# Cysinfo > Cyber Security Community ## Posts - [6th Meetup – Introduction to Secure Multi Party Computation](https://cysinfo.com/6th-meetup-introduction-to-secure-multi-party-computation/): In this presentation, Jitendra Kumar Patel covered the concept of Secure Multi Party Computation (SMPC) and its applications. He also showed how SMPC could help multiple distrusting parties, who want to mutually evaluate a joint function by keeping their inputs as PRIVATE as possible and obtaining a fair output.   Presentation: - [6th Meetup – Bluetooth [in]security](https://cysinfo.com/6th-meetup-bluetooth-insecurity/): In this presentation, Jiggyasu Sharma covered Bluetooth security focusing on Bluetooth low energy weaknesses and he also demonstrated Bluetooth low energy traffic capturing and cracking them using Ubertooth One.   Presentation: - [5th Quarterly Meetup – 10th October 2015](https://cysinfo.com/5th-quarterly-meetup-10th-october-2015/): In this meet, Sreelakshmy and Mythily delivered presentation on “Partial Homomorphic Encryption”,Archita Aparichita covered the topic on “DLL Preloading Attack” and Monnappa KA presented on the topics “Basic Malware Analysis, Automating Malware Analysis and Reverse Engineering Malware”.   Here is the link to presentations and video demonstrations: 1. Partial Homomorphic Encryption 2. DLL Preloading Attack 3. Basic Malware Analysis  4. Automating […] - [5th Meetup -Reverse Engineering Malware](https://cysinfo.com/5th-meetup-reverse-engineering-malware/): In this awesome presentation, Monnappa explained the concepts of malware reverse engineering. Presentation:   Video Demo – 1:   Video Demo – 2:   Video Demo – 3: - [5th Meetup – Automating Malware Analysis](https://cysinfo.com/5th-meetup-automating-malware-analysis/): In this presentation, Monnappa explained the concept of automated malware analysis, sandbox and sandbox architecture.   Presentation:   Video Demo: - [5th Meetup – Basic Malware Analysis](https://cysinfo.com/sx-5th-meetup-basic-malware-analysis/): In this presentation, Monnappa explained the concept of malware analysis.   Presentation:   Video Demo: - [5th Meetup – DLL Preloading Attack](https://cysinfo.com/sx-5th-meetup-dll-preloading-attack/): In this presentation, Archita  explained the dll preloading attack.   Presentation: - [5th Meetup -Partial Homomorphic Encryption](https://cysinfo.com/sx-5th-meetup-partial-homomorphic-encryption/): In this presentation, Sreelakshmy and Mythily discussed about the partial homomorphic encryption and its applications.   Presentation: - [4th Quarterly Meetup – 23rd May 2015](https://cysinfo.com/securityxploded-4th-quarterly-meetup-23rd-may-2015/): In this meet, Subrat Sarkar delivered presentation on “Exposing the secrets of Windows Credential Provider”, Raghav Pande covered the topic on “Defeating Public Exploit Protections(EMET v5.2 and more)”, Amit Malik presented the topic “Return Address – The Silver Bullet” and Monnappa KApresented the topic on “Hunting Rootkit From the Dark Corners Of Memory”.   Here […] - [4th meetup – Hunting Rootkit From the Dark Corners Of Memory](https://cysinfo.com/sx-4th-meetup-hunting-rootkit-from-the-dark-corners-of-memory/): In this awesome presentation, Monnappa explained the concept of Rootkits, types of Rootkits, Memory Forensics. He demonstrated various stealth techniques used by the TDSS Rootkit and showed how to identify its presence and understand its capabilities and various functionality using memory forensics.   Presentation:   Video Demo: - [4th Meetup -Return Address – The silver bullet](https://cysinfo.com/sx-4th-meetup-return-address-the-silver-bullet/): In this awesome presentation, Amit Malik discussed about the importance of return address in solving some of the problems related to analysis and detection of the malicious codes.   Presentation: - [4th Meetup – Defeating public exploit protections (EMET v5.2 and more)](https://cysinfo.com/sx-4th-meetup-defeating-public-exploit-protections-emet-v5-2-and-more/): In this awesome presentation, Raghav Pande explained the concept of public protections and showed how public exploit mitigation toolkits are not enough to protect from a targeted attack as well as how easy it is to evade all public protections.   Presentation: - [4th Meetup – Exposing the secrets of Windows credential provider](https://cysinfo.com/sx-4th-meetup-exposing-the-secrets-of-windows-credential-provider/): In this awesome presentation, Subrat Sarkar explained the concepts of Windows logon mechanism, Windows Logon architecture, Windows credential provider and showed how an attacker can take advantage of credential provider to steal Windows password in plain text and how to find and mitigate this issue.   Presentation: - [3rd Quarterly Meetup – 24th Jan 2015](https://cysinfo.com/securityxploded-3rd-quarterly-meetup-24th-jan-2015/): In this meet, Sameer Patil delivered presentations on “Anatomy of Exploit Kits”, Satyam Saxenacovered the topic on “Detecting the Malicious Url using Machine Learning” and Monnappa KApresented the topic on “Hunting the Gh0st RAT cyber espionage malware using Memory Forensics”.   Here is the link to presentations and video demonstrations: 1. Anatomy of Exploit Kits […] - [3rd Meetup – Hunting Ghost RAT Using Memory Forensics](https://cysinfo.com/sx-3rd-meetup-hunting-ghost-rat-using-memory-forensics/): In this awesome presentation, Monnappa KA explained the details of Ghost RAT malware used in various Cyber Espionage attacks. He showcased the sandbox analysis, traffic pattern and decrypting the communications of Ghost RAT from packet capture. He also demonstrated both manual and automated method of detecting and decrypting the communications of Ghost RAT using memory […] - [3rd Meetup – Malicious Url Detection Using Machine Learning](https://cysinfo.com/sx-3rd-meetup-malicious-url-detection-using-machine-learning/): In this awesome presentation, Satyam Saxena explained the concept of detecting malicious urls using machine learning.The presentation mainly focused on using various infrastructure based features of an url, to design a machine learning system which can automatically predict the probability of its maliciousness.   Presentation: - [3rd Meetup – Anatomy of Exploit Kits](https://cysinfo.com/sx-3rd-meetup-anatomy-of-exploit-kits/): In this awesome presentation, Sameer Patil explained the concept of Exploit Kits and its working with some interesting case studies. He also covered various phases of exploitation and demonstrated the analysis of Nuclear and Fiesta exploit kits.   Presentation:   Video Demo 1:   Video Demo 2: - [2nd Quarterly Meet – 27th Sep 2014](https://cysinfo.com/securityxploded-2nd-quarterly-meet-27th-sep-2014/): In this meet, Raghav Pande and Monnappa delivered fabulous presentations on reverse engineering the evasive tactics of advanced malwares. Here is the link to presentations and video demonstrations: 1. Dissecting BetaBot 2. Reversing and Decrypting the Communications of APT Malware Here are the few snapshots from the session - [2nd Meetup – Reversing and Decrypting the Communications of APT Malware](https://cysinfo.com/sx-2nd-meetup-reversing-and-decrypting-the-communications-of-apt-malware/): In this awesome presentation, Monnappa explained about Etumbot malware used in a Cyber Espionage attack.  He showcased the sandbox analysis, Reverse engineering and Decrypting the communications of Etumbot Backdoor using practical video demonstrations.    Presentation:   Video Demo 1:   Video Demo 2:   Video Demo 3:   References: http://www.arbornetworks.com/asert/2014/06/illuminating-the-etumbot-apt-backdoor/ http://www.fireeye.com/blog/technical/botnet-activities-research/2014/09/darwins-favorite-apt-group-2.html - [Meetup 2 – Dissecting BetaBot](https://cysinfo.com/sx-meetup-2-dissecting-betabot/): In this presentation, Raghav Pande explained various self defending mechanisms of BetaBot.  He also presented unpacking, hooking and injection methods of this malware using illustrative screenshots.    Presentation: - [1st Quarterly Meet – 21st Jun 2014](https://cysinfo.com/securityxploded-1st-quarterly-meet-21st-jun-2014/): Our rocking stars, Amit Malik & Monnappa delivered fabulous presentations on detection and mitigation of advanced attacks emerging in Security arena. Here is the link to presentations and video demonstrations, 1. Watering Hole Attacks Case Study and Analysis 2. Chronicles of Malware and Detection Systems. Here are the few snapshots from the session,       - [Meetup 1 – Chronicles of Malware and Detection Systems](https://cysinfo.com/sx-meetup-1-chronicles-of-malware-and-detection-systems/): In this presentation, Amit Malik showcased emerging trends on how Malwares have evolved over the time.  He also presented new and special detection techniques to combat each of these sophisticated attacks.    Presentation: - [Meetup 1 – Watering Hole Attacks Case Study and Analysis](https://cysinfo.com/sx-meetup-1-watering-hole-attacks-case-study-and-analysis/): In this presentation Monnappa showcased a novel concept in security arena – “Watering Hole Attack”. He presented various exploitation methods around it using the practical video demonstration.   