<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>IONSEC Resources</title><description>Real-world cyber attacks, expert analysis, and the latest security trends from the IONSEC incident response team.</description><link>https://www.ionsec.io</link><language>en-us</language><item><title>Coercion to krbtgt: NTLM Relay and ADCS ESC8 in 2026</title><link>https://www.ionsec.io/resources/coercion-to-krbtgt-ntlm-relay-and-adcs-esc8-in-2026</link><guid isPermaLink="true">https://www.ionsec.io/resources/coercion-to-krbtgt-ntlm-relay-and-adcs-esc8-in-2026</guid><description>A full ESC8 walkthrough against a lab domain, then the forensic reconstruction — why the certificate serial, not the source IP, is the artifact that ties the whole chain together.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>Article</category><category>adcs</category><category>esc8</category><category>ntlm-relay</category><category>active-directory</category><category>dfir</category><category>threat-intelligence</category><author>IONSEC Team</author></item><item><title>The 60-Minute Site: Phishing That Deletes Its Own Evidence</title><link>https://www.ionsec.io/resources/cloudflare-drop-60-minute-phishing</link><guid isPermaLink="true">https://www.ionsec.io/resources/cloudflare-drop-60-minute-phishing</guid><description>Cloudflare Drop publishes a site on a trusted workers.dev address with no account, then deletes it after an hour. That one-hour fuse burns your forensic evidence with it.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>Blog</category><category>phishing</category><category>cloudflare</category><category>detection-engineering</category><category>threat-hunting</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>MAES: The M365 Analyzer &amp; Extractor Suite</title><link>https://www.ionsec.io/resources/maes-the-m365-analyzer-extractor-suite</link><guid isPermaLink="true">https://www.ionsec.io/resources/maes-the-m365-analyzer-extractor-suite</guid><description>At IONSEC, we’re excited to introduce MAES: The M365 Analyzer &amp; Extractor Suite — an open-source platform purpose-built to simplify and accelerate Microsoft 365 (M365) forensic investigations.</description><pubDate>Wed, 20 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>dfir</category><category>microsoft-365</category><category>cloud-forensics</category><author>IONSEC Team</author></item><item><title>Tikun13 Checker – כלי קוד פתוח לבדיקת יישום תיקון 13</title><link>https://www.ionsec.io/resources/tikun13checker</link><guid isPermaLink="true">https://www.ionsec.io/resources/tikun13checker</guid><description>Tikun13 Checker הוא כלי קוד פתוח, מבוסס דפדפן, שפותח על ידי IONSEC כדי לסייע לארגונים בישראל ליישם את דרישות תיקון 13 לחוק הגנת הפרטיות.</description><pubDate>Sun, 17 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>compliance</category><category>privacy</category><category>tikun-13</category><category>israel</category><author>IONSEC Team</author></item><item><title>DO Audit Log Scraper v2.0</title><link>https://www.ionsec.io/resources/do-audit-log-scraper-v2-0</link><guid isPermaLink="true">https://www.ionsec.io/resources/do-audit-log-scraper-v2-0</guid><description>The DO Audit Log Scraper is a Chrome/Chromium extension that enables forensic-grade audit log extraction.</description><pubDate>Mon, 11 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>dfir</category><category>audit-logs</category><category>digitalocean</category><author>IONSEC Team</author></item><item><title>FlareInspect - Cloudflare Assessment Tool</title><link>https://www.ionsec.io/resources/flareinspect</link><guid isPermaLink="true">https://www.ionsec.io/resources/flareinspect</guid><description>FlareInspect is a CLI-based assessment framework designed to revolutionize how organizations evaluate and monitor their Cloudflare security posture.</description><pubDate>Sun, 03 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>cloudflare</category><category>cloud-security</category><category>security-assessment</category><author>IONSEC Team</author></item><item><title>Forti-DFIR: Open-Source Framework for Fortinet Forensics &amp; Incident Response</title><link>https://www.ionsec.io/resources/forti-dfir-open-source-framework-for-fortinet-forensics-incident-response</link><guid isPermaLink="true">https://www.ionsec.io/resources/forti-dfir-open-source-framework-for-fortinet-forensics-incident-response</guid><description>At IONSEC, we’re proud to introduce Forti-DFIR — an open-source initiative created to give security teams the tools they need for forensic investigations and incident response in Fortinet environments.