IONSEC

Open source · APT research

The work behind the retainer.

Six open-source DFIR tools, published research on state-sponsored actors, and the forums where we present it. Free to use, free to read, no gate.

Threat research

Campaigns we tracked, actors we named, and intrusions we took apart — written up in full.

ArticleCoercion to krbtgt: NTLM Relay and ADCS ESC8 in 2026A full ESC8 walkthrough against a lab domain, then the forensic reconstruction — why the certificate serial, not the source IP, is the artifact that ties the whole chain together.Jul 2026 · 15 minBlogThe 60-Minute Site: Phishing That Deletes Its Own EvidenceCloudflare Drop publishes a site on a trusted workers.dev address with no account, then deletes it after an hour. That one-hour fuse burns your forensic evidence with it.Jul 2026 · 6 minCase StudyWhen Research Meets RealityHow Threat-Actor Campaigns Cast a Shadow on Legitimate npm Binaries (and What IONSEC IR Sees in the wild)Jul 2025 · 8 minCase StudyHow a Weaponized Zoom Installer Opened the Door for BlueNoroffIONSEC investigates a BlueNoroff intrusion that began with a weaponized Zoom installer, combining deepfakes, social engineering and evasive scripting.Jul 2025 · 8 minCase StudyIranian Threat Actor Hijacks DNSקבוצת התקיפה האיראנית פתח אלקודס פרצה לרשם דומיינים ישראלי ושינתה רשומות DNS ו-MX של יותר מ-1,000 דומיינים, והפנתה אותם לשרת זדוני ולדף תעמולה.Jul 2025 · 9 minArticleWhy Malware Analysis Training is Vital: Lessons from Real-World Cyber AttacksPicture this: airport metal detectors efficiently catch large, obvious weapons, but small components slip through unnoticed. Once inside, attackers assemble them into a complete weapon.Dec 2024 · 1 minBlogReverse Engineering GodPotato (MSASCui.exe)Privilege escalation is a critical technique employed by attackers to gain unauthorized access to higher system privileges, often leading to significant security breaches.Nov 2024 · 4 minBlogClearing the Mist: Unveiling Fog RansomwareA full analysis of the Fog Ransomware Group: the malware it deploys, the TTPs it relies on to infiltrate high-tech firms, and how defenders can disrupt it.Aug 2024 · 5 minNewsIONSEC Shares Wiper Malware Research with Czech Delegation in IsraelIONSEC hosted a Czech delegation in Israel to present our Wiper malware research, including the campaign we track as Operation HANDALA.Jun 2024 · 1 minBlogSovaTeam - New State-Sponsored APTHow IONSEC and White-Hat traced the Sova Team threat actor through a ransom note to uncover a state-sponsored APT operating past strict security controls.Mar 2024 · 8 minBlogסקירה מודיעינית 2024 #OpIsraelIONSEC הינה חברת בוטיק לשירותי אבטחת מידע ותגובה לאירועי סייבר (24/7) העוסקת במחקר ותגובה לאיומים מתקדמים ומספקת פתרונות אבטחה מותאמים אישית לחברות ברחבי העולם.Mar 2024 · 10 min