens | Blocklisting or Whitelisting in the Right Way | 
| 2019-04-26/a> | Rob VandenBrink | Pillaging Passwords from Service Accounts | 
| 2019-04-24/a> | Rob VandenBrink | Where have all the Domain Admins gone?  Rooting out Unwanted Domain Administrators | 
| 2019-03-06/a> | Xavier Mertens | Keep an Eye on Disposable Email Addresses | 
| 2018-11-27/a> | Rob VandenBrink | Data Exfiltration in Penetration Tests | 
| 2018-09-19/a> | Rob VandenBrink | Certificates Revisited - SSL VPN Certificates 2 Ways | 
| 2018-09-05/a> | Rob VandenBrink | Where have all my Certificates gone?  (And when do they expire?) | 
| 2018-08-24/a> | Xavier Mertens | Microsoft Publisher Files Delivering Malware | 
| 2018-06-15/a> | Lorna Hutcheson | SMTP Strangeness - Possible C2 | 
| 2018-05-19/a> | Xavier Mertens | Malicious Powershell Targeting UK Bank Customers | 
| 2018-05-10/a> | Bojan Zdrnja | Exfiltrating data from (very) isolated environments | 
| 2017-12-13/a> | Xavier Mertens | Tracking Newly Registered Domains | 
| 2017-11-03/a> | Xavier Mertens | Simple Analysis of an Obfuscated JAR File | 
| 2017-08-17/a> | Xavier Mertens | Maldoc with auto-updated link | 
| 2017-06-08/a> | Tom Webb | Summer STEM for Kids | 
| 2017-05-10/a> | Johannes Ullrich | Read This If You Are Using a Script to Pull Data From This Site | 
| 2017-04-20/a> | Xavier Mertens | DNS Query Length... Because Size Does Matter | 
| 2016-09-04/a> | Russ McRee | Kali Linux 2016.2 Release: https://www.kali.org/news/kali-linux-20162-release/ | 
| 2016-07-26/a> | Johannes Ullrich | Command and Control Channels Using "AAAA" DNS Records | 
| 2016-06-15/a> | Richard Porter | Warp Speed Ahead, L7 Open Source Packet Generator: Warp17 | 
| 2016-04-02/a> | Russell Eubanks | Why Can't We Be Friends? | 
| 2015-12-24/a> | Xavier Mertens | Unity Makes Strength | 
| 2015-11-09/a> | John Bambenek | Protecting Users and Enterprises from the Mobile Malware Threat | 
| 2015-09-03/a> | Xavier Mertens | Querying the DShield API from RTIR | 
| 2014-08-22/a> | Richard Porter | OCLHashCat 1.30 Released | 
| 2014-08-09/a> | Adrien de Beaupre | Complete application ownage via Multi-POST XSRF | 
| 2014-07-19/a> | Russ McRee | Keeping the RATs out: the trap is sprung - Part 3 | 
| 2014-07-18/a> | Russ McRee | Keeping the RATs out: **it happens - Part 2 | 
| 2014-07-16/a> | Russ McRee | Keeping the RATs out: an exercise in building IOCs - Part 1 | 
| 2014-03-13/a> | Daniel Wesemann | Identification and authentication are hard ... finding out intention is even harder | 
| 2013-06-18/a> | Russ McRee | Volatility rules...any questions? | 
| 2013-04-25/a> | Adam Swanger | Guest Diary: Dylan Johnson - A week in the life of some Perimeter Firewalls | 
| 2013-04-17/a> | John Bambenek | UPDATEDx1: Boston-Related Malware Campaigns Have Begun - Now with Waco Plant Explosion Fun | 
| 2013-04-16/a> | John Bambenek | Fake Boston Marathon Scams Update | 
| 2013-04-15/a> | John Bambenek | Please send any spam (full headers), URLs or other suspicious content scamming off Boston Marathon explosions to handlers@sans.org | 
| 2013-03-03/a> | Richard Porter | Uptick in MSSQL Activity | 
| 2013-02-06/a> | Johannes Ullrich | Are you losing system logging information (and don't know it)? | 
| 2012-10-30/a> | Mark Hofman | Cyber Security Awareness Month - Day 30 - DSD 35 mitigating controls | 
| 2012-05-22/a> | Johannes Ullrich | nmap 6 released | 
| 2012-01-03/a> | Rick Wanner | Analysis of the Stratfor Password List | 
| 2011-12-25/a> | Deborah Hale | Another Company Falls Victim | 
| 2011-10-26/a> | Rick Wanner | Critical Control 17:Penetration Tests and Red Team Exercises | 
| 2010-10-03/a> | Adrien de Beaupre | Canada's Cyber Security Strategy released today | 
| 2010-08-23/a> | Manuel Humberto Santander Pelaez | Firefox plugins to perform penetration testing activities | 
| 2010-08-16/a> | Raul Siles | Blind Elephant: A New Web Application Fingerprinting Tool | 
| 2010-07-08/a> | Kyle Haugsness | Pirate Bay account database compromised | 
| 2010-06-06/a> | Manuel Humberto Santander Pelaez | Nice OS X exploit tutorial | 
| 2010-04-13/a> | Adrien de Beaupre | Web App Testing Tools | 
| 2010-03-06/a> | Tony Carothers | Integration and the Security of New Technologies | 
| 2010-02-22/a> | Rob VandenBrink | New Risks in Penetration Testing | 
| 2009-07-27/a> | Raul Siles | New Hacker Challenge: Prison Break - Breaking, Entering & Decoding | 
| 2009-04-21/a> | Bojan Zdrnja | Web application vulnerabilities | 
| 2009-01-20/a> | Adrien de Beaupre | Obamamania | 
| 2008-11-25/a> | Andre Ludwig | The beginnings of a collaborative approach to IDS | 
| 2008-09-20/a> | Rick Wanner | New (to me) nmap Features | 
| 2008-07-18/a> | Adrien de Beaupre | Exit process? | 
| 2008-03-30/a> | Mark Hofman | Mail Anyone? |