Presentation:   Video Demonstration: References: žhttp://about-threats.trendmicro.com/RelatedThreats.aspx?language=au&name=Watering+Hole+101 http://www.fireeye.com/blog/technical/cyber-exploits/2014/02/operation-snowman-deputydog-actor-compromises-us-veterans-of-foreign-wars-website.html http://www.securityweek.com/new-ie-10-zero-day-used-watering-hole-attack-targeting-us-military žhttp://blogs.cisco.com/security/watering-hole-attacks-target-energy-sector/ - [Session 11: (Part 2) Dissecting the HeartBeat APT RAT Features](https://cysinfo.com/session-11-part-2-dissecting-the-heartbeat-apt-rat-features/): This session demonstrated various features of HeartBeat APT RAT using reverse engineering. Demo Video Part 2a – Decrypting various communications Demo Video Part 2b – HeartBeat RAT Functionality 1 -Process enumeration Demo Video Part 2c – HeartBeat RAT Functionality 2 – Process termination Demo Video Part 2d – HeartBeat RAT Functionality 3 – Create and […] - [PyMal](https://cysinfo.com/pymal/): PyMal is a python based interactive Malware Analysis Framework. It is built on the top of three pure python programes Pefile, Pydbg and Volatility. The main aim of the project is to combine all the Malware Analysis related tools into a single interface for rapid analysis.   PyMal have several wrapper functions to manipulate Executable […] - [Session 10: (Part 1) Reversing & Decrypting Communications of HeartBeat RAT](https://cysinfo.com/session-10-part-1-reversing-decrypting-communications-of-heartbeat-rat/): This session covered the reversing of HearBeat Rat and decrypting its network communication Demo Video 1 – Decrypting HeartBeat APT RAT communication Demo Video 2 – Reversing the HearBeat APT RAT - [Session 9: Malware Analysis using PyMal & Malpimp](https://cysinfo.com/session-9-malware-analysis-using-pymal-malpimp/): This session covered two tools Pymal and Malpimp and demonstrated the use and purpose of these tools, these tools can be helpful in accelerating the malware analysis process. - [ExeScan](https://cysinfo.com/exescan/): ExeScan is a console based tool to detect anomalies in PE (Portable Executable) files. It quickly scans given executable file and detect all kind of anomalies in its PE header fields including checksum verification’s, size of various header fields, improper size of raw data, non-ascii/empty section names etc. Various packers/protectors modify PE header to make reversing […] - [Session 8: Introduction to Android Architecture and its Malware Analysis](https://cysinfo.com/session-8-introduction-to-android-architecture-and-its-malware-analysis/): This session covered the android architecture and some tools to analyse android malwares. - [Session 7: Malware Memory Forensics](https://cysinfo.com/session-7-malware-memory-forensics/): This session covered the tools and techniques to perform malware memory forensics.   Demo Video 1 – Malware Memory Forensics Demo Video 2 – Malware Memory Forensics - [Session 6: Malware Sandbox Analysis](https://cysinfo.com/session-6-malware-sandbox-analysis/): This presentation covered the process of automating the analysis of malware using the custom written sandbox   Demo Video 1 – Sanbox Analysis of Spybot Demo Video 2 – Sandbox Analysis of Zbot Demo Video 3 – Sandbox Analysis of Prolaco - [Session 5: Reverse Engineering Automation (Scripts, plugins etc.)](https://cysinfo.com/session-5-reverse-engineering-automation-scripts-plugins-etc/): This presentation covered the concept of automating reverse engineering using custom scripts and plugins. - [Session 4: Anti-Analysis Techniques (Anti-debugging, Anti-VM etc.)](https://cysinfo.com/session-4-anti-analysis-techniques-anti-debugging-anti-vm-etc/): Most of the time it is common to encounter malware which performs anti-analyis techniques, understanding these techniques will help in analyzing such malwares. - [Session 3: Botnet Analysis – Part 2](https://cysinfo.com/session-3-botnet-analysis-part-2/): This session will introduce some more advanced methods of analysis and detection. - [Session 2: Botnet Analysis – Part 1](https://cysinfo.com/session-2-botnet-analysis-part-1/): This session will discuss some stealth techniques used by malwares and also demonstrates some rapid reversing techniques to accelerate the reversing tasks. Video Demo - [Session 1: Detection and Removal of Malwares](https://cysinfo.com/session-1-detection-and-removal-of-malwares/): This session will introduce you with some tools and tricks to identify and remove malwares from the infected system.   [Note: View the video in 720HD quality] Demo Video 1 Demo Video 2 Demo Video 3 Demo Video 4   - [ShellDetect](https://cysinfo.com/shelldetect/): Shell Detect is a tool to detect presence of Shell Code within a file or network stream. You can either provide raw binary file (such as generated from Metasploit  or network stream file as input to this tool. These days attackers distribute malicious files which contains hidden exploit shell code. On opening such files, exploit shell […] - [Session 12 – Case Study: Rootkit Analysis](https://cysinfo.com/session-12-case-study-rootkit-analysis/): This session covered the concept of rootkit and demonstrated some of the techniques used by the rooktits.   Demo Video 1: Mader – SSDT Hooking  Demo Video 2: Prolaco – Process Hiding using DKOM Demo Video 3: Darkmegi/waltrodock – Installs Device Driver  Demo Video 4: Carberp – Syscall Patch and Inline Hooks - [Session 11 – Practical Reversing Part VI – Exploit Development [advanced]](https://cysinfo.com/session-11-practical-reversing-part-vi-exploit-development-advanced/): This session discussed some of the protections added by the operating system and processors to mitigate the exploitation, and also presented some ways to bypass those protections.   DemoVideo 1: Heap Spray  DemoVideo 2: Bypassing DEP   - [Session 10 – Practical Reversing Part V – Exploit Development [basic]](https://cysinfo.com/session-10-practical-reversing-part-v-exploit-development-basic/): This session covered the basic techniques of exploitation, some of these techniques may not work on latest operating system due various protections added into them. But these techniques are very crucial to understand the basic nature of exploit     Demo Video 1: EIP Overwrite Demo Video 2: SEH Overwrite - [Session 9 – Practical Reversing Part IV – Basic & Advanced Malware Analysis](https://cysinfo.com/session-9-practical-reversing-part-iv-basic-and-advanced-malware-analysis/): This session covered the concept of basic and advanced malware analysis.   Video Demo   Demo Video 1: Basic Malware Analysis   Demo Video 2: Advanced Malware Analysis - [Session 8 – Practical Reversing Part III – Malware Memory Forensics](https://cysinfo.com/session-8-practical-reversing-part-iii-malware-memory-forensics/): Memory forensics is an investigation technique which involves examining the computer’s memory for forensic artifacts. This presentation covers the concept of memory forensics and shows how to perform memory forensics using an investigation scenario.   Video Demo - [Session 7 – Practical ReversingPart II – Unpacking Malware](https://cysinfo.com/session-7-practical-reversingpart-ii-unpacking-malware/): In reverse engineering understanding cryptographic functions and packers are the two most challenging and sophisticated tasks. In real life virtually all malwares use some form of packing so understanding packing/unpacking is one of the most important task in malware analysis. Check the reference section for additional material. We highly recommend Lena151 (see reference) material for […] - [Session 6 – Practical Reversing Part I – Basic Reversing](https://cysinfo.com/session-6-practical-reversing-part-i-basic-reversing/): This session covers the concept of basic Reverse engineering. Malwares most of time uses packers and cryptors to thwart the analysis efforts, so it becomes important to understand the concept of unpacking. This presentation covers the concept of packer and a demo showing unpacking of packer called UPX.     Video Demo - [MalPimp](https://cysinfo.com/malpimp/): About Malpimp Malpimp is an advanced API tracing tool and designed to automate the reverse engineering process. In the backend it uses pydbg to hook the APIs. It provides include and exclude policies to increase the control on the application in execution. Being command-line tool makes it perfect for automation of malware as well as […] - [Session 5 – Reverse Engineering Basics and Tool Guide](https://cysinfo.com/session-5-reverse-engineering-basics-and-tool-guide/): Reverse engineering tools are essential in understanding the functionality and the inner workings of a binary. The presentation covers the concept of some of the commonly used reverse engineering tools. - [Session 4 – Assembly Programming Basics](https://cysinfo.com/session-4-assembly-programming-basics/): While Analyzing the malwares most of the time we don’t have its source code, so in order to understand their functionality one has to debug/disassemble the binary (executable, dll etc.), Understanding the assembly language will help you build a high level logic while your are debugging/disassembling the malware sample. - [Session 3 – Windows PE File Format Basics](https://cysinfo.com/session-3-windows-pe-file-format-basics/): This session covered the basic concept of PE File format which is the native Windows executable file format, good understanding of it will help in reverse engineering and will help in understanding more advanced concepts of packers, loaders etc. - [Session 2 – Introduction to Windows Internals](https://cysinfo.com/session-2-introduction-to-windows-internals/): This session covered the concept of Windows Internals. The concept of Windows internals will allow one to understand the working of Windows operating system. - [Session 1 – Reversing & Malware Analysis Lab Setup Guide](https://cysinfo.com/session-1-reversing-malware-analysis-lab-setup-guide/): This session will guide you to prepare your lab for malware analysis. - [Linux Memory Diff Analysis using Volatility](https://cysinfo.com/linux-memory-diff-analysis-using-volatility-2/): This blog post contains details of Linux Mem Diff Tool, this tool uses Volatility advanced memory forensics framework to run various plugins against the clean and infected Linux memory image and reports the changes. Similar tool to perform diff analysis on the Windows memory images can be found here Why this tool? Many times