SentinelLabs Logo RGB WhitePurp
ABOUT
CONTACT
VISIT SENTINELONE.COM

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 17

Phil Stokes / April 23, 2021

FIN7 admin locked up for 10 years, REvil ransomware demand ransom from Apple, and second APT actor found using SUPERNOVA in long-term hack of US enterprise.

Read More
Apple Silicon Rosetta 2 And The Challenges For Endpoint Security 8
labs

Why Your macOS EDR Solution Shouldn’t Be Running Under Rosetta 2

Phil Stokes / April 12, 2021

Your legacy Intel software may appear to run just fine on Apple silicon thanks to Rosetta 2, but what are the performance and security consequences?

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 15

Phil Stokes / April 9, 2021

Pwn2Own highlights the right path for talented hackers, organizations warned about critical SAP bugs, and APT34 targets job hunters with novel backdoor.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 13

Phil Stokes / March 26, 2021

Thieves steal user data from Carding Mafia crime site, OpenSSL vulnerable to denial of service attacks, and an ethical researcher gets shopped to the cops.

Read More
New MacOS Malware XcodeSpy Targets Xcode Developers With EggShell Backdoor 6
labs
Security & Intelligence

New macOS Malware XcodeSpy Targets Xcode Developers with EggShell Backdoor

Phil Stokes / March 18, 2021

Targeting software developers is one route to a successful supply chain attack. Now threat actors are going after Apple developers through the Xcode IDE.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 10

Phil Stokes / March 5, 2021

Darknet hacker forums learn what it's like to be hacked, Chinese APT exploits MS Exchange Server, and the SolarWinds breach turns up 3 new malware families.

Read More
5 Things You Need To Know About Silver Sparrow 1
labs

Silver Sparrow Malware: 5 Things You Need to Know

Phil Stokes / February 22, 2021

Read here for all the need to know details and stay one step ahead of the latest macOS threat. IOCs contained within.

Read More
20 Common Tools Techniques Used By MacOS Threat Actors Malware 6
labs
Security Research

20 Common Tools & Techniques Used by macOS Threat Actors & Malware

Phil Stokes / February 16, 2021

Threat hunting on macOS? These are the tools malware most often leverages, with ITW examples, MITRE behavioral indicators and links to further research.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 7

Phil Stokes / February 12, 2021

SIM-swapping gang targeting US celebs gets busted in the UK, zero days haunt Chrome and Windows, and hackers waltz past weak security in public water system.

Read More
Blog Weekly Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 4

Phil Stokes / January 22, 2021

Biden injects money & expertise into U.S. cybersecurity, scammers leave stolen enterprise creds in plain sight, and adult website leaks 2m users' details.

Read More
Previous
1 … 8 9 10 11 12 … 20
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout
    LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout
    May 14, 2026
  • PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
    PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
    May 7, 2026
  • LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience
    LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience
    May 6, 2026

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2026 SentinelOne, All Rights Reserved.