Skip to content
View yankywilson's full-sized avatar

Block or report yankywilson

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
yankywilson/README.md

🛡️ Yanky Wilson

🔍 Threat Intelligence · 🎯 Attribution · 🚨 Incident Response · 🧬 Reverse Engineering

I figure out who's behind the attack.

When an intrusion hits, I work the artifacts — logs, memory, network telemetry, binaries, infrastructure — back to the actor. Reverse engineer the payload. Pivot the C2. TTPs to MITRE. Infrastructure to clusters. Clusters to known groups. Then I turn that intelligence into detections that catch them the next time.


⚔️ What I Do

🎯 Attribution research — Pivoting on infrastructure, malware, and tradecraft to link activity to known threat actors. Heavy focus on Iranian state-sponsored clusters (APT33 / Peach Sandstorm, APT42), financially motivated RMM abuse operators, and PhaaS infrastructure tracking.

🧬 Malware reverse engineering — Static and dynamic analysis of operator-side payloads. Identifying anti-forensic techniques, custom C2 protocols, steganographic beaconing, and configuration structures. Extracting durable signatures from binary internals that survive infrastructure rotation.

🚨 Incident response — Full lifecycle ownership. Triage, scoping, containment, eradication, recovery, post-incident reporting. Sole forensic investigator on complex endpoint cases including memory acquisition, browser forensics, and anti-forensic application analysis.

🔧 Detection engineering — Sigma, KQL, YARA, Suricata. Operationalizing IOCs and TTPs into Sentinel and Defender so the next intrusion gets caught at alert-time, not after.

🌐 OSINT infrastructure tracking — Censys / urlscan / passive DNS / certificate transparency pivot chains. Building cluster maps of operator infrastructure that hold up across rotation cycles.


🛠️ Stack

⚡ Microsoft Sentinel · Defender for Endpoint · CrowdStrike Falcon · Intune · Entra ID 💻 KQL · Sigma · Suricata · YARA · PowerShell · Python 🔬 Volatility · pdf-parser · pdfplumber · binary reverse engineering · Chromium DB forensics 🌐 Censys · urlscan.io · crt.sh · ANY.RUN · abuse.ch · Hunt.io · passive DNS 📊 MITRE ATT&CK · Diamond Model · Kill Chain · STIX 2.1


📌 Pinned Work

  • 🛰️ jdy-botnet-threat-analysis — MIPS64 implant RE and infrastructure CTI on the JDY recon botnet (Volt Typhoon / KV lineage, MITRE G1017). Recovered AES-128-CBC tasking (correcting the published AES-256 key as IV||KEY), mapped the jdyfj relay cluster, working decryptor + Sigma/YARA + tiered reporting.
  • 🍩 donutcluster-AS138995 — Novel DonutLoader variant. Custom stego C2 on TCP/7070, reflective DLL loader, recoverable CFG1 config, 14-host infrastructure cluster. YARA, Suricata, IOCs.
  • 🐻 🇺🇦 gamybear-cert-ua-18329-analysis — 15+ binary-level corrections to CERT-UA#18329 GAMYBEAR. Persistence misattribution, TLS implementation failure, and IOC validation against the actual ieupdater.exe loader.
  • 👻 ghost-cring-defender-toolkit — Defender toolkit derived from binary-level RE of CISA AA25-050A Cring.exe. 25+ documented advisory gaps including MD5-only hash representation, missing binary-internal IOCs, and family-level TTPs not enacted by the analyzed sample. Multi-platform detection (YARA, Sigma, KQL, SPL, EQL, FQL), STIX 2.1 IOC bundle, and MITRE ATT&CK Navigator gap layer.
  • 🎣 sneaky2fa-kc-cluster — OSINT analysis of an active Sneaky2FA PhaaS operator running 117 origin servers from Kansas City, MO. Documents aged-domain acquisition tradecraft for enterprise mail-filter bypass.
  • 🔴 screenconnect-rogue-tenant-investigation — CTI and detections for rogue ScreenConnect tenant abuse
  • 🌐 DNS-Filter-Bypass-Forensics-Toolkit — PowerShell forensics for DNS evasion on managed Windows fleets

📜 Certifications

🏅 CompTIA CySA+ · CompTIA Security+ · EC-Council Certified Threat Intelligence Analyst (C|TIA) · EC-Council Certified SOC Analyst (C|SA) · ISC2 Certified in Cybersecurity (CC)

Pinned Loading

  1. jdy-botnet-threat-analysis jdy-botnet-threat-analysis Public

    Defensive CTI analysis of the JDY reconnaissance botnet (China-nexus, Volt Typhoon / KV lineage, MITRE G1017): MIPS64 implant reverse engineering, infrastructure enumeration, tiered intelligence re…

    Python 28 20

  2. shinysp1d3r-intel shinysp1d3r-intel Public

    Reverse engineering, infrastructure analysis, and detection content for the ShinySp1d3r ransomware family and an associated rogue ScreenConnect / MeshCentral estate. 63 findings, 9 YARA, 36 Sigma, …

    YARA

  3. terndoor-uat9244 terndoor-uat9244 Public

    Threat intelligence and detection content for TernDoor, a China-nexus (UAT-9244 / FamousSparrow / Tropic Trooper) modular backdoor of the CrowDoor lineage. Full technical report, IOCs, and YARA / S…

    YARA

  4. ghost-cring-defender-toolkit ghost-cring-defender-toolkit Public

    Defender toolkit for Ghost (Cring) ransomware, derived from binary-level reverse engineering of the AA25-050A sample. Detection rules (YARA, Sigma, KQL, SPL, EQL), STIX 2.1 IOCs, hunt queries, hard…

    YARA

  5. sneaky2fa-kc-cluster sneaky2fa-kc-cluster Public

    How a Sneaky2FA PhaaS operator bought 9-year-old legitimate domains to bypass enterprise mail-filter reputation systems — full infrastructure analysis of a 117-host cluster in Kansas City, MO. Aged…

  6. donutcluster-AS138995 donutcluster-AS138995 Public

    Novel DonutLoader variant — dual-channel custom C2 (HXh payload delivery TCP/8853 + steganographic beacon TCP/7070), 10-host operator cluster on AS138995, Hunt.io Chalubo mislabel documented. YARA,…

    YARA