Log inSign up
SpiderLabs
6,106 posts
SpiderLabs profile banner
@SpiderLabs

SpiderLabs

@SpiderLabs
The elite security team at @LevelBlueCyber. Response & Investigations. Analysis & Testing. Research & Development. Follow for info on the latest threats.
Everywhere
levelblue.com/blogs/spiderla…
Joined January 2009
364
Following
27K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @SpiderLabs
    SpiderLabs
    @SpiderLabs
    Aug 27
    Our researchers recently found a 7-stage exploit chain that abuses Cloud Files, Windows Object Manager namespaces, Defender remediation and Windows Error Reporting to escalate from a standard user to SYSTEM on fully patched Windows systems. levelblue.com/blogs/spiderla…
    Image
  • @SpiderLabs
    SpiderLabs
    @SpiderLabs
    Aug 10
    A ClickFix case brought our team down a BabaDeda chain that led to an undocumented end: CNCMachineRMS, a 1.14 MB RAT with zero imports, every string built on the stack, and its own scripting language. The full research + PDF report below. ⤵️
    levelblue.com
    CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
    This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn't expect.
  • @SpiderLabs
    SpiderLabs
    @SpiderLabs
    Jul 17
    🪝#Phishing Alert: LevelBlue #MailMarshal has detected a phishing campaign targeting hotels, venues, and wedding service providers. Threat actors are sending convincing fake business inquiries covering wedding venues, event planning, and related services to trick recipients into
    Image
  • @SpiderLabs
    SpiderLabs
    @SpiderLabs
    Jul 16
    Some teams follow alerts. SpiderLabs follows behavior, patterns, intent, and instinct, long before it reaches your environment. 🕷️💡 Precision matters when threats evolve overnight.   Take a closer look at how that kind of visibility shows up in the real world. ⤵️
    Image
    00:00
  • @SpiderLabs
    SpiderLabs
    @SpiderLabs
    Jul 15
    Our gift to you: we have decided to do something for the community, with the hopes that more security vendors follow suit. We've been developing an advanced open-source Linux engine - dubbed owLSM - and have made it accessible for free, just for YOU. Meet owLSM: ⭐ A full Sigma
    Image
Advertisement
Advertisement