PacketWatch @packetwatch
PacketWatch utilizes packet-level network analysis and proactive human-based threat hunting to find risks that conventional cybersecurity tools may miss. packetwatch.com Scottsdale, AZ Joined March 2018-
Tweets211
-
Followers32
-
Following26
-
Likes14
6/16/26 packetwatch.com/resources/thre… - PacketWatch's Team Sixty43 profiles how a ClickFix attack leverages the finger protocol to deliver its first payload (CastleLoader). See the TTPs and IOCs. #clickfix #castleloader #threatprofile #threatintelligence #threathunting #cybersecurity #phishing #dfir #networksecurity #informationsecurity #teamsixty43
6/15/26 packetwatch.com/resources/thre… - This week, we briefed our clients on the new Ghost-sender Email Spoofing research from InfoGuard Labs. Be sure to test your domain for the vulnerability. #cybersecurity #threatintelligence #threathunting #informationsecurity #networksecurity #ransomware #malware #dfir
6/1/26 packetwatch.com/resources/thre… - This week, we briefed our clients on new social engineering attacks targeting law firms. The Silent Ransomware Group has been showing up in person. #cybersecurity #threatintelligence #threathunting #informationsecurity #networksecurity #ransomware #malware #dfir
PacketWatch's Team Sixty43 profiles an M365 threat traced to Device Code Phishing, complete with tactics, techniques, and procedures. packetwatch.com/resources/thre… #malware #threatprofile #threatintelligence #threathunting #cybersecurity #devicecodephishing #phishing #dfir #networksecurity #informationsecurity #teamsixty43
While hunting for anomalous RMMs in a healthcare organization, #TeamSixty43 identified #ScreenConnect traffic from an unmanaged endpoint. We immediately kicked off an investigation, as rogue RMMs are almost never a good thing and are often leveraged by various criminal actors, such as #ransomware groups. Forensic analysis of the device revealed that the user had fallen for a fake IRS-themed phishing attack. Based on Team Sixty43’s analysis, this was most likely an Initial Access Broker who was quietly and slowly staging. They brought in tools such as #HideUL to hide evidence of their presence, and deleted event logs, tools, and parts of the browser's history. Criminal operators do not need exploits, AI, or fancy tactics. They exploit the obvious gaps in security: unmanaged devices, tight IT budgets, and social engineering. And traditional controls alone are no longer sufficient. - Firewalls do not block #RMM traffic by default. - Network logs only capture a fraction of your network's data. - EDRs often fail to alert on rogue RMM activity because IT teams need to use them. - Email filters allow phishing emails from trusted vendors. You need to control what RMMs are allowed to run in your environment and monitor the network for signs of rogue RMMs. Only proactive threat hunting using Full Packet Capture can identify the subtle signs of these risks before they reach endgame. Team Sixty43 used PacketWatch platform data to identify the suspicious ScreenConnect traffic, pinpoint the source hostname of the unmanaged device, and retroactively hunt for signs of lateral movement—all within minutes. Below are the IOCs our team collected from the incident. Your team can use these to hunt for this threat in your environment, too. +++ IOCs +++ store-na-phx-1.gofile[.]io (download link for ScreenConnect) pub-e468619e47134d1e942f5a4c5dba818b.r2[.]dev (download URL for ScreenConnect) superops-wininstaller-prod.s3.us-east-2.amazonaws[.]com (SuperOps download link) acosigin[.]cc (phishing link) instance-sr3d21-relay.screenconnect[.]com (ScreenConnect Relays) relay.gnmstechome[.]top (ScreenConnect Relays) relay.sslenfftechio[.]top (ScreenConnect Relays) +++ #threathunting #dfir #cybersurity #informationsecurity #threatintelligence #networksecurity
5/18/26 packetwatch.com/resources/thre… - This week, we briefed our clients on the recent increase in Device Code Phishing attacks and how to protect themselves, starting with Microsoft 365. #cybersecurity #threatintelligence #threathunting #informationsecurity #networksecurity #ransomware #malware #dfir
From Andy O. on PacketWatch's #TeamSixty43: Happy Friday! I wanted to share a quick threat-hunting tip: hunt for cleartext LDAP in your networks. One of the best ways to do this is through using Full Packet Capture. Using PacketWatch's FPC session data, you can run the query "ldap.authtype:simple". What this does is looks for the value "simple" in LDAP authentication. In LDAP, simple authentication is, if you will, simply authenticating by sending the LDAP server your FQDN and your password.... in cleartext. You might say "wow, that's crazy, why would anyone ever do that?" That's the thing, every time I run this hunt and find cleartext LDAP credentials in simple authentication, the client's IT and security teams are never aware of it. When I pull up PacketWatch or Wireshark to show them the password of a domain admin account, they