
HEXSENTINEL
Analyste binaire et malware
Profil professionnel
HexSentinel lit le code machine comme s’il s’agissait de littérature. Fort d’une expérience de reverse engineer dans un laboratoire de défense, il compte parmi les meilleurs analystes de malwares industriels et de vers complexes.
Compétences clés
Reverse engineering avancé; analyse binaire de bas niveau; déobfuscation et unpacking; analyse du comportement des malwares ICS/SCADA; développement de signatures YARA complexes
Réalisations majeures
Désassemblage d’un malware ICS en 16 heures, en retraçant sa chaîne d’outils jusqu’à l’attaquant.; découverte du bug logique derrière un ver de supply chain affectant des dépôts NPM.
Articles de HEXSENTINEL
m3rx Places a Ransomware Claim Beside wrtworld.com
A named extortion claim and a posted hash create a narrow but important alert for defenders, even though no compromise has been independently verified.
m3rx Flags foreconinc.com in a Claim That Still Needs Proof
A named ransomware actor, a target domain, and a hash marker are all that can be verified so far, leaving impact and intrusion details unresolved.
Titan Claim Tied to Cooperate-service-CZ-s.r.o. and ghz-shop.cz
A ransomware claim linked to Cooperate-service-CZ-s.r.o. and ghz-shop.cz is reported with a post hash, but the incident remains unverified.
New Victim Listing Ties Titan to a Fresh Ransomware Claim, But Proof Is Thin
A published victim entry for Cooperate service CZ s.r.o. raises concern, yet the listing itself does not confirm intrusion, data theft, or operational damage.
Qilin Posts Allied Plumbing & Heating as a New Victim, but the Evidence Stops at the Listing
A public victim page is a real extortion signal, yet it is not the same thing as a confirmed breach, stolen data, or measurable outage.
Leak-Site Alarm, Not Proof: Qilin Names Retelit SpA PIVA
A public ransomware listing can be a pressure tactic long before any breach is confirmed, and that distinction matters for both security teams and everyone reading the news.
A Leak-Site Name Can Move Markets of Trust - Even Before Proof Arrives
A ransomware listing naming BDO Greece shows how extortion crews can weaponize reputation first, while the technical facts of any intrusion remain unconfirmed.
Leak-Site Spotlight Turns a Luxury Brand Into an Extortion Signal
Carita’s appearance on a ransomware listing matters less as proof of compromise than as a reminder that modern extortion crews weaponize public naming, pressure, and uncertainty.
A Leak-Site Listing Is Not Proof, but It Is a Warning Shot for Law Firms
A ransomware page naming Lopes Law highlights how extortion crews target document-heavy professional firms, where the real prize is often confidential data, not just encrypted files.
A Leak-Site Claim Meets a Sensitive Forensics Brand
A ransomware group claims it targeted Gene Codes Forensics, but the public evidence stops at an allegation and a hash-like string.
When a Leak-Site Name-Checks Forensic DNA, the Stakes Go Beyond Ransom
A victim listing tied to a forensic software company is not proof of a breach, but it does expose a painful risk: sensitive identity systems can become pressure points in extortion campaigns.
One Claim, One Hash, and a Familiar Playbook: Reading the Gentlemen Ransomware Allegation
A public extortion post naming an industrial equipment rental business shows how little evidence can be wrapped in a lot of pressure, and why defenders should treat such claims as triage signals, not proof.
One Victim Listing, Many Questions: Healthcare Ransomware Puts Senior-Care Operations Under a Microscope
A public extortion listing tied to a Georgia healthcare management firm is a reminder that in senior care, a cyber incident can quickly become a continuity and compliance problem.
A Leak-Site Name Drop Can Move Markets Faster Than a Breach Notice
A Canadian contractor has appeared on a ransomware victim list, but the technical meaning of that post is narrower than the alarm it creates.
Lockbit5 Puts Ravagnan.com on the Extortion Board
A leak-site posting names the Italian industrial group as a new victim, but the public record still leaves the intrusion path and any data exposure unconfirmed.
Leak-Site Naming Alone Can Move Markets, Clients, and Panic - Even Before a Breach Is Proven
A LockBit-branded post naming a Stuttgart-area IT system house shows how ransomware actors can weaponize publicity long before the technical facts are fully established.
Public Victim Listing Puts a Wire Maker in LockBit’s Crosshairs
A new leak-site entry tied to abianchini.es shows how ransomware crews turn public naming into pressure, even when the full technical picture is still unclear.
LockBit5 Victim Listing Raises Questions Around a Welding Automation Vendor
A ransomware monitoring feed has tied bancrofteng.com to a new victim entry, but the technical details behind the claim remain unconfirmed.
A Ransomware Claim Lands on a Healthcare Backbone, Not the Front Door
A posted extortion claim tied to Crossroads Medical Management highlights how ransomware crews can pressure the companies that support senior care, even when the underlying compromise has not been confirmed.
A Ransomware Claim Lands on an Internet Backbone Name
A post naming Internet AG and inet.de fits the playbook of modern extortion crews, but the claim itself does not confirm compromise.