while […] - [Hunting and Decrypting Communications of Gh0st RAT in Memory](https://cysinfo.com/hunting-and-decrypting-communications-of-gh0st-rat-in-memory/): This blog post contains the details of detecting the encrypted Gh0st RAT communication, decrypting it and finding malicious Gh0st Rat artifacts (like process, network connections and DLL) in memory. I also present a Volatility (Advanced Memory Forensics Framework) plugin (ghostrat) which detects the encrypted Gh0st RAT communication, decrypts it and also automatically identifies the malicious […] - [Hunting APT RAT 9002 In Memory Using Volatility Plugin](https://cysinfo.com/hunting-apt-rat-9002-in-memory-using-volatility-plugin/): On Nov 10, 2013 FireEye published a blog about how the latest IE zero day exploit was used in the wild by the APT actors to serve 9002 RAT (aka Hydraq/McRat/Mdmbot). The FireEye blog also mentioned that the threat actors directly injected the payload of 9002 RAT into memory without writing to disk. This technique […] - [Cysinfo Cyber Security Meetup – 28th May 2016, Bangalore](https://cysinfo.com/cysinfo-cyber-security-meetup-28th-may-2016-bangalore/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 28th May 2016 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST. Here is Schedule of Security Talks: 09:30 – 10:10 Understanding Cryptolocker(ransomware) with a case […] - [Cysinfo Cyber Security Meetup – 30th January 2016](https://cysinfo.com/cysinfo-cyber-security-meetup-30th-january-2016/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 30th January 2016 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. Here is Schedule of Security Talks: 10:15 – 11:00 – Breaking into hospital […] - [Cysinfo Cyber Security Meetup – 10th October 2015](https://cysinfo.com/cysinfo-cyber-security-meetup-10th-october-2015/): Friendly reminder for the upcoming Cysinfo cyber security community meet on 10th October 2015 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. Here is Schedule of Security Talks: 10:00-10:45 – Partial Homomorphic Encryption – Sreelakshmy and Mythily […] - [Cysinfo Cyber Security Meetup – 23rd May 2015, Bangalore, India](https://cysinfo.com/cysinfo-cyber-security-meetup-23rd-may-2015-bangalore-india/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 23rd May 2015 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. After the meet, we will upload the presentations/videos for our online users to […] - [Cysinfo cyber security meet, 24th Jan - Bangalore](https://cysinfo.com/cysinfo-3rd-cyber-security-meet-24th-jan-bangalore/): Our upcoming Cysinfo cyber security community meet is on 24th January 2015 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. Looking forward to meet you all   Here is Schedule of Security Talks: 10:30-11:15 – Anatomy of Exploit […] - [Cysinfo Meet – 27th Sep 2014, Bangalore, India](https://cysinfo.com/cysinfo-2nd-meet-27th-sep-2014-bangalore-india/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 10th October 2015 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. Here is Schedule of Security Talks: 10:00-10:30 – Partial Homomorphic Encryption – Sreelakshmy and […] - [Cysinfo Meet – 21st June, Bangalore, India](https://cysinfo.com/cysinfo-meet-21st-june-bangalore-india/): This is an announcement for Cysinfo meet on 21st june 2014 in bangalore, india. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 10 AM IST. After the meet, we will upload the presentations/videos for our online users to our website. Talks: 10:30-11:30 – […] - [CYSINFO CYBER SECURITY MEETUP – 18th July 2026](https://cysinfo.com/cysinfo-cyber-security-meetup-18th-july-2026/): We’re thrilled to announce the upcoming Cysinfo Cybersecurity Community Meetup, scheduled on Saturday, 18th July 2026, at Vemana Institute of Technology, Bangalore. The meetup will start at 9:30 AM IST and is completely free and open to everyone — students, professionals, and enthusiasts alike. All you need to do is register below to attend. Cysinfo meets are all about sharing knowledge and building connections within the cybersecurity community. Just come with an open mind, curiosity, and the willingness to learn and share!. A big thank you to Vemana Institute of Technology and Vemana Business Incubation Center for supporting us and providing […] - [15th Quarterly Meetup – 22nd March 2026](https://cysinfo.com/15th-quarterly-meetup-22nd-march-2026/): In this meet, Nikhil Hegde presented on “Synthetic Threats: Using LLMs to Stress-Test Detection Systems”, Nagarjun Rallapalli & P P Shashwath Aiyappa presented on “Practical session on Agentic AI Attacks”, Divyanshu presented on “Automating Supply Chain Security with SBOM Using Syft and Grype”, and Monnappa K A presented on “Hunting Advanced Threats Using Endpoint Telemetry.” Here are the links to presentations and video demonstrations Here are a few snapshots from the sessions - [15th Quarterly Meetup – Automating Supply Chain Security with SBOM Using Syft and Grype](https://cysinfo.com/15th-quarterly-meetup-automating-supply-chain-security-with-sbom-using-syft-and-grype/): In this meet, Divyanshu presented on “Automating Supply Chain Security with SBOM Using Syft and Grype” - [15th Quarterly Meetup – Practical session on Agentic AI Attacks](https://cysinfo.com/15th-quarterly-meetup-practical-session-on-agentic-ai-attacks/): In this meet, Nagarjun Rallapalli & P P Shashwath Aiyappa presented on “Practical session on Agentic AI Attacks” - [15th Quarterly Meetup – Synthetic Threats: Using LLMs to Stress-Test Detection Systems](https://cysinfo.com/15th-quarterly-meetup-synthetic-threats-using-llms-to-stress-test-detection-systems/): In this meet, Nikhil Hegde presented on “Synthetic Threats: Using LLMs to Stress-Test Detection Systems” - [15th Quarterly Meetup – Hunting Advanced Threats Using Endpoint Telemetry](https://cysinfo.com/15th-quarterly-meetup-hunting-advanced-threats-using-endpoint-telemetry/): In this meet, Monnappa K A presented on “Hunting Advanced Threats Using Endpoint Telemetry” - [CYSINFO CYBER SECURITY MEETUP – 21st March 2026](https://cysinfo.com/cysinfo-cyber-security-meetup-21st-march-2026/): We’re thrilled to announce the upcoming Cysinfo Cybersecurity Community Meetup, scheduled on Saturday, 21st March 2026, at Vemana Institute of Technology, Bangalore. The meetup will start at 9:30 AM IST and is completely free and open to everyone — students, professionals, and enthusiasts alike. All you need to do is register below to attend. Cysinfo meets are all about sharing knowledge and building connections within the cybersecurity community. Just come with an open mind, curiosity, and the willingness to learn and share!. A big thank you to Vemana Institute of Technology for supporting us and providing the venue. 🙏 Join us […] - [14th Quarterly Meetup – 16th November 2025](https://cysinfo.com/14th-quarterly-meetup-16th-november-2025/): In this meet, Saqeeb presented on “The Ultimate Serial Port Detective – Baudowl”, Surya Teja presented on “Detecting Bad Apples: Understanding macOS Malware TTPs”, Adity Roy and Nikita Biradar presented on “Attacking and Defending AI” and Monnappa K A presented on “Threat Hunting with Garuda: From Manual Analysis to AI-Driven Hunting” Here are the links to presentations and video demonstrations Here are a few snapshots from the sessions - [14th Quarterly Meetup – Threat Hunting with Garuda: From Manual Analysis to AI-Driven Hunting](https://cysinfo.com/14th-quarterly-meetup-threat-hunting-with-garuda-from-manual-analysis-to-ai-driven-hunting/): In this meet, Monnappa K A presented on “Threat Hunting with Garuda: From Manual Analysis to AI-Driven Hunting” - [14th Quarterly Meetup – Attacking and Defending AI](https://cysinfo.com/14th-quarterly-meetup-attacking-and-defending-ai/): In this meet, Adity Roy and Nikita Biradar presented on “Attacking and Defending AI” - [14th Quarterly Meetup – The Ultimate Serial Port Detective – Baudowl](https://cysinfo.com/14th-quarterly-meetup-the-ultimate-serial-port-detective-baudowl/): In this meet, Saqeeb presented on “The Ultimate Serial Port Detective – Baudowl” - [14th Quarterly Meetup – Detecting Bad Apples: Understanding macOS Malware TTPs](https://cysinfo.com/14th-quarterly-meetup-detecting-bad-apples-understanding-macos-malware-ttps/): In this meet, Surya Teja presented on “Detecting Bad Apples: Understanding macOS Malware TTPs” - [Introduction to Threat Hunting Using Garuda Framework](https://cysinfo.com/introduction-to-threat-hunting-using-garuda-framework/): The Garuda Threat Hunting Framework, released at DEF CON 2025, is a PowerShell-based framework designed to simplify manual threat hunting. It allows you to correlate, filter, and investigate Sysmon events efficiently. In this video, I demonstrate how to install Garuda, explore its key features, and perform a step-by-step hunt of a Living-off-the-Land (LoLbin) attack using real telemetry data. If you’re interested in learning how to use Garuda effectively for endpoint investigations and enhance your manual hunting skills, watch the full video here: In case you missed my previous video on how Garuda integrates with LLM to perform AI-powered threat hunting, here […] - [CYSINFO CYBER SECURITY MEETUP – 15th November 2025](https://cysinfo.com/cysinfo-cyber-security-meetup-15th-november-2025/): We’re thrilled to announce the upcoming Cysinfo Cybersecurity Community Meetup, scheduled on Saturday, 15th November 2025, at Vemana Institute of Technology, Bangalore. The meetup will start at 9:30 AM IST and is completely free and open to everyone — students, professionals, and enthusiasts alike. All you need to do is register below to attend. Cysinfo meets are all about sharing knowledge and building connections within the cybersecurity community. Just come with an open mind, curiosity, and the willingness to learn and share!. A big thank you to Vemana Institute of Technology for supporting us and providing the venue. 