Threat Intelligence

threat intel scoring

Beyond Decay Curves: Rethinking IOC Scoring

This methodology now lives at /how-we-score/ as a short, evergreen reference — this post remains the full technical deep-dive. Most security teams assume IOC scoring is a solved problem. Indicators arrive from threat feeds, confidence values are assigned, decay functions reduce scores over time, and detections are prioritized accordingly. On paper, the process appears objective […]

Beyond Decay Curves: Rethinking IOC Scoring Read More »

MacSync

MacSync Stealer: C2 Infrastructure Rotation

On 5 May 2026, an RST Cloud customer’s Jamf Protect blocked a download from jacksonvillemma[.]com. Four days earlier, the operator’s prior MacSync C2 had been publicly disclosed. Twenty-four hours after that disclosure, the new C2’s TLS certificate had been issued. Three days later, the new C2 was attempting to deliver its loader to a managed

MacSync Stealer: C2 Infrastructure Rotation Read More »