SentinelLabs Logo RGB WhitePurp
ABOUT
CONTACT
VISIT SENTINELONE.COM

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 2

Phil Stokes / January 14, 2022

Cops bust crimeware gang in Kyiv, Texas firm bankrupt after paying ransom but getting no data returned, and MS Defender has simple bypass known for 8 years.

Read More
A Threat Hunters Guide To The Macs Most Prevalent Adware Infections 2022 12
labs
Security & Intelligence

A Threat Hunter’s Guide to the Mac’s Most Prevalent Adware Infections 2022

Phil Stokes / January 4, 2022

Mac adware is hidden, persistent, and evasive, fingerprinting devices and delivering custom payloads. Learn how to hunt it on macOS.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 51

Phil Stokes / December 17, 2021

51 individuals arrested for trading stolen data, the internet explodes with fears over Java logging vuln, and NSO's iMessage exploit is a monster to behold.

Read More
Top 10 MacOS Malware Discoveries In 2021 A Guide To Prevention Detection 6
labs

Top 10 macOS Malware Discoveries in 2021 | A Guide To Prevention & Detection

Phil Stokes / December 14, 2021

Learn about all the new malware targeting macOS in 2021, and the changing tactics, techniques and procedures being employed by threat actors.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 49

Phil Stokes / December 3, 2021

Cyber cops nab 1000 fraudsters in 20 countries, critical printer bug allows for remote attacks, and new phishing lures exploit Omicron fears.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 47

Phil Stokes / November 19, 2021

UK's NCSC wages war on phishing, "move over SquirrelWaffle", Emotet is back, and Iranian APTs exploit Microsoft bugs to drop ransomware.

Read More
Backdoor MacOS.Macma Spies On Activists But Cant Hide From Behavioral Detection 5
labs

Backdoor macOS.Macma Spies On Activists But Can’t Hide From Behavioral Detection

Phil Stokes / November 17, 2021

Novel macOS malware installs a keylogger and AV capture components on activists' devices. How can Mac users detect such behavior before it's too late?

Read More
Infect If Needed A Deeper Dive Into Targeted Backdoor MacOS Macma 7
labs
Security Research

Infect If Needed | A Deeper Dive Into Targeted Backdoor macOS.Macma

Phil Stokes / November 15, 2021

SentinelLabs reveals further IoCs, behavior and analysis around suspected APT attack targeting macOS users and Hong Kong pro-democracy activists.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 45

Phil Stokes / November 5, 2021

It's armageddon for Gamaredon after SSU outing, ransomware gang may have snagged cancer patients' PII, and medical students face fraud risk after data leak.

Read More
Image4 2 1600x900
labs

Apple’s macOS Monterey | 6 Security Changes That May Have Passed You By

Phil Stokes / October 26, 2021

Apple's annual macOS upgrade is here, fully supported by SentinelOne, and with a few changes since the early betas. Are you ready for macOS Monterey?

Read More
Previous
1 … 5 6 7 8 9 … 20
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
    Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
    March 19, 2026
  • LABScon25 Replay | Your Apps May Be Gone, But the Hackers Made $9 Billion and They’re Still Here
    LABScon25 Replay | Your Apps May Be Gone, But the Hackers Made $9 Billion and They’re Still Here
    March 17, 2026
  • From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
    From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
    March 9, 2026

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2026 SentinelOne, All Rights Reserved.