🙏 Join us […] - [AI-Powered Threat Hunting Using Garuda Framework](https://cysinfo.com/ai-powered-threat-hunting-using-garuda-framework/): In this video, we explore how AI enhances threat hunting by integrating Large Language Models (LLMs) with the Garuda Threat Hunting Framework. Garuda is a manual, PowerShell-based threat hunting and investigation framework designed to transform raw Sysmon telemetry into structured, actionable intelligence for Windows environments. It allows you to correlate, filter, and analyze sysmon events more efficiently. The video demonstrates how Garuda, when combined with the reasoning and automation capabilities of LLMs, enables AI-powered autonomous threat hunting—allowing analysts to automatically detect anomalies, correlate TTPs, and uncover adversary activity. To get idea of how to use Garuda Framework for manual threat hunting, […] - [13th Quarterly Meetup - 9th March 2019](https://cysinfo.com/13th-quarterly-meetup-9th-march-2019/): In this meet, Ashwin Shenoi presented on “Closer look at PHP Unserialization” , Monnappa K A presented on “Understanding Malware Persistence Techniques” , Shruti Dixit & Geethna TK presented on “Getting started with cybersecurity through CTFs” , Akul Pillai presented on “A look into the sanitizer family (ASAN & UBSAN)” , Vikram Kharvi presented on “Understanding & analyzing obfuscated malicious web scripts” and Amar Prusty presented on “Emerging Trends in Cybersecurity” Here is the link to presentations and video demonstrations Closer look at PHP Unserialization Understanding Malware Persistence Techniques Getting started with cybersecurity through CTFs A look into the sanitizer family (ASAN & […] - [13th Quarterly Meetup - Closer look at PHP Unserialization](https://cysinfo.com/13th-quarterly-meetup-closer-look-at-php-unserialization/): In this meet, Ashwin Shenoi delivered presentation on “GCloser look at PHP Unserialization” Video Demo - [13th Quarterly Meetup - Understanding Malware Persistence Techniques](https://cysinfo.com/13th-quarterly-meetup-understanding-malware-persistence-techniques/): In this meet, Monnappa K A delivered presentation on “Understanding Malware Persistence Techniques” Demo 1 – Understanding the IFEO Technique Demo 2 – Malware Using IFEO (Trojan.Zusy) Demo 3 – Simple Anti-Analysis Using IFEO (Trojan.Small) Demo 4 – Simple Anti-Analysis using IFEO (Brontok Worm) Demo 5 – Winlogon Persistence (Turla gazer backdoor) Demo 6 –  Persistence Through Accessibility Programs (Trojan Occamy) Demo 7 – Persistence Through AppInit DLLs (T9000 APT Backdoor) Demo 8 – DLL Search Order Hijacking - [13th Quarterly Meetup - Getting started with cybersecurity through CTFs](https://cysinfo.com/13th-quarterly-meetup-getting-started-with-cybersecurity-through-ctfs/): In this meet, Shruti Dixit & Geethna TK delivered presentation on “Getting started with cybersecurity through CTFs” - [13th Quarterly Meetup - A look into the sanitizer family (ASAN & UBSAN)](https://cysinfo.com/13th-quarterly-meetup-a-look-into-the-sanitizer-family-asan-ubsan/): In this meet, Akul Pillai delivered presentation on “A look into the sanitizer family (ASAN & UBSAN)” Demo 1 Demo 2: - [13th Quarterly Meetup - Understanding & analyzing obfuscated malicious web scripts](https://cysinfo.com/13th-quarterly-meetup-understanding-analyzing-obfuscated-malicious-web-scripts/): In this meet, Vikram Kharvi delivered presentation on “Understanding & analyzing obfuscated malicious web scripts” - [13th Quarterly Meetup - Emerging Trends in Cybersecurity](https://cysinfo.com/13th-quarterly-meetup-emerging-trends-in-cybersecurity/): In this meet, Amar Prusty delivered presentation on “Emerging Trends in Cybersecurity” - [CYSINFO CYBER SECURITY MEETUP – 9th March 2019](https://cysinfo.com/cysinfo-cyber-security-meetup-9th-march-2019/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 9th March 2019 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST. We would like to thank Amrita University and Amrita TBI for supporting and providing us the venue for the meet. Venue:Amrita University (Amrita Vishwa Vidyapeetham)Bengaluru CampusKasavanahalli, Carmelaram P.O.Bengaluru – 560 035India Google Maps Link: https://goo.gl/maps/suwS63XFHtA2 How to Reach the venue: https://www.amrita.edu/campus/bengaluru/reach-us Contact Details: Email: contact@cysinfo.com Join our Mailing list to get to know our inside story and for […] - [AzorUlt Version 2: Atrocious Spyware infection using 3 in 1 RTF Document](https://cysinfo.com/azorult-version-2-atrocious-spyware-infection-using-3-1-rtf-document/): Hey there! We have seen plenty of Spam mail campaigns carrying RTF document, which exploits infamous vulnerabilities to compromise end user machines with various malware. Now Let me Ask you something.. Were all the systems in your network patched for CVE-2017-11882, CVE-2017-8759 and CVE-2017-0199? If the answer is NO, you are prone to be compromised with this Malicious RTF document!!! This single RTF document carries 3 infamous exploits, desperately tries to exploit with at least one and then tries infecting the user machine with an Atrocious Spyware – AzorUlt Version 2. Lets Jump in… All started when the end users at a […] - [12th Quarterly Meetup - 17th Feb 2018](https://cysinfo.com/12th-quarterly-meetup-17th-feb-2018/): In this meet, Akhil Mahendra​​​ presented on “The Art of Executing JavaScript” , Monnappa K A presented on “Reversing and Decrypting Malware Communications” , Abhishek J.M presented on “Analysis of Android APK using Adhrit” , Sreelakshmi presented on “DeViL – Detect Virtual Machine in Linux” , Swaroop Yermalkar presented on “OWASP iGoat – A Learning Tool for iOS App Pentesting and Security” and Akshay Ajayan presented on “Unicorn: The Ultimate CPU Emulator” Here is the link to presentations and video demonstrations: The Art of Executing JavaScript Reversing and Decrypting Malware Communications Analysis of Android APK using Adhrit DeViL – Detect Virtual Machine in […] - [12th Meetup - Unicorn: The Ultimate CPU Emulator](https://cysinfo.com/12th-meetup-unicorn-ultimate-cpu-emulator/): In this meet, Akshay Ajayan delivered presentation on “Unicorn: The Ultimate CPU Emulator” - [12th Meetup - DeViL - Detect Virtual Machine in Linux](https://cysinfo.com/12th-meetup-devil-detect-virtual-machine-linux/): In this meet, Sreelakshmi​​​ delivered presentation on “DeViL – Detect Virtual Machine in Linux” - [12th Meetup - Analysis of Android APK using Adhrit](https://cysinfo.com/12th-meetup-analysis-android-apk-using-adhrit/): In this meet, Abhishek J.M delivered presentation on “Analysis of Android APK using Adhrit” - [12th Meetup - Reversing and Decrypting Malware Communications](https://cysinfo.com/12th-meetup-reversing-decrypting-malware-communications/): In this meet, Monnappa K A delivered presentation on “Reversing and Decrypting Malware Communications”   Video Demo 1: Video Demo 2: Video Demo 3: References: http://www.arbornetworks.com/asert/2014/06/illuminating-the-etumbot-apt-backdoor/ http://www.fireeye.com/blog/technical/botnet-activities-research/2014/09/darwins-favorite-apt-group-2.html - [12th Meetup – The Art of Executing JavaScript](https://cysinfo.com/12th-meetup-art-executing-javascript/): In this meet, Akhil Mahendra​​​ delivered presentation on “The Art of Executing JavaScript”   Demo: CSP bypass https://www.youtube.com/watch?v=LUtWj3stVlU Demo: angular js xss https://www.youtube.com/watch?v=xecuNPanQJA - [CYSINFO CYBER SECURITY MEETUP – 17TH Feb 2018](https://cysinfo.com/cysinfo-cyber-security-meetup-17th-feb-2018/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 17th Feb 2018 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST. We would like to thank Amrita University and Amrita TBI for supporting and providing us the venue for the meet.   Venue: Amrita University (Amrita Vishwa Vidyapeetham) Bengaluru Campus Kasavanahalli, Carmelaram P.O. Bengaluru – 560 035 India Google Maps Link: https://goo.gl/maps/suwS63XFHtA2 How to Reach the venue: https://www.amrita.edu/campus/bengaluru/reach-us Contact Details: Email: contact@cysinfo.com Join our Mailing list to get to […] - [11th Quarterly Meetup – 29TH July 2017](https://cysinfo.com/11th-quarterly-meetup-29th-july-2017/): In this meet, Ashutosh Ahelleya presented on “Bit Flipping Attack on AES-CBC” , Monnappa K A presented on “Understanding Evasive Hollow Process Injection techniques” , Siddharth Muralee presented on “Dynamic Binary Analysis using angr” , Ajithkumar Vyasarao presented on “Security Challenges in D2D Communication” and Shivkrishna A presented on “S2E (Selective Symbolic Execution)” Here is the link to presentations and video demonstrations: Bit Flipping Attack on AES-CBC Understanding Evasive Hollow Process Injection techniques Dynamic Binary Analysis using angr Security Challenges in D2D Communication S2E (Selective Symbolic Execution)   Here are the few snapshots from the session   - [11th Meetup - S2E (Selective Symbolic Execution)](https://cysinfo.com/11th-meetup-s2e-selective-symbolic-execution/): In this meet, Shivkrishna A delivered presentation on “S2E (Selective Symbolic Execution)” - [11th Meetup - Security Challenges in D2D Communication](https://cysinfo.com/11th-meetup-security-challenges-in-d2d-communication/): In this meet, Ajithkumar Vyasarao delivered presentation on “Security Challenges in D2D Communication” - [11th Meetup - Dynamic Binary Analysis using angr](https://cysinfo.com/11th-meetup-dynamic-binary-analysis-using-angr/): In this meet, Siddharth Muralee delivered presentation on “Dynamic Binary Analysis using angr” - [11th Meetup - Understanding Evasive Hollow Process Injection techniques](https://cysinfo.com/11th-meetup-understanding-evasive-hollow-process-injection-techniques/): In