Skip to content
NVISO Labs

NVISO Labs

Cyber security research, straight from the lab! 🐀

  • twitter
  • linkedin
  • mail us
  • our company
  • SSO
  • All
  • Blue Team
  • Cloud Security
    • AWS
    • Azure
    • GCP
    • Microsoft 365
  • Awareness
  • Forensics
  • Other
    • Application Security
    • IoT Security
    • Web Security
    • Industrial Security
    • Mobile Security
    • Cyber Strategy
    • Purple Team
    • Red Team
    • Events

Author: Nicholas Dhaeyer

Nicholas Dhaeyer is a Threat Hunter for NVISO. Nicholas specializes in Threat Hunting, Malware analysis & Industrial Control System (ICS) / Operational Technology (OT) Security. Nicholas has worked in the NVISO SOC solving security incidents for our MDR clients. You can reach out to Nicholas via [Twitter](https://twitter.com/DhaeyerWolf) or [LinkedIn](https://www.linkedin.com/in/nicholas-dhaeyer5167/)

The SOC Toolbox: Analyzing AutoHotKey compiled executables

A quick post on how to extract AutoHotKey scripts from an AutoHotKey script compiled executable.

Nicholas Dhaeyer Forensics, Windows, Blue Team 2 Comments July 20, 2023July 18, 2023 2 Minutes

OneNote Embedded URL Abuse

OneNote Embedded URL Abuse

Whilst Microsoft is fixing the embedded files feature in OneNote I decided to abuse a whole other feature. Embedded URLs. Turns out this is something they may also have to fix.

Nicholas Dhaeyer Cyber Threats, Maldoc, phishing, Malware, SOC, Threat Hunting, Blue Team, Qbot, OneNote 4 Comments March 27, 2023April 26, 2023 5 Minutes

OneNote Embedded file abuse

In recent weeks OneNote has gotten a lot of media attention as threat actors are abusing the embedded files feature in OneNote in their phishing campaigns. In this post we will analyze this new way of malware delivery and create a detection rule for it.

Nicholas Dhaeyer Cyber Threats, OneNote, Maldoc, Malware, phishing, Reverse Engineering, Threat Hunting, Blue Team, Detection Engineering, Qbot 4 Comments February 27, 2023July 18, 2023 8 Minutes
NVISO Homepage
Services
Jobs
Blog
Info and support
info@nviso.eu
Got hacked?
csirt@nviso.eu