Labs Home

Author

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.

Phil Stokes
  • macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

    macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

  • Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis

    Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis

  • Inside the LLM | Understanding AI & the Mechanics of Modern Attacks

    Inside the LLM | Understanding AI & the Mechanics of Modern Attacks

  • macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

    macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

  • BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence

    BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence

  • 11 Ways to Tweak radare2 for Faster and Easier macOS Malware Analysis

    11 Ways to Tweak radare2 for Faster and Easier macOS Malware Analysis

  • Bloated Binaries | How to Detect and Analyze Large macOS Malware Files

    Bloated Binaries | How to Detect and Analyze Large macOS Malware Files

  • Automating String Decryption and Other Reverse Engineering Tasks in radare2 With r2pipe

    Automating String Decryption and Other Reverse Engineering Tasks in radare2 With r2pipe

  • Radare2 Power Ups | Delivering Faster macOS Malware Analysis With r2 Customization

    Radare2 Power Ups | Delivering Faster macOS Malware Analysis With r2 Customization

  • Use of Obfuscated Beacons in ‘pymafka’ Supply Chain Attack Signals a New Trend in macOS Attack TTPs

    Use of Obfuscated Beacons in ‘pymafka’ Supply Chain Attack Signals a New Trend in macOS Attack TTPs

  • The Art and Science of macOS Malware Hunting with radare2 | Leveraging Xrefs, YARA and Zignatures

    The Art and Science of macOS Malware Hunting with radare2 | Leveraging Xrefs, YARA and Zignatures

  • A Threat Hunter’s Guide to the Mac’s Most Prevalent Adware Infections 2022

    A Threat Hunter’s Guide to the Mac’s Most Prevalent Adware Infections 2022