this meet, Monnappa K A delivered presentation on “Understanding Evasive Hollow Process Injection techniques”   Demo1: Investigating Taidoor’s Evasive Hollow Process Injection Demo2: Investigating Kuluoz’s Evasive Hollow Process Injection. Demo3: Investigating Modified Kuluoz’s Evasive Hollow Process Injection Demo4: Investigating Kronos malware’s Evasive Hollow Process Injection   - [11th Meetup - Bit Flipping Attack on AES-CBC](https://cysinfo.com/11th-meetup-bit-flipping-attack-on-aes-cbc/): In this meet, Ashutosh Ahelleya delivered presentation on “Bit Flipping Attack on AES-CBC” - [Karo Ransomware - Which played Hide n seek behind "Petya" Wiper waves!](https://cysinfo.com/karo-ransomware-played-hide-n-seek-behind-petya-wiper-waves/): In between the waves of Petya Ransomware-wiper, another serious ransomware were spreading across, The “Karo Ransomware”. The initial vector being spam mails with a document file. The document file is password protected and this malware is Virtualization aware and refuses to run in sandboxes. Once infected Karo encrypts the files with the (.ipygh) extension and it will communicate with the TOR Command and communication server. Lets Jump in.. One of the spam mail originated from an e-mail address “johnitgbwp[at]outlook.com” Once the user tries to open the document, a password popup will appear to enter the password which is in the body of […] - [CYSINFO CYBER SECURITY MEETUP – 29TH July 2017](https://cysinfo.com/cysinfo-cyber-security-meetup-29th-july-2017/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 29th July 2017 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST. We would like to thank  Amrita University and Amrita TBI for supporting and providing us the venue for the meet.   Venue: Amrita University (Amrita Vishwa Vidyapeetham) Bengaluru Campus Kasavanahalli, Carmelaram P.O. Bengaluru – 560 035 Karnataka, India Google Maps Link: https://goo.gl/maps/suwS63XFHtA2 How to Reach the venue: https://www.amrita.edu/campus/bengaluru/reach-us Contact Details: Email: contact@cysinfo.com Join our Mailing list to get to […] - [A Journey From Loki Bot Campaign To Venom Spyware](https://cysinfo.com/journey-loki-bot-campaign-venom-spyware/): SUMMARY When it comes to Macro Malware, several people try to finish it off with two workarounds, Disable Macro (GPO) and user awareness. That said what if a malicious document doesn’t use Macro codes to do its malicious tasks? What if a document is exploiting a vulnerability to do its malicious activities? That said, Let me invite you to a very new spam mail campaign happened or happening around the Globe, mostly GCC countries, as of this writing, which doesn’t use any Macro codes. This write up will be a journey from the initial spam mail which the user received in […] - [Cyber Attack Impersonating Identity of Indian Think Tank to Target Central Bureau of Investigation (CBI) and Possibly Indian Army Officials](https://cysinfo.com/cyber-attack-targeting-cbi-and-possibly-indian-army-officials/): In my previous blog posts I posted details of cyber attacks targeting Indian Ministry of External Affairs and Indian Navy’s Warship and Submarine Manufacturer. This blog post describes another attack campaign where attackers impersonated identity of Indian think tank IDSA (Institute for Defence Studies and Analyses) and sent out spear-phishing emails to target officials of the Central Bureau of Investigation (CBI) and possibly the officials of Indian Army. IDSA (Institute for Defence Studies and Analyses) is an Indian think tank for advanced research in international relations, especially strategic and security issues, and also trains civilian and military officers of the Government […] - [Aadhar:  Good, Bad And Ugly](https://cysinfo.com/aadhar-good-bad-ugly/): Before I begin I would like to quote current Attorney General of India “The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi What is Aadhar ? From food rations to marriage certificates, entrance exams to train ticket concessions, mobile phone cards to banking, Indians are now being asked to produce a 12-digit […] - [Analysis of Shadow Brokers Release - Operation Center](https://cysinfo.com/analysis-shadow-brokers-release-operation-center/): We have always been curious to know about what goes on inside the state sponsored security agencies like NSA (National Security Agency). Since the agency is known to operate on multiple spying operations in the past for tracking criminals and terrorists, it might sometimes need the use of zero day exploits to get into targeted systems. Last week a hacker group named “Shadow Brokers” released some malicious programs and tools that were actually used by the Equation Group of NSA for spying. The most popular release was FuzzBunch (FB) and Operation Center (OC).   We have analyzed these tools and these […] - ["Agent Tesla" New Spyware Variant plucked from Hacker’s Arena !](https://cysinfo.com/agent-tesla-new-spyware-variant-plucked-hackers-arena/): Hello there!  before we begin our journey, spare some time to update the below spyware signature (No detections anywhere) in all your controls, which digests IOCs: MD5 – 68AB498574C0BEAE225A04D04A2571A1 (new variant of spyware) NB: The day was sunny and was analyzing a targeted spam mail and its attached macro malware – normal routine 🙂 But this investigation , lead me to a brand new variant of spyware which has no detection as of this writing. This whole article circles around phishing, macro malware, its command and control, creeping into command and control and then finding another brand new spyware which is yet […] - [Episode 3 - Shellcode Analysis with APITracker](https://cysinfo.com/episode-3-shellcode-analysis-apitracker/): Text: Audience Level: Beginner to Medium. Few months back we released our new tool APITacker. The idea behind the tool is more mature than the tool itself. Using APITracker we can hook APIs on large scale from DLLs to track the execution of the sample. APITracker is based on pydbg python debugger. Before we move on to the shellcode analysis lets take a look at the config file of the APITracker. APITracker: https://cysinfo.com/apitracker-windows-api-tracing-tool/ *Error Correction: In video, shellcode is not using any hash based API resolver. The values are basically the ascii values for API names.           - [New Password Protected Macro Malware evades Sandbox and Infects the victims with Ursnif Malware !!](https://cysinfo.com/new-password-protected-macro-malware-evades-sandbox-infects-victims-ursnif-malware/): These days, Along with the unforeseen climatic conditions, several unpredictable malware campaigns are also occurring across the connected world. Mostly Offenders are relying on spam mails and the associated malicious Macros, to drop and infect the targeted victims with various other atrocious malware. Studies shows 95% of successful security attacks created by Human mistakes!! Security sensitive entities are hardening the controls to their maximum to escape from these types of campaigns or infections. On the other hand, malware authors are taking lot of inventive steps to evade these, so-called ‘hardened security controls’. That said, Lets jump into a very latest Document malware, […] - [10th Quarterly Meetup – 25th February 2017](https://cysinfo.com/10th-quarterly-meetup-25th-february-2017/): In this meet, Jiggyasu Sharma presented on “Tracking Attacks Using Hospital Honeypots” , Abhishek Bhuyan presented on “Security Analytics using ELK stack” , Heeraj Nair presented on “XXE – XML External Entity Attack” , Monnappa K A presented on “Linux Malware Analysis” , Aswin M Guptha presented on “Introduction to Binary Exploitation” and Amit Malik presented on “ATM Malware: Understanding the threat” Here is the link to presentations and video demonstrations: Tracking Attacks Using Hospital Honeypots Security Analytics using ELK stack XXE – XML External Entity Attack Linux Malware Analysis Introduction to Binary Exploitation ATM Malware: Understanding the threat   Here are the few snapshots […] - [10th Meetup - ATM Malware: Understanding the threat](https://cysinfo.com/10th-meetup-atm-malware-understanding-threat/): In this meet, Amit Malik delivered presentation on “ATM Malware: Understanding the threat”   - [10th Meetup - Introduction to Binary Exploitation](https://cysinfo.com/10th-meetup-introduction-binary-exploitation/): In this meet, Aswin M Guptha delivered presentation on “Introduction to Binary Exploitation” - [10th Meetup - Linux Malware Analysis](https://cysinfo.com/10th-meetup-linux-malware-analysis/): In this meet,Monnappa K A delivered presentation on “Linux Malware Analysis” Demo 1 – Analysis of Linux malware Tsunami using Limon Sandbox  Demo 2a – Analysis of Linux Malware Mayhem using Limon: Demo 2b – Examining the malicious exit() function of Linux malware mayhem :   - [10th Meetup - XXE - XML External Entity Attack](https://cysinfo.com/10th-meetup-xxe-xml-external-entity-attack/): In this meet, Heeraj Nair delivered presentation on “XXE – XML External Entity Attack ”   - [10th Meetup - Security Analytics using ELK stack](https://cysinfo.com/10th-meetup-security-analytics-using-elk-stack/): In this meet, Abhishek Bhuyan delivered presentation on “Security Analytics using ELK stack” - [Hype vs Truth: State of Detection Technologies](https://cysinfo.com/hype-vs-truth-state-detection-technologies/): Introduction: Sensors were bleeping but still high value assets got compromised, emergency response team was called and asked for the most important question “we have detection technology from five vendors, how is that possible?”