are always shocked. "We never knew this system was doing this..." Based on Team Sixty43's research and data from the hunts we have run, these simple LDAP authentications are often caused by bad default configurations for firewall LDAP integrations to Active Directory. Many firewalls can use LDAP to do user lookups to help authenticate users via VPN. There are many issues with this alone, but there are reasons organizations choose this, which is a different subject. And, based on our findings, it is every major firewall vendor - PAN, SonicWall, Fortinet, Cisco, etc. Outside of insecure default configurations of firewalls/VPNs, we also see it when other LDAP integrations are not properly secured, like IT management systems and AD management software. And, in almost every case, they are leaking domain admin credentials or service accounts with DA. The fix for this is enforcing LDAPS, or at minimum, SASL authentication for LDAP. The implementation varies per vendor unfortunately. This is absolutely a goldmine for threat actors. Why dump LSASS when the network has DA creds floating in it? This is why when clients onboard at PacketWatch, we run a full security assessment to find critical issues like cleartext LDAP and fix them ASAP. If you want to see if your network is leaking credentials in cleartext LDAP, or has other hidden vulnerabilities, please hit us up PacketWatch!! We can run a Network Security Assessment and give you full network visibility with our Rapid Response Assurance! #threathunting #cybersecurity #networksecurity #informationsecurity #dfir #passwords
PacketWatch's Team Sixty43 profiles a threat involving EvilAI and Vibe-coded malware, complete with tactics, techniques, and procedures. packetwatch.com/resources/thre… #malware #threatprofile #threatintelligence #threathunting #cybersecurity #evilai #vibecoding #powershell #dfir #networksecurity #informationsecurity #teamsixty43
PacketWatch's #TeamSixty43 profiles a threat packetwatch.com/resources/thre… involving the toxic trio #KongTuke, #ClickFix, and #Havoc, complete with tactics, techniques, and procedures. #ransomware #malware #threatprofile #threatintelligence #threathunting #cybersecurity #informationsecurity #dfir
5/4/26 packetwatch.com/resources/thre… - This week, we briefed our clients on the second-most-active Ransomware-as-a-Service organization, The Gentleman. We describe their observed TTPs. #cybersecurity #threatintelligence #threathunting #informationsecurity #networksecurity #ransomware #malware #dfir
PacketWatch's #TeamSixty43 has detected a new #ClickFix campaign. This campaign lures victims in with a #FakeCaptcha to solve that tricks the user into running a malicious PowerShell script that installs #Vidar Stealer onto the victim's machine. Below is a list of #IOCs our team has recovered from these incidents. It is recommended to block these domains. If you are a #PacketWatch client, rest assured that our threat hunt team has run hunts to identify any sign of this campaign in your environment. +++ IOCs +++ FakeCaptcha > Vidar Windows Terminal > PowerShell > [random characters].exe pohuimne[.]lol (payload) noscalpelvasectomy[.]com (FakeCaptcha) productionmaza[.]cfd (C2) prokladka[.]lol (payload) dtc.victorramarisimobiliaria[.]com[.]br (C2) +++ #threathunting #dfir #cybersurity #informationsecurity #threatintelligence
Threat Profile: packetwatch.com/resources/thre… PacketWatch Team Sixty43 provides extensive profile on Lynx Ransomware and its tactics, techniques, and procedures. #teamsixty43 #lynx #ransomware #threatprofile #threatintelligence #threathunting #cybersecurity #informationsecurity #dfir
4/20/26 packetwatch.com/resources/thre… - This week, we briefed our clients on Anthropic's announcement of Claude Mythos Preview and its alleged ability to discover and exploit vulnerabilities. #cybersecurity #threatintelligence #threathunting #informationsecurity #networksecurity #dfir
PacketWatch Threat Intelligence: Windows Downgrade Attack, National Public Data Leak, More: hubs.li/Q02K-9Kw0
GitHub Access Concerns, CrowdStrike Scams, and more in our latest #ThreatIntel report on July 29, 2024: hubs.li/Q02JhL050
Read our latest #ThreatIntel report: Microsoft MHTML Zero-Day, Rockyou2024, and More hubs.li/Q02GF-s50
CEO Vantage Point: Partners are More than Vendors Read now: hubs.li/Q02FJBJ20 #cybersecurity
A GrimResource Breakdown and a Vulnerability Roundup: hubs.li/Q02DZ8Nq0
"In the race to get systems back online after a #ransomware incident, organizations tend to 'jump the gun.' But remember, Eradication comes before Recovery in the SANS Incident Response (IR) Framework," says PacketWatch CEO Chuck Matthews. hubs.li/Q02D3brb0
#ThreatIntel 🔒 Stay ahead of #cybersecurity threats with our latest insights: hubs.li/Q02C6-FX0
Igor Os @igor_os777
24K Followers 23K Following Experienced #Unix and #Linux #SysAdmin with over twenty years background in Systems Analysis, Problem Resolution, Application Support, and Process #Automation.
