LIVE
2.9M influencer listings 🏢40.7K sponsor listings 🌍60.12B combined audience reach 📊13 platforms indexed 🗺️130+ countries covered 🏷️10,000+ niches 🦋1.07M Bluesky creators 🟣735.8K Twitch creators 🎙️650.7K podcast creators 🐘148.8K Mastodon creators 🥊79.4K Kick creators ▶️76.9K YouTube creators ✈️50.8K Telegram creators 𝕏48.4K X creators 🎵22.4K TikTok creators 📈7.2K Pinterest creators 🎮5.7K Discord creators 🎬3.6K Rumble creators 📈1.5K Substack creators 🧵1.3K Threads creators 2.9M influencer listings 🏢40.7K sponsor listings 🌍60.12B combined audience reach 📊13 platforms indexed 🗺️130+ countries covered 🏷️10,000+ niches 🦋1.07M Bluesky creators 🟣735.8K Twitch creators 🎙️650.7K podcast creators 🐘148.8K Mastodon creators 🥊79.4K Kick creators ▶️76.9K YouTube creators ✈️50.8K Telegram creators 𝕏48.4K X creators 🎵22.4K TikTok creators 📈7.2K Pinterest creators 🎮5.7K Discord creators 🎬3.6K Rumble creators 📈1.5K Substack creators 🧵1.3K Threads creators
Stephan Berger

Stephan Berger

🔄 Data last refreshed 15 hours ago
🤝

Make a deal with Stephan Berger

🔒 Paid proposals held safely in escrow — released only when the work's approved.

Every booking is a normal escrow-protected deal.

Followers
1.2K
Account age
3 yrs
🧰 Free analysis for Stephan Berger
🕵️ Fake follower check 📊 Engagement rate 💰 What they charge

Known for

In March, I had the pleasure of attending the course “Advanced Linux Malware Reverse Engineering" with Marion Marschalek. Since reverse engineering isn’t my main area of expertise, my brain was completely fried by the end of each evening (I’d end up lying on the hotel bed watching episode after episode of House Hunters 😂). I hadn’t been challenged like that since the EDR Evasion course, about whic24 views In March, I had the pleasure of attending the course “Advanced Linux Malware Reverse Engineering" with Marion Marschalek. Since reverse engineering isn’t my main area of expertise, my brain was completely fried by the end of each evening (I’d end up lying on the hotel bed watching episode after episode of House Hunters 😂). I hadn’t been challenged like that since the EDR Evasion course, about whic On a recent Linux-based Incident Response case, we found a dropped GSocket binary as a persistence mechanism [1]. The threat actor planted the dropped binaries under user-space directories to blend in, specifically masquerading as legitimate system processes:
./.config/dbus/php-fpm
./.config/htop/defunct
Persistence was established via standard execution vectors, either triggered through cron entr9 views On a recent Linux-based Incident Response case, we found a dropped GSocket binary as a persistence mechanism [1]. The threat actor planted the dropped binaries under user-space directories to blend in, specifically masquerading as legitimate system processes: ./.config/dbus/php-fpm ./.config/htop/defunct Persistence was established via standard execution vectors, either triggered through cron entr Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes:
A memory dump of the lsass.exe process (lsass.dmp) was created on a server, hardly a subtle move, but when there is no one watching, there is no judge. [1]
I checked our case data, and this is more 7 views Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes: A memory dump of the lsass.exe process (lsass.dmp) was created on a server, hardly a subtle move, but when there is no one watching, there is no judge. [1] I checked our case data, and this is more One of our pentesters was tasked with assessing a customer's perimeter and found an exposed FTP server. They queried the server's FQDN on a specialized service and (surprisingly?) found leaked login credentials.
One set worked. Upon logging in, they discovered dozens of webshells! Someone had clearly found these leaked credentials before we did and tried to exploit the server. The first sign of ex4 views One of our pentesters was tasked with assessing a customer's perimeter and found an exposed FTP server. They queried the server's FQDN on a specialized service and (surprisingly?) found leaked login credentials. One set worked. Upon logging in, they discovered dozens of webshells! Someone had clearly found these leaked credentials before we did and tried to exploit the server. The first sign of ex

📊 Post engagement

6
Avg engagement / post
0.5%
Engagement vs followers
Nov 2022
On Mastodon since

🔥 Top post: In March, I had the pleasure of attending the course “Advanced L · 24 likes + reposts