</description><pubDate>Fri, 01 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>dfir</category><category>fortinet</category><category>network-forensics</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>When Research Meets Reality</title><link>https://www.ionsec.io/resources/when-research-meets-reality</link><guid isPermaLink="true">https://www.ionsec.io/resources/when-research-meets-reality</guid><description>How Threat-Actor Campaigns Cast a Shadow on Legitimate npm Binaries (and What IONSEC IR Sees in the wild)</description><pubDate>Sun, 06 Jul 2025 00:00:00 GMT</pubDate><category>Case Study</category><category>supply-chain</category><category>npm</category><category>threat-intelligence</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>How a Weaponized Zoom Installer Opened the Door for BlueNoroff</title><link>https://www.ionsec.io/resources/how-a-weaponized-zoom-installer-opened-the-door-for-bluenoroff</link><guid isPermaLink="true">https://www.ionsec.io/resources/how-a-weaponized-zoom-installer-opened-the-door-for-bluenoroff</guid><description>IONSEC investigates a BlueNoroff intrusion that began with a weaponized Zoom installer, combining deepfakes, social engineering and evasive scripting.</description><pubDate>Thu, 03 Jul 2025 00:00:00 GMT</pubDate><category>Case Study</category><category>bluenoroff</category><category>apt</category><category>social-engineering</category><category>incident-response</category><category>macos</category><author>IONSEC Team</author></item><item><title>Iranian Threat Actor Hijacks DNS</title><link>https://www.ionsec.io/resources/iranian-threat-actor-hijacks-dns</link><guid isPermaLink="true">https://www.ionsec.io/resources/iranian-threat-actor-hijacks-dns</guid><description>קבוצת התקיפה האיראנית פתח אלקודס פרצה לרשם דומיינים ישראלי ושינתה רשומות DNS ו-MX של יותר מ-1,000 דומיינים, והפנתה אותם לשרת זדוני ולדף תעמולה.</description><pubDate>Wed, 02 Jul 2025 00:00:00 GMT</pubDate><category>Case Study</category><category>dns-hijacking</category><category>iran</category><category>apt</category><category>incident-response</category><category>israel</category><author>IONSEC Team</author></item><item><title>RansomProtect – Open-Source Defense Against Ransomware &amp; Wipers</title><link>https://www.ionsec.io/resources/ransomprotect---open-source-defense-against-ransomware-wipers</link><guid isPermaLink="true">https://www.ionsec.io/resources/ransomprotect---open-source-defense-against-ransomware-wipers</guid><description>RansomProtect is our open-source tool that detects and blocks ransomware and wipers early in the infection chain, where built-in OS defenses fall short.</description><pubDate>Tue, 01 Jul 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>ransomware</category><category>wiper</category><category>endpoint-security</category><author>IONSEC Team</author></item><item><title>IONSEC at the IMPROVATE CISO Summit</title><link>https://www.ionsec.io/resources/ionsec-at-the-improvate-ciso-summit</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-at-the-improvate-ciso-summit</guid><description>Two months ago, IONSEC had the privilege of participating in the CISO Summit by IMPROVATE — a premier platform for connecting with Israel’s leading cybersecurity executives and security professionals.</description><pubDate>Mon, 30 Jun 2025 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>conference</category><category>ciso</category><author>IONSEC Team</author></item><item><title>LIVE from GISEC Global 2025 – Israeli Pavilion</title><link>https://www.ionsec.io/resources/gisec-2025</link><guid isPermaLink="true">https://www.ionsec.io/resources/gisec-2025</guid><description>IONSEC is proud to showcase an exclusive preview of our next-generation Digital Forensics and Incident Response (DFIR) platform at GISEC Global 2025, one of the world’s premier cybersecurity events in Dubai.</description><pubDate>Tue, 06 May 2025 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>gisec</category><category>conference</category><author>IONSEC Team</author></item><item><title>Why Malware Analysis Training is Vital: Lessons from Real-World Cyber Attacks</title><link>https://www.ionsec.io/resources/why-malware-analysis-training-is-vital-lessons-from-real-world-cyber-attacks</link><guid isPermaLink="true">https://www.ionsec.io/resources/why-malware-analysis-training-is-vital-lessons-from-real-world-cyber-attacks</guid><description>Picture this: airport metal detectors efficiently catch large, obvious weapons, but small components slip through unnoticed. Once inside, attackers assemble them into a complete weapon.</description><pubDate>Wed, 11 Dec 2024 00:00:00 GMT</pubDate><category>Article</category><category>malware-analysis</category><category>training</category><category>awareness</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>IONSEC at HackExpo 2024 – Breach at the Frontline</title><link>https://www.ionsec.io/resources/ionsec-at-hackexpo-2024---breach-at-the-frontline</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-at-hackexpo-2024---breach-at-the-frontline</guid><description>At HackExpo 2024, IONSEC CEO Nir Halfon shared practical strategies for responding to exploits in fintech first-party applications under live pressure.