SentinelLabs Logo RGB WhitePurp
ABOUT
CONTACT
VISIT SENTINELONE.COM

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 43

Phil Stokes / October 22, 2021

US bans export of hacking tools, cryptocurrency scammers target YouTubers, and FIN7 dupes IT pros into conducting ransomware attacks.

Read More
Case Studies In MacOS Malware String Decryption With Radare2 13
labs
Security Research

Techniques for String Decryption in macOS Malware with Radare2

Phil Stokes / October 12, 2021

In Part 3 of our macOS reversing series, we look at three different macOS malware samples and walk you through how to decipher encrypted strings.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 41

Phil Stokes / October 8, 2021

US Gov plans to fine contractors with weak cybersecurity, hackers steal Twitch's entire IP, and ransomware gang makes healthcare its top target.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 39

Phil Stokes / September 24, 2021

Treasury sanctions crypto exchange for aiding cybercrime, disgruntled researchers drop a raft of Apple zero days, and an FBI sting on REvil fires blanks.

Read More
Defeating MacOS Malware Anti Analysis Tricks With Radare2 10
labs
Security Research

Defeating macOS Malware Anti-Analysis Tricks with Radare2

Phil Stokes / September 20, 2021

Learn how to beat malware authors' control flow and avoid executing unwanted parts of their code to analyze macOS malware in radare2.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 37

Phil Stokes / September 10, 2021

Cyber grave robbers nabbed in Florida, another Azure cloud bug allows cross-account attacks, and ransomware gang goes after negotiators.

Read More
6 Pro Tricks For Rapid MacOS Malware Triage With Radare2 7
labs
Security Research

6 Pro Tricks for Rapid macOS Malware Triage with Radare2

Phil Stokes / August 30, 2021

Learn more about reversing real-world macOS malware in this new series for intermediate to advanced analysts, starting with these r2 tips!

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 35

Phil Stokes / August 27, 2021

Tech giants pledge $30bn to help cybersecurity, Azure Cloud bug exposes Fortune 500 firms, and Windows 10 zero day is dropped on Twitter.

Read More
New GBU Weekly
labs

The Good, the Bad and the Ugly in Cybersecurity – Week 33

Phil Stokes / August 13, 2021

PetitPotam vuln gets plugged in Patch Tuesday, LockBit gang aim to extort $50m from latest victim, and cryptocoin thief gets cold feet, returns $600m haul.

Read More
Massive New AdLoad Campaign Goes Entirely Undetected By Apples XProtect 5
labs
Security Research

Massive New AdLoad Campaign Goes Entirely Undetected By Apple’s XProtect

Phil Stokes / August 11, 2021

Learn how to detect the latest variant of this widespread adware and browser hijacker, its infection pattern and indicators of compromise.

Read More
Previous
1 … 6 7 8 9 10 … 20
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
    Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
    March 19, 2026
  • LABScon25 Replay | Your Apps May Be Gone, But the Hackers Made $9 Billion and They’re Still Here
    LABScon25 Replay | Your Apps May Be Gone, But the Hackers Made $9 Billion and They’re Still Here
    March 17, 2026
  • From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
    From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
    March 9, 2026

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2026 SentinelOne, All Rights Reserved.