. A piece of code bypassed the world’s most innovative technologies for detection on this earth. It is not a simple situation but interestingly it is a relatively common situation in breaches. At the same time it raises some serious questions: are detection technologies so weak or that piece of code is something truly sophisticated? As a matter of fact the truth is majority of the time that […] - [Nefarious Macro Malware drops “Loki Bot” to steal sensitive information across GCC countries!](https://cysinfo.com/nefarious-macro-malware-drops-loki-bot-across-gcc-countries/): Macro malware are still playing its atrocious activities in the wild, frightening all the sectors around the globe. Latest Spam campaign which flew around GCC countries created a “scary rain” across multiple entities. This spam mail was not targeted only for a particular entity, but extensively across multiple firms in Middle east, anticipating huge number of victims. On the other hand, the recipients in these mails (BCC) were clearly social engineered. NB: The malware and associated files were analyzed within private secured environment, without actually allowing it to communicate to its command and control While analyzing, we may come across with unhygienic […] - [Cyber Attack Targeting Indian Navy's Submarine and Warship Manufacturer](https://cysinfo.com/cyber-attack-targeting-indian-navys-submarine-warship-manufacturer/): In my previous blog posts I described attack campaigns targeting Indian government organizations, and  Indian Embassies and Ministry of External affairs. In this blog post I describe a new attack campaign where cyber espionage group targeted the users of Mazagon Dock Shipbuilders Limited (also called as ship builder to the nation). Mazagon Dock Shipbuilders Limited (MDL) is a Public Sector Undertaking of Government of India (Ministry of Defence) and it specializes in manufacturing warships and submarines for the Indian Navy. In order to infect the users associated with Mazagon Dock Shipbuilders Limited (MDL), the attackers distributed spear-phishing emails containing malicious excel […] - [CYSINFO CYBER SECURITY MEETUP – 25TH FEBRUARY 2017](https://cysinfo.com/cysinfo-cyber-security-meetup-25th-february-2017/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 25th February 2017 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST. Venue: Amrita University (Amrita Vishwa Vidyapeetham) Bengaluru Campus Kasavanahalli, Carmelaram P.O. Bengaluru – 560 035 Karnataka, India Google Maps Link: https://goo.gl/maps/suwS63XFHtA2 How to Reach the venue: https://www.amrita.edu/campus/bengaluru/reach-us Contact Details: Email: contact@cysinfo.com Join our Mailing list to get to know our inside story and for more interactive discussion with experts.   Note: Lunch will not be provided by us. The College canteen will be open. - [Uri Terror attack & Kashmir Protest Themed spear phishing emails targeting Indian Embassies and Indian Ministry of external affairs](https://cysinfo.com/uri-terror-attack-spear-phishing-emails-targeting-indian-embassies-and-indian-mea/): In my previous blog I posted details of a cyber attack targeting Indian government organizations. This blog post describes another attack campaign where attackers used the Uri terror attack and Kashmir protest themed spear phishing emails to target officials in the Indian Embassies and Indian Ministry of External Affairs (MEA). In order to infect the victims, the attackers distributed spear-phishing emails containing malicious word document which dropped a malware capable of spying on infected systems. The email purported to have been sent from legitimate email ids. The attackers spoofed the email ids associated with Indian Ministry of Home Affairs to send […] - [Indian Cyber Space and Privacy: Legal Perspective](https://cysinfo.com/indian-cyber-space-privacy-legal-perspective/): What is so great about these internet companies that they, provide consumer’s/user’s access to their services so easily and usually that too for no apparent charges at all? As an internet strong market, Indian citizens or users from India are on the grid of all internet companies. Besides as was evident from recently concluded general elections, trends of marketing – aptly, targeted marketing were no different in election canvassing from product promotions of small or big products. In fact, lately, a huge amount of attention has been paid to government snooping, and the bulk collection and storage of vast amounts of […] - [Malware Actors Using NIC Cyber Security Themed Spear Phishing to Target Indian Government Organizations](https://cysinfo.com/malware-actors-using-nic-cyber-security-themed-spear-phishing-target-indian-government-organizations/): This blog post describes an attack campaign where NIC (National Informatics Centre) Cyber Security themed spear phishing email was used to possibly target Indian government organizations. In order to infect the victims, the attackers distributed spear-phishing email, which purports to have been sent from NIC’s Incident response team, the attackers spoofed an email id that is associated with Indian Ministry of Defence to send out email to the victims. Attackers also used the name of the top NIC official in the signature of the email, this is to make it look like the email was sent by a high ranking Government […] - [9th Quarterly Meetup – 19th November 2016](https://cysinfo.com/9th-quarterly-meetup-19th-november-2016/): In this meet, Abhijit Mohanta  delivered presentation on “Malware Detection using Machine Learning “,Ajay Kumar  presented on “Deep Web – what to do and what not to do ”, Adithya Naresh presented on “Introduction to ICS/SCADA security ”,Amit Malik  presented on “POS Malware: Is your Debit/Credit Transcations Secure? ”,Rakesh Paruchuri  presented on “Format String Vulnerability ”, Jayakrishna Menon  presented on “Dynamic Binary Instrumentation ”, Parth Parmar presented on “Image (PNG) Forensic Analysis ” and Monnappa K A presented on “Investigating Malicious Office Documents: Analyzing Macros Malwares used in Cyber Attacks ” Here is the link to presentations and video demonstrations: Malware Detection using Machine Learning Deep Web – what to do […] - [9th Quarterly Meetup – Image (PNG) Forensic Analysis](https://cysinfo.com/9th-quarterly-meetup-image-png-forensic-analysis/): In this meet, Parth Parmar delivered presentation on “Image (PNG) Forensic Analysis ” - [9th Meetup - Introduction to ICS/SCADA security](https://cysinfo.com/9th-meetup-introduction-icsscada-security/): In this meet, Adithya Naresh delivered presentation on “Introduction to ICS/SCADA security” - [9th Meetup - Dynamic Binary Instrumentation](https://cysinfo.com/9th-meetup-dynamic-binary-instrumentation/): In this meet, Jayakrishna Menon delivered presentation on “Dynamic Binary Instrumentation”. The scripts used in the presentation can be downloaded from GitHub   Video Demo :  - [9th Meetup - Format String Vulnerability](https://cysinfo.com/9th-meetup-format-string-vulnerability/): In this meet, Rakesh Paruchuri delivered presentation on “Format String Vulnerability” - [9th Meetup - POS Malware: Is your Debit/Credit Transactions Secure?](https://cysinfo.com/9th-meetup-pos-malware-debitcredit-transactions-secure/): In this meet, Amit Malik delivered presentation on “POS Malware: Is your Debit/Credit Transactions Secure” - [9th Meetup - Deep Web - what to do and what not to do](https://cysinfo.com/9th-meetup-deep-web-not/): In this meet, Ajay Kumar delivered presentation on “Deep Web – what to do and what not to do ” - [9th Meetup - Malware Detection using Machine Learning](https://cysinfo.com/9th-meetup-malware-detection-using-machine-learning/): In this meet, Abhijit Mohanta delivered presentation on “Malware Detection using Machine Learning ” - [What will happen to your virtual property after your life time?](https://cysinfo.com/virtual-property/): Introduction Lately a lot of my clients have raised queries about getting legitimate access to virtual accounts and e- properties of their deceased loved ones. Analyzing these queries I intend to explain the complexity and solution to simplify legal and practical issues so emanating out in form of a virtual property will. In today’s world use, of computers, storage devices and software(s) is no more an option or utility but a necessity. While this virtual reality opens gateway to new form of user experience(s), gaming, data depositions, creative, social interactions and revenue generation models it also calls for an interpretation of […] - [Psinfo](https://cysinfo.com/psinfo/): Psinfo is a Volatility plugin which collects the process related information from the VAD (Virtual Address Descriptor) and PEB (Process Enivornment Block) and displays the collected information and suspicious memory regions for all the processes running on the system. This plugin should allow a security analyst to get the process related information and spot any process anamoly without having to run multiple plugins. - [HollowFind](https://cysinfo.com/hollowfind/):   Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect and divert the forensic analysis techniques. The plugin detects such attacks by finding discrepancy in the VAD and PEB, it also disassembles the address of entry point to detect any redirection attempts and also reports any suspicious memory regions which should help in detecting any injected code. - [CYSINFO CYBER SECURITY MEETUP – 19TH NOVEMBER 2016](https://cysinfo.com/cysinfo-cyber-security-meetup-19th-november-2016/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 19th November 2016 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST.     Venue: Amrita University (Amrita Vishwa Vidyapeetham) Bengaluru Campus Kasavanahalli, Carmelaram P.O. Bengaluru – 560 035 Karnataka, India Google Maps Link: https://goo.gl/maps/suwS63XFHtA2 How to Reach the venue: https://www.amrita.edu/campus/bengaluru/reach-us Contact Details: Email: contact@cysinfo.com Join our Mailing list to get to know our inside story and for more interactive discussion with experts.   