Original malware research โ reverse engineering, infrastructure analysis, and detection engineering from real samples.
Free reports, IOC feeds, and detection rules (YARA, Sigma, Suricata) for defenders.
https://t.co/TuvERTRzE4
Fake FACEIT pages tell CS2 players to paste a command. The script at 202[.]71[.]14[.]31 fetches an executable built for Steam accounts. Capability read from code, no victims confirmed.
14 rules + IOCs:
https://t.co/F540sZMl8w
#ThreatIntel#ClickFix#DFIR
One operator hit 198 Gotenberg endpoints with CVE-2026-42589 in 54 minutes, from 107[.]175[.]69[.]137.
The rule you'd write from the exploit source never fires: the newline hits the wire JSON-escaped, decoded only after a sensor passed it.
https://t.co/vo6GCoBk9S
#ThreatIntel
Sliver C2 + an Ethereum-resolved backdoor staged at 193[.]233[.]202[.]17. Builds on incident work from @HuntressLabs and the infra writeup from @Huntio. C2 rotated 5x through a contract that never changed.
https://t.co/zezKwiPHAc
#ThreatIntel#Sliver#DFIR
A carrier-managed router was crashed on purpose so it would write credential-bearing core dumps, then made to upload them itself. 424,946,514 bytes out, no shell needed. 30 detection rules and 127 IOCs, free.
https://t.co/wW2aMw0TKd
#ThreatIntelligence#Telecom#DFIR
An operator pointed an 8-class Java exploit toolkit at 192[.]3[.]1[.]116. Not one chain stole a byte.
What they took came through doors already open, including logs they made the app write for them.
30 rules + 72 IOCs, free.
https://t.co/PUayHrc2Jr
#ThreatIntelligence#DFIR
New on The Hunter's Ledger: paste indicators, see which of 54 feeds carry them. Pick single detection rules, download engine-native. Read any report at Brief, Analyst or Full depth. Plus a rolling threat-intel wire.
https://t.co/TuvERTS7tC
#ThreatIntel#DFIR
99 hand-written exploit scripts on one exposed server, aimed at four Southeast Asian governments.
Three fell. The rest bounced off OTP, patching and account lockout, and the operator saved the receipts.
27 rules + 44 IOCs:
https://t.co/yce699Ubhl
#ThreatIntel#DFIR
22-file intrusion toolkit exposed at 91[.]197[.]98[.]188. The operator wrote almost none of it.
3 named actors' tools in one kit, and none is the operator. Tool matches are not identity.
29 rules + 49 IOCs:
https://t.co/7ff2khLaNA
#ThreatIntel#RAT#DFIR
Thanks to @Hunters_Ledger, the Suricata rule index has a new ruleset!
This is what the open source community is all about - when researchers, defenders and contributors share their knowledge, it makes everyone stronger.
Check the Suricata Rule Index: https://t.co/QRaCrH9KcN
A cryptojacking operator's ledgers claimed ~7,145 compromises. Independent evidence covers 7.
Reading the code behind those ledgers explains it: most "success" checks return true on a 404, a 401, or no reply at all.
https://t.co/q8I3fzcjg9
#ThreatIntel#Cryptojacking#DFIR
The Hunter's Ledger Suricata feed is now an official suricata-update source.
suricata-update enable-source the-hunters-ledger/open
67 rules, own SID block. Engine-validated on real hardware, run in my own SOC, so misfires get fixed and shipped to you.
https://t.co/hzBFfaIapQ
@jasonish@Suricata_IDS Thank you @jasonish and team for brining me into this amazing project. Very excited that my rules will be assisting defenders in a much wider way now!
One Brazilian operator, two malware lines: KAIDO, a Quasar-fork RAT whose hidden-desktop HVNC hijacks a victim's live session (beats most 2FA), + the EvilSoul-Engine stealer-builder MaaS behind it. C2 144[.]172[.]109[.]203:
https://t.co/JOXJkOVmlr
#ThreatIntel#RAT#MaaS
๐๐๐ป๐ ๐ฏ.๐ฌ ๐ถ๐ ๐น๐ถ๐๐ฒ. ๐ฃ๐๐น๐น ๐๐ต๐ฒ ๐๐ต๐ฟ๐ฒ๐ฎ๐ฑ. ๐
Most threat hunting tools stop at the lookup. You get a result, maybe a tag, and then you're on your own figuring out what connects to what.
We built v3 to fix that. Every indicator, whether it's an IP, a domain, or a hash, should open into the full picture automatically.
๐ Here's what's new: https://t.co/vwdO3QT9QH
โ 60+ API endpoints across C2, AttackCapture, Vulnerability Intel, SQL, and more
โ Remote MCP server, connect Claude or other AI tools straight to Hunt data
โ Cloudflare Buster turns one domain into a full infrastructure cluster
โ Passive DNS History gives you a real timeline of DNS changes, not just a point-in-time snapshot
โ Attack Reports turns exposed attacker directories into structured campaign reports, tied to specific IPs, IOCs, and CVEs
โ Exploit Capture indexes 54,000+ AI-classified files staged in attacker open directories right now
โ Provider Radar now includes Registrar intelligence, catching domain provisioning patterns before those domains go live in an attack
โ Flattened data architecture so HuntSQL joins are finally possible, no workarounds
โ And much more!
And the best part: you get 14 days free, no credit card needed. Open an account and start hunting today ๐ https://t.co/E6aUhCpXD1
The Hunter's Ledger now publishes a free Suricata rule feed โ 101 rules, auto-updating, SID range 1900000-1999999. Add with one command:
suricata-update add-source hunters-ledger https://t.co/ei2Fq1oqO5
#Suricata#DetectionEngineering#ThreatIntel