Hud @DeltaCatt26
0 Followers 20 Following
Shane Connor @shanetconnor
211 Followers 2K Following Engineer of code & chaos ⚡💻. Writer of worlds ✍️📖. Rider of roads 🏍️🌄.
Maria @Maria9514usa
31 Followers 722 Following Business owner, single, outgoing, outdoorsy, beach lover🚫pornography
Preston Moore @prstnmr
168 Followers 837 Following I help districts + early learning programs turn behavior challenges into better outcomes. Director of Partnerships - East @ Housman Learning
Muhammad Hendro @hendro_jun
338 Followers 2K Following
Shaquib Izhar @saquib_izhar
112 Followers 2K Following \x4d\x63\x69\x27\x66\x73\x20\x67\x64\x73\x71\x77\x6f\x7a
CHA Minseok(Jacky) @mstoned7
3K Followers 5K Following CHA is my family name. Threat Intelligence Researcher at AhnLab / Keybase : mstoned7 , Signal : mstoned7.21 / Tweets are my own.
ShieldsUpAI @ShieldsUPAI
239 Followers 3K Following Pioneering Managed Security Assurance™ MSAP Provider Unrivaled CISO Expertise.™ Unparalleled Assessments. Beyond Security. Absolute Assurance.™ SOC NOC ISMS SME
Cassidy @cassidykei
696 Followers 3K Following mainly using twitter for news and acnh content 🦝🌱 views do not reflect my employer
Chaperone_350 @chaperone_350
1 Followers 54 Following
Bikash Dash @Memport
164 Followers 2K Following गते शोको न कर्तव्यो भविष्यं नैव चिंतयेत्। वर्तमानेन कालेन वर्तयंति विचक्षणाः॥ Vuln Research♧Exploitation♧Fuzzing♧PenTest
Downtime Monkey @DowntimeMonkey
5K Followers 5K Following Website downtime alerts & monitoring. Email & SMS alerts if website goes down. 60 sites monitored every 3 minutes FREE https://t.co/fzEy5jrXB3 #DowntimeAlerts
0str1chS3c @ostrich_sec
25 Followers 136 Following Cyber security analyst | Threat Hunter | Cat Dad | Opinions are mine
LoginRadius @LoginRadius
11K Followers 8K Following Add enterprise-grade #Authentication, Authorization, Identity Verification, #UserManagement, and #AccountSecurity to your apps with minimal to zero code! 🚀
Bishop Fox @bishopfox
26K Followers 4K Following A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking VC @forgepointcap @carrickcapital @WestCap8
Amsel Drei @amsel_drei
19 Followers 573 Following
CIO AKR @cio_akr
142 Followers 558 Following
ctrevornelson @CTrevorNelson
10K Followers 4K Following “Trevor is a Maricopa treasure” #PublicSchoolProud #NoParty #NeverTrump
Cara C @the_cara_c
699 Followers 2K Following A little of this, a little of that. Mostly elections administration & voting 🗳 Team member at Maricopa County @RecordersOffice @MaricopaVote. Personal account.
KC @kc0636
0 Followers 21 Following
Claudia Martín @CLAVDIAmartin
7K Followers 8K Following Economist, I work in IT and Data Security. Passionate about new economic theories and practices! #greenneweconomy #techdeflation
aztechcouncil @aztechcouncil
8K Followers 2K Following The Arizona Technology Council is Arizona's premier trade association for science + technology companies. Request more information: [email protected].
