top of page

From 1 to 5: How We Mapped a Post-Operation Endgame C2 Infrastructure
From 1 to 5: How We Mapped a Post-Operation Endgame C2 Infrastructure
Patrick Duggan
Nov 26, 20254 min read
Pattern 43: The Password is in the Filename
Pattern 43: The Password is in the Filename
Patrick Duggan
Nov 26, 20253 min read
The Mentat's Analysis: Who's Behind Pattern 38?
For the uninitiated: In Frank Herbert's Dune universe, a Mentat is a human trained to perform computer-like analysis after thinking machines were banned. They c
Patrick Duggan
Nov 25, 20255 min read
Dear GitHub Security: You're Welcome
*An open letter to the team that suspends accounts but doesn't return calls*
Patrick Duggan
Nov 25, 20254 min read
Follow the Followers: Unraveling GitHub's Shadow Social Graph
*How recursive network analysis exposed a coordinated follow-farm connected to supply chain attacks*
Patrick Duggan
Nov 25, 20255 min read
Stealc/Rhadamanthys: Anatomy of a GitHub Supply Chain Infostealer
We caught an information stealer campaign distributing malware through GitHub issue comments. This post documents the complete technical analysis: the malware f
Patrick Duggan
Nov 25, 20255 min read
Pattern 38: Building an Automated Supply Chain Attack Disclosure Pipeline
Here's a scenario that's becoming disturbingly common:
Patrick Duggan
Nov 25, 20254 min read
Pattern 41: The Mechanical Horde - Automated Repository Saturation
While investigating GitHub supply chain threats (Pattern 38), we discovered something peculiar: accounts creating hundreds of repositories with **mechanical pre
Patrick Duggan
Nov 24, 20253 min read
Rhyme of the Anusfragger: When Supply Chain Defense Meets 80's Metal
Rhyme of the Anusfragger: When Supply Chain Defense Meets 80's Metal
Patrick Duggan
Nov 24, 20256 min read
We Found Their Server: Pattern #38 C2 Infrastructure Exposed
We Found Their Server: Pattern #38 C2 Infrastructure Exposed
Patrick Duggan
Nov 24, 20255 min read
Pattern #38: GitHub Supply Chain Attacks Use Stolen Developer Credentials from 2023 Breaches
Pattern #38 supply chain attacks on GitHub use **two distinct account types**, not one:
Patrick Duggan
Nov 23, 20255 min read
Thank You, ANUSFRAGGER: How Attacking My Partner Saved Microsoft
Thank You, ANUSFRAGGER: How Attacking My Partner Saved Microsoft
Patrick Duggan
Nov 23, 202511 min read
Hall of Shame: FireSuper - GitHub Supply Chain Sleeper Account
Hall of Shame: FireSuper - GitHub Supply Chain Sleeper Account
Patrick Duggan
Nov 23, 20256 min read
They Picked the Wrong Day: Supply Chain Attack on Active Threat Intel Researcher
They Picked the Wrong Day: Supply Chain Attack on Active Threat Intel Researcher
Patrick Duggan
Nov 23, 20258 min read
UNC6395: I Told You So (The Breach That Won't Stop Breaching)
UNC6395: I Told You So (The Breach That Won't Stop Breaching)
Patrick Duggan
Nov 23, 20255 min read
When Attackers Have Better OpSec Than You (The Death of HTTP)
When Attackers Have Better OpSec Than You (The Death of HTTP)
Patrick Duggan
Nov 23, 20259 min read
When Dropping Your Shields Reveals Attack Infrastructure (The SSL/TLS Honeypot Strategy)
When Dropping Your Shields Reveals Attack Infrastructure (The SSL/TLS Honeypot Strategy)
Patrick Duggan
Nov 23, 20258 min read
We Don't Discover Threats. We Prove We Can Reproduce What Enterprise Systems Detect. (And That's Better.)
We Don't Discover Threats. We Prove We Can Reproduce What Enterprise Systems Detect. (And That's Better.)
Patrick Duggan
Nov 22, 20256 min read
I Tracked Who's Consuming Our Free Threat Intel Feed. The Results Got Creepy.
I Tracked Who's Consuming Our Free Threat Intel Feed. The Results Got Creepy.
Patrick Duggan
Nov 22, 20258 min read
When Microsoft, Google, and Cloudflare Download Your Threat Intel (And You're Just a Guy in Minnesota)
When Microsoft, Google, and Cloudflare Download Your Threat Intel (And You're Just a Guy in Minnesota)
Patrick Duggan
Nov 22, 20256 min read
bottom of page