Make a deal with Stephan Berger
🔒 Paid proposals held safely in escrow — released only when the work's approved.
Known for
24 views
In March, I had the pleasure of attending the course “Advanced Linux Malware Reverse Engineering" with Marion Marschalek. Since reverse engineering isn’t my main area of expertise, my brain was completely fried by the end of each evening (I’d end up lying on the hotel bed watching episode after episode of House Hunters 😂). I hadn’t been challenged like that since the EDR Evasion course, about whic
9 views
On a recent Linux-based Incident Response case, we found a dropped GSocket binary as a persistence mechanism [1]. The threat actor planted the dropped binaries under user-space directories to blend in, specifically masquerading as legitimate system processes:
./.config/dbus/php-fpm
./.config/htop/defunct
Persistence was established via standard execution vectors, either triggered through cron entr
7 views
Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes:
A memory dump of the lsass.exe process (lsass.dmp) was created on a server, hardly a subtle move, but when there is no one watching, there is no judge. [1]
I checked our case data, and this is more
4 views
One of our pentesters was tasked with assessing a customer's perimeter and found an exposed FTP server. They queried the server's FQDN on a specialized service and (surprisingly?) found leaked login credentials.
One set worked. Upon logging in, they discovered dozens of webshells! Someone had clearly found these leaked credentials before we did and tried to exploit the server. The first sign of ex
📊 Post engagement
🔥 Top post: In March, I had the pleasure of attending the course “Advanced L · 24 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
🔥 Top post
In March, I had the pleasure of attending the course “Advanced Linux Malware Reverse Engineering" with Marion Marschalek. Since reverse engineering isn’t my main area of expertise, my brain was completely fried by the end of each evening (I’d end up lying on the hotel bed watchi…
Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes:
A memory dump of the lsass.exe proces…
We recently analyzed an interesting piece of malware that utilizes the legitimate JavaScript runtime, Deno.
The malware was used as a first-stage implant after the user was tricked into downloading and running the malware.
Read the full …
One of our pentesters was tasked with assessing a customer's perimeter and found an exposed FTP server. They queried the server's FQDN on a specialized service and (surprisingly?) found leaked login credentials.
One set worked. Upon loggin…
People who have been following me long enough should know by now how much I love these nitty-gritty details of forensics, the little breadcrumbs that give you critical clues about your ongoing case.
My colleagues Andreas Klaus and Bruno Ko…
On a recent Linux-based Incident Response case, we found a dropped GSocket binary as a persistence mechanism [1]. The threat actor planted the dropped binaries under user-space directories to blend in, specifically masquerading as legitima…
Here’s another IG Labs post. After my teammate Evgen published his research on ViperTunnel last week, my other teammate, @schnee_FLO_cke, published a blog post today on BravoX, a ransomware-as-a-service (RaaS) provider.
Well done - such a …
As today is the 10th of April, I'm giving away a 10% discount on my upcoming Anti-Forensics training in Belgium at the end of the month.
We still have seats left (somebody booked in just yesterday). Personally, I think it will be awesome, …
A big shout-out to the @toulousehacking Review Committee. I submitted two talks, and one was accepted. Both talks were reviewed by three reviewers, and I received their comments along with the decision (Accepted/Rejected).
This is so valu…
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 92% real, active audience · Low fake-follower risk.
- Engagement (~0.5% of followers engage each post) is around typical for Mastodon.
- Verified account.
- Established account (3+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message Stephan Berger
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with Stephan Berger
Booking an event / appearance is a Pro feature. Upgrade to book Stephan Berger for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ Stephan Berger gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.
Auto-generated from Mastodon's public data — no affiliation with or endorsement by SocialDB. Is this you? Claim it · Remove