WGM Associates @WGMAssociates
109 Followers 453 Following We provide services in IT infrastructure, analytics, application development and information security to small and medium-sized businesses.
Randy Rose @RandyPlaysBass
242 Followers 1K Following 50% silly, 50% serious, 50% half-silly/half-serious. The Indiana Jones of Cybersecurity. My tweets are meh.
Stanley @Stanley99948476
0 Followers 726 Following
SANS.edu Internet Sto... @sans_isc
117K Followers 86 Following @[email protected] - https://t.co/8IgCGtJnZd - Global Network Security Information Sharing Community -
0str1chS3c @ostrich_sec
25 Followers 136 Following Cyber security analyst | Threat Hunter | Cat Dad | Opinions are mine
CactusCon @CactusCon
4K Followers 93 Following Arizona's hacker con. CactusCon 14: Feb 6 & 7 2026 in beautiful Mesa, AZ. https://t.co/29lnaRVQy9 + LinkedIn, Bluesky, Mastodon
Squire Patton Boggs @SPB_Global
11K Followers 4K Following 🌍 Global Law Firm providing insight at the point where Law, Business and Gov meet. Reposts are not endorsements.
CVE Announcements @CVEannounce
26K Followers 5 Following Account maintained by the CVE™ Program to update the community on CVE-related announcements. https://t.co/2P9qfFrKeu
CVE @CVEnew
58K Followers 3 Following Official account maintained by the CVE™ Program to notify the community of new CVE IDs. Posts contain abbreviated details. Full CVE Records on https://t.co/ALn4YvUtom
NSA Cyber @NSACyber
156K Followers 12 Following We protect our nation’s most sensitive systems against cyber threats. Likes, retweets, and follows ≠ endorsement.
U.S. Cyber Command @US_CYBERCOM
143K Followers 259 Following Official Twitter page of U.S. Cyber Command (Following, retweets and links do not equal endorsement)
Cybersecurity and Inf... @CISAgov
323K Followers 106 Following America's Cyber Defense Agency and National Coordinator for Critical Infrastructure Security & Resilience. Likes, reshares, follows ≠ endorsements.
CISA Cyber @CISACyber
298K Followers 73 Following Part of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
briankrebs @briankrebs
331K Followers 2K Following Independent investigative journalist. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter. Mastodon: https://t.co/fTKNavlMwp
Help a Reporter Out @helpareporter
114K Followers 2K Following Help a Reporter Out (HARO) connects journalists with expert sources. Powered by @Featureddotcom
HKA @HKAGlobal
958 Followers 669 Following HKA is a leading global consultancy in risk mitigation, dispute resolution, expert witness and litigation support services.
MalwareTech @MalwareTechBlog
272K Followers 1 Following Not here anymore. Profiles: https://t.co/sFoOuGmYK2
Scott Helme @Scott_Helme
37K Followers 326 Following Hacker, researcher, builder of things. Founded @securityheaders/@reporturi, Pluralsight author, Microsoft MVP, award winning entrepreneur. Likes cars.
Have I Been Pwned @haveibeenpwned
176K Followers 1 Following Check if you have an email address or password that has been compromised in a data breach. Created and maintained by @troyhunt.
Troy Hunt @troyhunt
249K Followers 1K Following Creator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
Bishop Fox @bishopfox
26K Followers 4K Following A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking VC @forgepointcap @carrickcapital @WestCap8
CrowdStrike @CrowdStrike
111K Followers 792 Following The first cloud-native platform that protects endpoints and cloud workloads, identity & data. #WeStopBreaches. Free trial: https://t.co/msBcUPjFKo
AZ Big Media @AZBigMedia
5K Followers 973 Following Our Publications: Az Business, AZRE, Az Business Leaders, Home & Design, Az Business Angels, Experience AZ, Ranking Arizona, Play Ball
PBJ Tech @PHXBizAndy
5K Followers 4K Following Technology, startup and entrepreneurship news coverage from @phxbizjournal. Header photo by Jerry Ferguson. Account handled by reporter Andy Blye.
ONE-Nonprofit Execs @ONEnonprofitAZ
723 Followers 507 Following ONE develops Arizona nonprofit leaders by providing education, networking and professional growth opportunities.
aztechcouncil @aztechcouncil
8K Followers 2K Following The Arizona Technology Council is Arizona's premier trade association for science + technology companies. Request more information: [email protected].





