IoC

FTP Banner Dead Drops: A Hunter’s Field Guide to E4del and PINHOLE

THREAT INTELLIGENCE REPORT  Prepared by   Essa Amous, CTO, RST Cloud  Reporting date   10 September 2026  Introduction  This article builds on the original research published by SOCRadar, which identified a Windows malware delivery campaign using FTP server banners as dead-drop resolvers to distribute the E4del and PINHOLE remote access trojans.Rather than embedding a fixed payload location […]

FTP Banner Dead Drops: A Hunter’s Field Guide to E4del and PINHOLE Read More »

TencShell and Gshell

TencShell and Gshell

THREAT INTELLIGENCE REPORT  Prepared by   Alexander Gould, CTI Strategist, RST Cloud  Reporting date   17 August 2026  Collection   Scan-derived figures are as at 10 August 2026 Active infrastructure and an exposed exploitation chain Summary  Suspected China-linked operators are running an intrusion campaign against government bodies in Taiwan, Thailand, Afghanistan and the United States, and against billing

TencShell and Gshell Read More »

threat intel scoring

Beyond Decay Curves: Rethinking IOC Scoring

This methodology now lives at /how-we-score/ as a short, evergreen reference — this post remains the full technical deep-dive. Most security teams assume IOC scoring is a solved problem. Indicators arrive from threat feeds, confidence values are assigned, decay functions reduce scores over time, and detections are prioritized accordingly. On paper, the process appears objective

Beyond Decay Curves: Rethinking IOC Scoring Read More »