Note: Lunch will not be provided by us. The College canteen will […] - [Cyber Security with Amit Malik - Episode 2 - Macro Code De-obfuscation using Vbscript Debugger](https://cysinfo.com/cyber-security-amit-malik-episode-2-macro-code-de-obfuscation-using-vbscript-debugger/): Video: Text: Audience Level: Internet user, Mid level Analyst Prerequisite: Programming Language Introduction: Obfuscation: https://en.wikipedia.org/wiki/Obfuscation_(software) Infection Method: Malicious documents are mostly delivered through email campaigns. The attacker send the tailored email to the victim with the malicious email attachment or a malicious web link. Once the victim open the malicious document it will download the malware from the internet and execute it on the victim machine. Case Study: Hades Ransomeware: https://www.proofpoint.com/us/threat-insight/post/hades-locker-ransomware-mimics-locky Password Protected Doc: https://resources.netskope.com/h/i/295024584-nitol-botnet-makes-a-resurgence-with-evasive-sandbox-analysis-technique (Its a bit lengthy, I will discuss only the analysis of dropped VBS file.) Analysis: We will use the code from previous episode to extract the […] - [APITracker - Windows API Tracing tool](https://cysinfo.com/apitracker-windows-api-tracing-tool/): APITracker is a major update to our tool Malpimp. It follows the same methodology for hooking and reporting but with an enhanced feature set and more stable logging options. New to APITracker: 1.Server Logging: APItracker can send the api logs on the remote server so you don’t have to worry about ransomewares etc. 2.Parameters: APItracker can also report the API parameters in a dynamic approach.. we can change the number of parmaters as per our requirements. 3.Heap Only logging: APITracker support heap only logging means by enabling the logheap option in config file it will only report the API calls that […] - [Cyber Security with Amit Malik - Episode 1 - Macro Analysis](https://cysinfo.com/cyber-security-amit-malik-episode-1-macro-analysis/): Video Link: Text: Audience Level: Beginner, Internet user Prerequisite: Python programming language Introduction: In this week I will discuss about the macro analysis since macros are one of the top threat today to compromise/infect the endpoint machines. These days the macro based downloaders download ransomeware, POS malware and other banking trojans so the investigation of the office documents is crucial. So in this session I will discuss about the tools and techniques to analyse the macro malwares. Infection Method: Malicious documents are mostly delivered through email campaigns. The attacker send the tailored email to the victim with the malicious email attachment. […] - [Detecting Malicious Processes Using Psinfo Volatility Plugin](https://cysinfo.com/detecting-malicious-processes-psinfo-volatility-plugin/): In the previous post we looked at HollowFind Volatility plugin and saw how it can detect different process hollowing techniques and display those malicious processes which are victims of process hollowing . In this post lets look at another Volatility plugin called Psinfo. This plugin is similar to hollowfind plugin but instead of identifying the malicious processes, it collects the process related information from the VAD (Virtual Address Descriptor) and PEB (Process Enivornment Block) and displays the collected information and suspicious memory regions for all the processes running on the system. The reason for writing this plugin is to collect information […] - [Detecting Deceptive Process Hollowing Techniques Using HollowFind Volatility Plugin](https://cysinfo.com/detecting-deceptive-hollowing-techniques/): In this blog post we will look at different types of process hollowing techniques used in the wild to bypass, confuse, deflect and divert the forensic analysis. I also present a Volatility plugin hollowfind to detect these different types of process hollowing. Before looking at the different types of process hollowing, lets try to understand the normal process hollowing, its working and detection. To explain the normal process hollowing I will use memory image which is  infected with Stuxnet. What is Process Hollowing? Process Hollowing or Hollow Process Injection is a code injection technique in which the executable section of a […] - [8th Quarterly Meetup – 17th September 2016](https://cysinfo.com/8th-quarterly-meetup-17th-september-2016/): In this meet, Ajay pratap Singh delivered presentation on “Attacking and Crashing IoT Devices via Bluetooth LE protocol”,Monnappa K A presented on “Investigating Malware using Memory Forensics” and “Understanding APT1 malware techniques using malware analysis and reverse engineering”, Ajithkumar V presented on “Elliptic curve cryptography”, Abhishek J M presented on “Dissecting Android APK”, Amit Malik presented on “EMET evasion techniques detected in the wild”, Sameer Patil presented on “Exploits & Mitigations – Memory Corruption Techniques” and Veerababu Penugonda presented on “IOT Exploitation”. Here is the link to presentations and video demonstrations: Attacking and Crashing IoT Devices via Bluetooth LE protocol Investigating Malware using Memory Forensics Elliptic curve […] - [8th Meetup - Understanding APT1 malware techniques using malware analysis and reverse engineering](https://cysinfo.com/8th-meetup-understanding-apt1-malware-techniques-using-malware-analysis-reverse-engineering/): In this meet,Monnappa K A presented on “Understanding APT1 malware techniques using malware analysis and reverse engineering” Video Demo :  Part 1 – Behavioral Analysis Of APT1 WEBC2-DIV Part 2 – Reverse Engineering APT1 WEBC2-DIV Part 3 – Understanding the WEBC2-DIV Technique – Sleep Part 4 – Understanding the WEBC2-DIV Technique – Download - [8th Meetup - IOT Exploitation](https://cysinfo.com/8th-meetup-iot-exploitation/): In this meet, Veerababu Penugonda presented on “IOT Exploitation” - [8th Meetup - Exploits & Mitigations - Memory Corruption Techniques](https://cysinfo.com/8th-meetup-exploits-mitigations-memory-corruption-techniques/): In this meet,  Sameer Patil presented on “Exploits & Mitigations – Memory Corruption Techniques” - [8th Meetup - EMET evasion techniques detected in the wild](https://cysinfo.com/8th-meetup-emet-evasion-techniques-detected-wild/): In this meet, Amit Malik presented on “EMET evasion techniques detected in the wild” - [8th Meetup - Dissecting Android APK](https://cysinfo.com/8th-meetup-dissecting-android-apk/): In this meet, Abhishek J M presented on “Dissecting Android APK” Video Demo :  - [8th Meetup - Elliptic curve cryptography](https://cysinfo.com/8th-meetup-elliptic-curve-cryptography/): In this meet, Ajithkumar V presented on “Elliptic curve cryptography” - [8th Meetup - Investigating Malware using Memory Forensics](https://cysinfo.com/8th-meetup-investigating-malware-using-memory-forensics/): In this meet, Monnappa K A presented on “Investigating Malware using Memory Forensics” Video Demo: https://youtu.be/C6uUDl0Vc6E - [8th Meetup - Attacking and Crashing IoT Devices via Bluetooth LE protocol](https://cysinfo.com/8th-meetup-attacking-crashing-iot-devices-via-bluetooth-le-protocol/): In this meet, Ajay pratap Singh delivered presentation on “Attacking and Crashing IoT Devices via Bluetooth LE protocol”   - [CYSINFO CYBER SECURITY MEETUP – 17TH SEPTEMBER 2016](https://cysinfo.com/cysinfo-cyber-security-meetup-17th-september-2016/): This is an announcement for the upcoming Cysinfo cyber security community meetup on 17th September 2016 in Bangalore, India. This meet is completely free and doesn’t require any registration or any other formalities to attend. The meet will start at 9:30 AM IST.   Venue: Amrita University (Amrita Vishwa Vidyapeetham) Bengaluru Campus Kasavanahalli, Carmelaram P.O. Bengaluru – 560 035 Karnataka, India Google Maps Link: https://goo.gl/maps/suwS63XFHtA2 How to Reach the venue: https://www.amrita.edu/campus/bengaluru/reach-us Contact Details: Email: contact@cysinfo.com Join our Mailing list to get to know our inside story and for more interactive discussion with experts.   Note: Lunch will not be provided by us. The College canteen will […] - [Blackout - Memory Analysis of BlackEnergy Big dropper](https://cysinfo.com/blackout-memory-analysis-of-blackenergy-big-dropper/): In late December a cyber attack caused power outage for few hours in the Ivano-Frankivsk region in Ukraine as mentioned here. Threat researchers from ESET linked this attack to a malware called “BlackEnergy” which attacked electricity distribution companies in Ukraine. This blog post contains the memory analysis details of BlackEnergy big dropper (SHA-1:896FCACFF6310BBE5335677E99E4C3D370F73D96) mentioned in the ESET blog This post also covers the details of the user mode and kernel mode components of BlackEnergy Rootkit and also covers some of the stealth techniques of BlackEnergy Rootkit. Sandbox Analysis The analysis started by running the malware sample in the sandbox. Running the […] - [Limon Sandbox for Analyzing Linux Malwares](https://cysinfo.com/limon-sandbox-for-analyzing-linux-malwares-2/): A number of devices are running Linux due to its flexibility and open source nature. This has made Linux platform the target for malware attacks, so it becomes important to analyze the Linux malwares. Today, there is a need to analyze Linux malwares in an automated way to understand its capabilities. Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators of Linux malware. It allows one to inspect the Linux malware before execution, during execution, and after execution (post-mortem analysis) by performing static, dynamic and memory analysis […] - [Limon Linux Sandbox](https://cysinfo.com/limon-linux-sandbox/): A number of devices are running Linux due to its flexibility and open source nature. This has made Linux platform the target for malware attacks, so it becomes important to analyze the Linux malwares. Today, there is a need to analyze Linux malwares in an automated way to understand its capabilities. Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators of Linux malware. It allows one to inspect the Linux malware before execution, during execution, and after execution (post-mortem analysis) by performing static, dynamic and memory analysis […] - [Linux Mem Diff Tool](https://cysinfo.com/linux-memory-diff-analysis-using-volatility/): Many times while doing memory analysis (or malware analysis) an analyst would be presented with lots of data and analyst has to manually find the malicious artifacts from that data which takes time and effort. This tool helps in solving that problem by comparing the results between the clean and infected memory images. This tool helps speed up analysis, reduce manual effort and allows you to focus on the relevant data.This tool helps us to perform Linux Memory Diff Analysis Using Volatility.   - [Setting up Limon Sandbox for Analyzing Linux Malwares](https://cysinfo.com/setting-up-limon-sandbox-for-analyzing-linux-malwares/): Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators of Linux malware. It allows one to inspect the Linux malware before execution, during execution, and after execution (post-mortem analysis) by performing static, dynamic and memory analysis using open source tools. Limon analyzes the malware in a controlled environment, monitors its activities and its child processes to determine the nature and purpose of the malware. It determines the malware’s process activity, interaction with the file system, network, it also performs memory analysis and stores the analyzed artifacts for […] - [7th Quarterly Meetup – 28th May 2016](https://cysinfo.com/7th-quarterly-meetup-28th-may-2016/): In this meet, Adarsh Agarwal delivered presentation on “Understanding Cryptolocker (Ransomware) with a Case study”, Satyam Saxena covered the topic on “Malicious Client Detection using Machine Learning”, Abhinav Chourasia presented on “Buffer Overflow Attacks”, Anirudh Duggal presented on “Fingerprinting Healthcare Institutions” and Monnappa K A presented on the topic “Reversing and Investigating Malware Evasive Tactics – Hollow Process Injection”.   Here is the link to presentations and video demonstrations: 1. Understanding Cryptolocker (Ransomware) with a Case Study 2. Malicious Client Detection using Machine Learning 3. Buffer Overflow Attacks 4. Fingerprinting Healthcare Institutions 5. Reversing and Investigating Malware Evasive Tactics – Hollow […] - [7th Meetup - Reversing and Investigating Malware Evasive Tactics – Hollow Process Injection](https://cysinfo.com/7th-meetup-reversing-and-investigating-malware-evasive-tactics-hollow-process-injection/): In this presentation, Monnappa explained the concept of code injection and hollow process injection. He demonstrated the working of hollow process injection using reverse engineering and showed how such infections can be detected and investigated using memory forensics Presentation:   Demo 1 – Understanding Hollow Process Injection Using Reverse Engineering:   Demo 2 – Investigating Hollow Process Injection Using Memory Forensics: - [7th Meetup - Fingerprinting Healthcare Institutions](https://cysinfo.com/7th-meetup-fingerprinting-healthcare-institutions/): In this presentation, Anirudh Duggal covered the techniques used to fingerprint vulnerable hospitals and healthcare infrastructure using web based tools. He also explained the potential attack points and the measures that can be taken to secure such infrastructure.   Presentation: - [7th Meetup - Buffer Overflow Attacks](https://cysinfo.com/7th-meetup-buffer-overflow-attacks/): In this presentation, Abhinav chourasia covered the concept of Buffer Overflow and he also demonstrated how one can exploit a vulnerable application and take control of a system and execute arbitrary commands on the system   Presentation: - [7th Meetup - Malicious Client Detection Using Machine Learning](https://cysinfo.com/7th-meetup-malicious-client-detection-using-machine-learning/): In this presentation, Satyam Saxena talked about features that can be used to detect DGA domains and he also covered how Whois information and passive dns data can be used to build model to detect the infected systems   Presentation: - [7th Meetup - Understanding Cryptolocker (Ransomware) with a Case Study](https://cysinfo.com/7th-meetup-understanding-cryptolocker-ransomware-with-a-case-study/): In this presentation, Adarsh Agarwal covered the the infection mechanism of Ransomwares, different variants of Ransomwares, differences between the variants, anatomy of ransomwares, timeline of the Ransomware infections since jan 2016 and the case study of TeslaCrypt V2   Presentation: - [6th Quarterly Meetup – 30th January 2016](https://cysinfo.com/6th-quarterly-meetup-30th-january-2016/): In this meet, Jiggyasu Sharma delivered presentation on “Bluetooth [in]security”, Jitendra Kumar Patel covered the topic on “Secure Multi Party Computation”, Anirudh Duggal presented on “Breaking Into Hospitals” and Monnappa K A presented on the topic “Linux Malware Analysis Using Limon Sandbox”.   Here is the link to presentations and video demonstrations: 1. Bluetooth [in]Security 2. Introduction to Secure Multi Party Computation 3. Breaking into Hospitals 4. Linux Malware Analysis using Limon Sandbox   Here are the few snapshots from the session - [6th Meetup – Linux Malware Analysis using Limon Sandbox](https://cysinfo.com/6th-meetup-linux-malware-analysis-using-limon-sandbox/): In this presentation, Monnappa covered Linux malware analysis and showed automation of Linux malware analysis using Limon sandbox, he also demonstrated analysis of Linux malwares Tsunami, Mayhem and Suterusu Rootkit using Limon   Presentation:   Demo 1 – Analysis of Linux Malware Tsunami using Limon:   Demo 2a – Analysis of Linux Malware Mayhem using Limon:   Demo 2b – Examining the malicious exit() function of Linux malware mayhem :   Demo 3 – Analysis of Suterusu Rootkit using Limon: - [6th Meetup – Breaking Into Hospitals](https://cysinfo.com/6th-meetup-breaking-into-hospitals/): In this presentation, Anirudh Duggal explained the need for securing healthcare infrastructure and showed how to fingerprint hospitals and healthcare institutions. He also covered attacks over the internet and insider attacks on them.   Presentation: ## Pages - [Reference for our Advanced Malware Analysis Training](https://cysinfo.com/reference-advanced-malware-analysis-training/): Here is the complete reference guide to all sessions of ourAdvanced Malware Analysis Training program. - [Reference for our Reverse Engineering & Malware Analysis Training](https://cysinfo.com/reference-for-our-reverse-engineering-malware-analysis-training/): Here is the complete reference guide to all sessions of our Reverse Engineering & Malware Analysis Training program. - [Monnappa's Contribution](https://cysinfo.com/monnappas-contribution/): Presentations Automating Linux Malware Analysis using Limon Sandbox at Black Hat Europe 2015 : Video Inspecting Linux Malwares using Limon Sandbox at FIRST 28th Annual Conference : Link Limon – Sandbox for Analyzing Linux Malwares at Black Hat Asia 2016 : Link Reversing and Decipering Cyber Espionage Malware Communications at 4SICS/FIRST – Summit on SCADA/ICS cyber security : Video Advanced Threats and Analysis at DSCI Best Practices Meet 2016 : Link Advanced Threats,Case Studies and Analysis at National Cyber Defence Summit 2016 : Link Tools Limon – Linux Sandbox : Link Linux mem diff Plugin (Volatility Plugin) : Link Gh0stRat Volatility Plugin (Volatility Plugin) : Link […] - [Contact Us](https://cysinfo.com/contact-us/): Get in touch with us using the form below. Or write to us at contact@cysinfo.com - [Our Associations](https://cysinfo.com/associations/):     - [Our Team](https://cysinfo.com/our-team/) - [About Cysinfo](https://cysinfo.com/about-cysinfo/): About Cysinfo Cysinfo is an open cyber security community committed to educate, empower, inspire and equip cyber security professionals and students to better fight and defend against cyber threats. Cysinfo believes in buliding a stronger community, so it provides a common forum to bring together individuals from various sectors to collaborate and share their experience,expertise and knowledge in the field of cyber security. We focus on spreading security awareness by hosting free meets, conducting trainings, developing tools, writing articles, sharing news and educating students through student mentorship program. What We Do a) Cyber Security Meets: We host cyber security meets, these […] - [Tools](https://cysinfo.com/tools/) - [Student Mentorship Programme](https://cysinfo.com/student-mentorship-programme/): Student Mentorship Programme is designed to help aspiring and passionate students to work on Security Research projects under the guidance of Expert Security mentors. Our ultimate aim is to lift the quality of education levels and generate greater research interest among students. Highlights of Student Mentorship Programme Only students from Engineering Institutes are eligible Every year 3 Student Groups will be selected Each team may consist of one to five members Each team will work on single project Each team will be mentored by Dedicated Security Expert in choosing & execution of projects Project duration will be from 3 to 6 […] - [Training](https://cysinfo.com/training/): Here are our past free Security Training series on Reverse Engineering/Malware Analysis/Exploit Development conducted over multiple sessions. [comment]: # (Generated by Hostinger Tools Plugin)