top of page

All Posts
Free Threat Intel for Canada: 37 IOCs for Eh-Holes Targeting the True North
Free Threat Intel for Canada: 37 IOCs for Eh-Holes Targeting the True North
Patrick Duggan
Nov 30, 20254 min read
Â
Â
Â
Free Threat Intel for Charities: 37 IOCs for Non-Profits Under Siege
Free Threat Intel for Charities: 37 IOCs for Non-Profits Under Siege
Patrick Duggan
Nov 30, 20254 min read
Â
Â
Â
Free Threat Intel for Schools: 34 IOCs for K-12 and Universities Under Siege
Free Threat Intel for Schools: 34 IOCs for K-12 and Universities Under Siege
Patrick Duggan
Nov 30, 20253 min read
Â
Â
Â
Free Threat Intel for Financial Services: 80+ IOCs Covering SOX, Chinese Walls, and Ransomware
Free Threat Intel for Financial Services: 80+ IOCs Covering SOX, Chinese Walls, and Ransomware
Patrick Duggan
Nov 30, 20254 min read
Â
Â
Â
Free Threat Intel for Minnesota Healthcare: 60 IOCs You Can Block Today
Free Threat Intel for Minnesota Healthcare: 60 IOCs You Can Block Today
Patrick Duggan
Nov 30, 20253 min read
Â
Â
Â
Hunting Supply Chain Attacks While Getting Supply Chain Attacked
Hunting Supply Chain Attacks While Getting Supply Chain Attacked
Patrick Duggan
Nov 30, 20252 min read
Â
Â
Â
The Magic Quadrant for People Who Can't Afford Magic
The Magic Quadrant for People Who Can't Afford Magic
Patrick Duggan
Nov 28, 20254 min read
Â
Â
Â
Ten Days of Threat Hunting: Nov 19-29, 2025
Ten Days of Threat Hunting: Nov 19-29, 2025
Patrick Duggan
Nov 28, 20253 min read
Â
Â
Â
Hitting Miscreants with a New Stick: MITRE Inference Engine 2.0
Hitting Miscreants with a New Stick: MITRE Inference Engine 2.0
Patrick Duggan
Nov 27, 20253 min read
Â
Â
Â
From 1 to 5: How We Mapped a Post-Operation Endgame C2 Infrastructure
From 1 to 5: How We Mapped a Post-Operation Endgame C2 Infrastructure
Patrick Duggan
Nov 26, 20254 min read
Â
Â
Â
Pattern 43: The Password is in the Filename
Pattern 43: The Password is in the Filename
Patrick Duggan
Nov 26, 20253 min read
Â
Â
Â
The Mentat's Analysis: Who's Behind Pattern 38?
For the uninitiated: In Frank Herbert's Dune universe, a Mentat is a human trained to perform computer-like analysis after thinking machines were banned. They c
Patrick Duggan
Nov 25, 20255 min read
Â
Â
Â
Dear GitHub Security: You're Welcome
*An open letter to the team that suspends accounts but doesn't return calls*
Patrick Duggan
Nov 25, 20254 min read
Â
Â
Â
Follow the Followers: Unraveling GitHub's Shadow Social Graph
*How recursive network analysis exposed a coordinated follow-farm connected to supply chain attacks*
Patrick Duggan
Nov 25, 20255 min read
Â
Â
Â
Stealc/Rhadamanthys: Anatomy of a GitHub Supply Chain Infostealer
We caught an information stealer campaign distributing malware through GitHub issue comments. This post documents the complete technical analysis: the malware f
Patrick Duggan
Nov 25, 20255 min read
Â
Â
Â
Pattern 38: Building an Automated Supply Chain Attack Disclosure Pipeline
Here's a scenario that's becoming disturbingly common:
Patrick Duggan
Nov 25, 20254 min read
Â
Â
Â
Pattern 41: The Mechanical Horde - Automated Repository Saturation
While investigating GitHub supply chain threats (Pattern 38), we discovered something peculiar: accounts creating hundreds of repositories with **mechanical pre
Patrick Duggan
Nov 24, 20253 min read
Â
Â
Â
Rhyme of the Anusfragger: When Supply Chain Defense Meets 80's Metal
Rhyme of the Anusfragger: When Supply Chain Defense Meets 80's Metal
Patrick Duggan
Nov 24, 20256 min read
Â
Â
Â
We Found Their Server: Pattern #38 C2 Infrastructure Exposed
We Found Their Server: Pattern #38 C2 Infrastructure Exposed
Patrick Duggan
Nov 24, 20255 min read
Â
Â
Â
Pattern #38: GitHub Supply Chain Attacks Use Stolen Developer Credentials from 2023 Breaches
Pattern #38 supply chain attacks on GitHub use **two distinct account types**, not one:
Patrick Duggan
Nov 23, 20255 min read
Â
Â
Â
bottom of page