</description><pubDate>Thu, 28 Nov 2024 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>conference</category><category>incident-response</category><category>fintech</category><author>IONSEC Team</author></item><item><title>Reverse Engineering GodPotato (MSASCui.exe)</title><link>https://www.ionsec.io/resources/reverse-engineering-godpotato-msascui-exe</link><guid isPermaLink="true">https://www.ionsec.io/resources/reverse-engineering-godpotato-msascui-exe</guid><description>Privilege escalation is a critical technique employed by attackers to gain unauthorized access to higher system privileges, often leading to significant security breaches.</description><pubDate>Sun, 10 Nov 2024 00:00:00 GMT</pubDate><category>Blog</category><category>reverse-engineering</category><category>privilege-escalation</category><category>windows</category><category>malware-analysis</category><author>IONSEC Team</author></item><item><title>Clearing the Mist: Unveiling Fog Ransomware</title><link>https://www.ionsec.io/resources/clearing-the-mist-unveiling-fog-ransomware</link><guid isPermaLink="true">https://www.ionsec.io/resources/clearing-the-mist-unveiling-fog-ransomware</guid><description>A full analysis of the Fog Ransomware Group: the malware it deploys, the TTPs it relies on to infiltrate high-tech firms, and how defenders can disrupt it.</description><pubDate>Sun, 25 Aug 2024 00:00:00 GMT</pubDate><category>Blog</category><category>ransomware</category><category>malware-analysis</category><category>threat-intelligence</category><category>ttps</category><author>IONSEC Team</author></item><item><title>IONSEC Joins the 3rd MIRROR Forum with INCD</title><link>https://www.ionsec.io/resources/ionsec-joins-the-3rd-mirror-forum-with-incd</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-joins-the-3rd-mirror-forum-with-incd</guid><description>On June 28, IONSEC proudly participated in the third MIRROR Forum — a unique gathering of 15 Incident Response (IR) companies across Israel, convened by the Israel National Cyber Directorate (INCD).</description><pubDate>Fri, 28 Jun 2024 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>incd</category><category>collaboration</category><author>IONSEC Team</author></item><item><title>IONSEC Shares Wiper Malware Research with Czech Delegation in Israel</title><link>https://www.ionsec.io/resources/ionsec-shares-wiper-malware-research-with-czech-delegation-in-israel</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-shares-wiper-malware-research-with-czech-delegation-in-israel</guid><description>IONSEC hosted a Czech delegation in Israel to present our Wiper malware research, including the campaign we track as Operation HANDALA.</description><pubDate>Sun, 02 Jun 2024 00:00:00 GMT</pubDate><category>News</category><category>wiper</category><category>malware-analysis</category><category>operation-handala</category><category>threat-intelligence</category><category>events</category><author>IONSEC Team</author></item><item><title>IONSEC at GPEC 2024 – Showcasing APT Research on the Global Stage</title><link>https://www.ionsec.io/resources/ionsec-at-gpec-2024---showcasing-apt-research-on-the-global-stage-98do0-brms0</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-at-gpec-2024---showcasing-apt-research-on-the-global-stage-98do0-brms0</guid><description>Wow — what a journey GPEC (General Police Equipment Exhibition &amp; Conference) was this year. Standing among 471 exhibitors from 32 different countries was nothing short of inspiring. The scale, the diversity, and the energy of the event made it a true highlight of 2024.</description><pubDate>Wed, 08 May 2024 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>conference</category><category>apt</category><category>threat-intelligence</category><author>IONSEC Team</author></item><item><title>SovaTeam - New State-Sponsored APT</title><link>https://www.ionsec.io/resources/sovateam---new-state-sponsored-apt</link><guid isPermaLink="true">https://www.ionsec.io/resources/sovateam---new-state-sponsored-apt</guid><description>How IONSEC and White-Hat traced the Sova Team threat actor through a ransom note to uncover a state-sponsored APT operating past strict security controls.</description><pubDate>Sun, 31 Mar 2024 00:00:00 GMT</pubDate><category>Blog</category><category>apt</category><category>ransomware</category><category>threat-intelligence</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>סקירה מודיעינית 2024 #OpIsrael</title><link>https://www.ionsec.io/resources/sqyrh-mvdy-ynyt-2024-opisrael</link><guid isPermaLink="true">https://www.ionsec.io/resources/sqyrh-mvdy-ynyt-2024-opisrael</guid><description>IONSEC הינה חברת בוטיק לשירותי אבטחת מידע ותגובה לאירועי סייבר (24/7) העוסקת במחקר ותגובה לאיומים מתקדמים ומספקת פתרונות אבטחה מותאמים אישית לחברות ברחבי העולם.</description><pubDate>Sun, 24 Mar 2024 00:00:00 GMT</pubDate><category>Blog</category><category>opisrael</category><category>threat-intelligence</category><category>hacktivism</category><category>israel</category><author>IONSEC Team</author></item></channel></rss>