Josh Stroschein | The Cyber Yeti
@jstrosch
Reverse engineer at FLARE/@Google | @pluralsight author | 😱 1M+ views on YT | 🎙️ Host of Behind the Binary podcast 👇
🔥 It's time again for a Pluralsight free trial giveaway! I'm giving away access for 30 days to all of Pluralsight - which includes all of my courses (18) and hands-on labs. Interested? Sign-up and find more details here 👇 pluralsight.thecyberyeti.com/q3-giveaway
Hi everyone! I’m looking for new opportunities in #threat research/hunting. 3+ yrs experience, focused on #ransomware in my last role, and independently tracking #APTs. DMs open — happy to connect or chat!
100 Days of YARA, YARA Rule Tips and The Current State of Email borne Threats with Greg Lesnewich x.com/i/broadcasts/1…
Check out this writeup for our .NET Crash Dump Analysis lab created by @DebugPrivilege Awesome work 😎 Blog Link: 0xsultan.github.io/dfir/Xintra-Cr…
I will be soon hiring a Senior Security Researcher. Pre-requisite: Strong knowledge in Active Directory, Entra ID, and doing security research, as well as willing to present the research at conferences.
Wrote Yara rules to cover some of the toolset used by Storm-2603 as discussed in Microsoft's latest blog post : microsoft.com/en-us/security… Covers an IIS backdoor, Warlock ransomware and SharpHostInfo: github.com/bartblaze/Yara… #Yara #CVE202553770 #ToolShell
Binary Ninja 5.1 is now released: binary.ninja/2025/07/24/5.1… - New WARP function matching - Pseudo Objective-C - Binexport plugin built-in - IL Rewriting Examples, APIs, and Docs - Arch: PPC VLE, mips-r5900, x32 + Much more!
Today's air show brought us an incredible moment of warbirds on parade, followed by a captivating reenactment of an Me 262 being pursued by two P-51 Mustangs. #Warbirds #MilitaryHistory #Avgeeks #AirVenture
As mentioned on the stream, we are giving away a voucher to @stvemillertime ‘s YARA course Check stream for details and reply to any of the social posts with the rules that inspired you to win! networkdefense.co/courses/yara/
100 Days of YARA, YARA Rule Tips and The Current State of Email borne Threats with Greg Lesnewich x.com/i/broadcasts/1…
Mark your calendars! The Invoke RE DEF CON 33 Meet Up will be at the CASBAR lounge in SAHARA on Thursday, August 7th from 3-6PM. Whether you're a seasoned pro or just starting out, this is a great opportunity to meet your fellow malware researchers and reverse engineers! RSVP👇
Tap in to the stream this week for some YARA fun, highlighting some crazy rules, how I think about learning yara (or anything) as a mid-career professional, and more!
🔥 Ready for this week's live stream with Greg Lesnewich... youtube.com/live/JIxbM82hW…
🔥 Ready for this week's live stream with Greg Lesnewich... youtube.com/live/JIxbM82hW…

New RE Video: youtube.com/watch?v=skOsJj… In this video, I reverse engineer a malicious SwiftUI dropper. Swift is fun to RE so I thought it would be a good idea :) Shout out to @txhaflaire for their recent blog post that covers this malware.
Another #DarkWatchMan campaign began on 15th June, with multiple waves over the following two days 🔥 DarkWatchMan is still written to disk by a .NET dropper. It also uses the same C2 and DGA as the 29th April campaign (the array contains the same initial strings for domains,…
🎙️ New Behind the Binary episode! 🚀 Join us as CTO Danny Quist dives into reverse engineering, binary analysis tools, & the fight against malware. Plus, personal insights on neuro-diversity & cognitive load. Listen now on Spotify! 👉 open.spotify.com/episode/6ICRY3…
We are incredibly proud to have assisted Europol 🇪🇺 in a global operation against the notorious pro-Russian #hacktivist group #NoName057(16) 🥳 Over the years, NoName057(16) has carried out thousands of #DDoS attacks against websites of western organisations and national…
🔥👇
I've been poking at #Golang malware a bit lately and wrote up some tips/tricks that I use when analyzing Golang. @jstrosch and I just talked about this on his live stream too. Check it out here -> (The livestream replay is linked in the blog post) 🤓 securityliterate.com/go-big-or-go-h…
🔥 Live streams continue next week with guest Greg Lesnewich! Greg is joining to talk about 100 days of YARA, practical YARA tips and the latest in email threats! Join us live on July 23rd 3pm CDT 👉 youtube.com/live/JIxbM82hW…