📊 Activity & format

Posting cadence
0.65 / week
A lower-frequency account — each post lands with more weight.
Content mix
Mostly text
Recent: 7 text · 5 image · 0 video.
Follower / following
1.1×
Follows 1.1K back. A more reciprocal / networked account.
🔥 Top post In March, I had the pleasure of attending the course “Advanced Linux Malware Reverse Engineering" with Marion Marschalek. Since reverse engineering isn’t my main area of expertise, my brain was completely fried by the end of each evening (I’d end up lying on the hotel bed watchi… ★ 24
And here is the second part of the Cleartext Password Series: https://dfir.ch/posts/fantastic_passwords_windows/ ★ 4 In a recent ISC SANS Diary, Xavier Mertens discussed a malicious ZIP archive that led to Remcos, a pretty common RAT. As Xavier noted, "Most of the files used in this infection path remain undetected by most AVs." [1] PowerShell, AppData, … ★ 2 I created two blog posts based on my Fantastic Cleartext Passwords talk, which I presented last year at BSides Munich, and I released the first part (Linux) today. The second part (Windows) will be released next week. Even if these techniq… ★ 9 Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes: A memory dump of the lsass.exe proces… ★ 7 We recently analyzed an interesting piece of malware that utilizes the legitimate JavaScript runtime, Deno. The malware was used as a first-stage implant after the user was tricked into downloading and running the malware. Read the full … ★ 3 One of our pentesters was tasked with assessing a customer's perimeter and found an exposed FTP server. They queried the server's FQDN on a specialized service and (surprisingly?) found leaked login credentials. One set worked. Upon loggin… ★ 4 People who have been following me long enough should know by now how much I love these nitty-gritty details of forensics, the little breadcrumbs that give you critical clues about your ongoing case. My colleagues Andreas Klaus and Bruno Ko… ★ 3 On a recent Linux-based Incident Response case, we found a dropped GSocket binary as a persistence mechanism [1]. The threat actor planted the dropped binaries under user-space directories to blend in, specifically masquerading as legitima… ★ 9 Here’s another IG Labs post. After my teammate Evgen published his research on ViperTunnel last week, my other teammate, @schnee_FLO_cke, published a blog post today on BravoX, a ransomware-as-a-service (RaaS) provider. Well done - such a … ★ 1 As today is the 10th of April, I'm giving away a 10% discount on my upcoming Anti-Forensics training in Belgium at the end of the month. We still have seats left (somebody booked in just yesterday). Personally, I think it will be awesome, … A big shout-out to the @toulousehacking Review Committee. I submitted two talks, and one was accepted. Both talks were reviewed by three reviewers, and I received their comments along with the decision (Accepted/Rejected). This is so valu… ★ 2

🐘 Community & instance

Home server
infosec.exchange
A cybersecurity & infosec server — its members and audience skew toward that niche, so expect a community-aligned, engaged following.
✅ Link-verified
Verified link
Proved ownership of a website linked on their profile — Mastodon's green-check verification, a real identity signal rather than a paid badge.
On Mastodon since
Nov 2022
Joined in the Twitter-exodus wave of late 2022 — part of the migration that made Mastodon a real destination.

💡 Facts

🗓️Joined Mastodon in 2022 — 3 years ago.
👁️Averages 6 views per post.
📤Posts about 0.7× per week.

🕵️ Fake follower check

Estimated
75/100
Good Credibility score
92%
Real Real audience
Low Fake-follower risk
High Data confidence
  • Est. 92% real, active audience · Low fake-follower risk.
  • Engagement (~0.5% of followers engage each post) is around typical for Mastodon.
  • Verified account.
  • Established account (3+ years old).

Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.

About

Head of Investigations @ InfoGuardAG

📸 Gallery

✉ Message Stephan Berger

Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.

See Pro $9.95/mo →

Already Pro? Log in.

🎤 Event / appearance with Stephan Berger

Booking an event / appearance is a Pro feature. Upgrade to book Stephan Berger for an in-person or virtual appearance — payment held safely in escrow until the event is done.

See Pro $9.95/mo →

Already Pro? Log in.

Auto-generated from Mastodon's public data — no affiliation with or endorsement by SocialDB. Is this you? Claim it · Remove