Log inSign up
Tony Lambert
3,871 posts
Tony Lambert profile banner
@ForensicITGuy

Tony Lambert

@ForensicITGuy
Recovering sysadmin that now chases adversaries instead of uptime. Sr Malware Analyst @redcanary
Tennessee
forensicitguy.github.io
Joined November 2011
1,219
Following
6,039
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @ForensicITGuy
    Tony Lambert
    @ForensicITGuy
    Dec 9, 2025
    Sometimes adversaries bring in their own tools, and if they leave behind a VM disk, analysis is fair game. In this post we look at some tools an adversary brought during a social engineering campaign.
    redcanary.com
    When adversaries bring their own virtual machine for persistence
    We peel back the layers on a threat involving an adversary who brought their own VM into an environment following aggressive spam bombing.
    1
  • @ForensicITGuy
    Tony Lambert
    @ForensicITGuy
    Oct 10, 2025
    It's not just you, most of the macOS stealers look the same nowadays, but there are subtle differences between stealer families to tell them apart. If you're a stickler for detail like us, you might enjoy this post showing differences between the malware.
    Image
    Distinguishing Atomic, Odyssey, and Poseidon stealers on macOS
    From redcanary.com
  • @ForensicITGuy
    Tony Lambert
    @ForensicITGuy
    May 19, 2025
    Do you miss @cobaltstrikebot? If so, here's a blog post showing how you can pull Cobalt Strike SpawnTo and watermark info with @shodanhq and some PowerShell:
    Lemony Fresh Shodan Data
    Squeezing Cobalt Strike Threat Intelligence from Shodan
    From forensicitguy.github.io
  • @ForensicITGuy
    Tony Lambert
    @ForensicITGuy
    Jan 18, 2025
    The first step to getting robust detections is writing brittle ones that get bypassed and finding out in a red team report.
    @nas_bench
    Nasreddine Bencherchali
    @nas_bench
    Jan 17, 2025
    Happy Friday 😁
    Image
    1
  • @ForensicITGuy
    Tony Lambert
    @ForensicITGuy
    Jan 3, 2025
    New blog post for #100DaysofYARA , in this one I look at a VenomRAT sample and create rules based on PE metadata and an encryption salt value. forensicitguy.github.io/exploring-veno… #malware
    VenomRAT
    Exploring VenomRAT Metadata and Encryption with YARA - #100DaysOfYara
    From forensicitguy.github.io
    2
Advertisement
Advertisement