SentinelLabs Logo RGB WhitePurp
ABOUT
CONTACT
VISIT SENTINELONE.COM

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.
Sharon Mccutcheon 665638 Unsplash 1 1 1600x900
labs

Crypto Mining On Mac: How macOS Malware is on the Rise

Phil Stokes / October 30, 2018

A review of the most recent Cryptojacking threats affecting Apple Mac users

Read More
Post Default
labs

Inside Safari Extensions | Malicious Plugins Remain on Mojave

Phil Stokes / October 23, 2018

In Part 2, we explore the pros and cons of Apple's new architecture and what it means for macOS malware & adware

Read More
Daniel Korpai 1318726 Unsplash 1600x900
labs

Inside Safari Extensions | Malware’s Golden Key to User Data

Phil Stokes / October 18, 2018

A 2-part series looking at the technology behind macOS extensions and how malicious add-ons can steal passwords, banking details and other sensitive data

Read More
Akash Rajendra 1284185 Unsplash 1600x900
labs

5 “Safe Computing” Practices for macOS and Why They Aren’t Enough

Phil Stokes / October 4, 2018

Phishing scams, trojans and ransomware are all live threats on Apple’s platform. Is it time for the macOS community to embrace Next Gen AV software?

Read More
Nikolay Tarashchenko 1327004 Unsplash
labs

Mojave Security Can Be Bypassed With SSH Keygen Wrapper

Phil Stokes / September 25, 2018

Any local or remote user can bypass Apple’s new Full Disk Access requirement using ssh. Find out how to stay safe

Read More
Fernand De Canne 1290695 Unsplash 1600x900
labs

On the Trail of OSX.FairyTale | Adware Playing at Malware

Phil Stokes / September 20, 2018

An adware installer tries its best to avoid detection, but leaves behind more clues than intended

Read More
1. Inside Fruitfly
labs

OSX.Fruitfly recycled | macOS still vulnerable to ‘old’ Perl script

Phil Stokes / August 23, 2018

13-years in the wild and counting? macOS is still vulnerable to OSX.Fruitfly, which can easily be repurposed by other bad actors

Read More
1. User Data Protections
labs

Command Line Intrusion | Mojave Blocks Admins, Too

Phil Stokes / August 13, 2018

MacOS Mojave's restrictions lock down user data, but pre-approval gives admins a 'backdoor'

Read More
1. Quintero Twitter
labs

Automated macOS malware submissions “infecting” VirusTotal

Phil Stokes / August 2, 2018

Fake submissions on VirusTotal appear to inflate hits for certain kinds of macOS malware

Read More
Calisto On Sierra
labs

We Nailed it! Calisto Detected installing Backdoor on macOS

Phil Stokes / July 23, 2018

Even SIP-protected Macs allow Calisto trojan to install a backdoor and to copy password and keychains. See a demo of how SentinelOne will protect you

Read More
Previous
1 … 17 18 19 20
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
    From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
    March 9, 2026
  • Silent Brothers | Ollama Hosts Form Anonymous AI Network Beyond Platform Guardrails
    Silent Brothers | Ollama Hosts Form Anonymous AI Network Beyond Platform Guardrails
    January 29, 2026
  • LABScon25 Replay | How to Bug Hotel Rooms v2.0
    LABScon25 Replay | How to Bug Hotel Rooms v2.0
    January 21, 2026

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2026 SentinelOne, All Rights Reserved.