SentinelLabs Logo RGB WhitePurp
ABOUT
CONTACT
VISIT SENTINELONE.COM

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.
Why Everything You Thought You Knew About MacOS Security Is Wrong 1
labs

10 Assumptions About macOS Security That Put Your Business At Risk

Phil Stokes / February 7, 2022

Keep your macOS devices safe by learning how to avoid the most common security risks from malware, adware, lack of visibility and more.

Read More
Sneaky Spies And Backdoor RATs SysJoker And DazzleSpy Malware Target MacOS 4
labs

How SysJoker and DazzleSpy Malware Target macOS

Phil Stokes / February 1, 2022

Targeting macOS users with cross-platform malware and leveraging OS vulnerabilities, threat actors begin 2022 by continuing the trends we saw last year.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 4

Phil Stokes / January 28, 2022

DeepDotNet owner gets 8 years in jail, Conti and Deadbolt ransomware hit big & small targets alike, and new ITW malware and exploits strike Apple platforms.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 2

Phil Stokes / January 14, 2022

Cops bust crimeware gang in Kyiv, Texas firm bankrupt after paying ransom but getting no data returned, and MS Defender has simple bypass known for 8 years.

Read More
A Threat Hunters Guide To The Macs Most Prevalent Adware Infections 2022 12
labs
Security & Intelligence

A Threat Hunter’s Guide to the Mac’s Most Prevalent Adware Infections 2022

Phil Stokes / January 4, 2022

Mac adware is hidden, persistent, and evasive, fingerprinting devices and delivering custom payloads. Learn how to hunt it on macOS.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 51

Phil Stokes / December 17, 2021

51 individuals arrested for trading stolen data, the internet explodes with fears over Java logging vuln, and NSO's iMessage exploit is a monster to behold.

Read More
Top 10 MacOS Malware Discoveries In 2021 A Guide To Prevention Detection 6
labs

Top 10 macOS Malware Discoveries in 2021 | A Guide To Prevention & Detection

Phil Stokes / December 14, 2021

Learn about all the new malware targeting macOS in 2021, and the changing tactics, techniques and procedures being employed by threat actors.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 49

Phil Stokes / December 3, 2021

Cyber cops nab 1000 fraudsters in 20 countries, critical printer bug allows for remote attacks, and new phishing lures exploit Omicron fears.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 47

Phil Stokes / November 19, 2021

UK's NCSC wages war on phishing, "move over SquirrelWaffle", Emotet is back, and Iranian APTs exploit Microsoft bugs to drop ransomware.

Read More
Backdoor MacOS.Macma Spies On Activists But Cant Hide From Behavioral Detection 5
labs

Backdoor macOS.Macma Spies On Activists But Can’t Hide From Behavioral Detection

Phil Stokes / November 17, 2021

Novel macOS malware installs a keylogger and AV capture components on activists' devices. How can Mac users detect such behavior before it's too late?

Read More
Previous
1 … 5 6 7 8 9 … 20
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
    macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
    June 23, 2026
  • LABScon25 Replay | Keynote: Steps to an Ecology of Cyber
    LABScon25 Replay | Keynote: Steps to an Ecology of Cyber
    June 11, 2026
  • LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine
    LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine
    June 2, 2026

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2026 SentinelOne, All Rights Reserved.