1. X
  2. Tony Lambert
Log inSign up
Tony Lambert
3,871 posts
Image
user avatar
Tony Lambert
@ForensicITGuy
Recovering sysadmin that now chases adversaries instead of uptime. Sr Malware Analyst @redcanary
Tennessee
forensicitguy.github.io
Joined November 2011
1,220
Following
6,041
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    Tony Lambert
    @ForensicITGuy
    Dec 9, 2025
    Sometimes adversaries bring in their own tools, and if they leave behind a VM disk, analysis is fair game. In this post we look at some tools an adversary brought during a social engineering campaign.
    redcanary.com
    When adversaries bring their own virtual machine for persistence
    We peel back the layers on a threat involving an adversary who brought their own VM into an environment following aggressive spam bombing.
    1.1K
  • user avatar
    Tony Lambert
    @ForensicITGuy
    Oct 10, 2025
    It's not just you, most of the macOS stealers look the same nowadays, but there are subtle differences between stealer families to tell them apart. If you're a stickler for detail like us, you might enjoy this post showing differences between the malware.
    Image
    Distinguishing Atomic, Odyssey, and Poseidon stealers on macOS
    From redcanary.com
    5.3K
  • user avatar
    Tony Lambert
    @ForensicITGuy
    May 19, 2025
    Do you miss @cobaltstrikebot? If so, here's a blog post showing how you can pull Cobalt Strike SpawnTo and watermark info with @shodanhq and some PowerShell:
    Lemony Fresh Shodan Data
    Squeezing Cobalt Strike Threat Intelligence from Shodan
    From forensicitguy.github.io
    10K
  • user avatar
    Tony Lambert
    @ForensicITGuy
    Jan 18, 2025
    The first step to getting robust detections is writing brittle ones that get bypassed and finding out in a red team report.
    user avatar
    Nasreddine Bencherchali
    @nas_bench
    Jan 17, 2025
    Happy Friday 😁
    Image
    2.2K
  • user avatar
    Tony Lambert
    @ForensicITGuy
    Jan 3, 2025
    New blog post for #100DaysofYARA , in this one I look at a VenomRAT sample and create rules based on PE metadata and an encryption salt value. forensicitguy.github.io/exploring-veno… #malware
    VenomRAT
    Exploring VenomRAT Metadata and Encryption with YARA - #100DaysOfYara
    From forensicitguy.github.io
    6.5K
  • See @ForensicITGuy's full profile

    Sign up
    Log in
Advertisement
Advertisement