Labs Home

Author

Phil Stokes

Phil Stokes is a Research Engineer at SentinelOne, specializing in macOS threat intelligence, platform vulnerabilities and malware analysis. He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform. Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.

Phil Stokes
  • How AdLoad macOS Malware Continues to Adapt & Evade

    How AdLoad macOS Malware Continues to Adapt & Evade

  • Detecting macOS.GMERA Malware Through Behavioral Inspection

    Detecting macOS.GMERA Malware Through Behavioral Inspection

  • macOS Incident Response | Part 3: System Manipulation

    macOS Incident Response | Part 3: System Manipulation

  • macOS Incident Response | Part 2: User Data, Activity and Behavior

    macOS Incident Response | Part 2: User Data, Activity and Behavior

  • macOS Incident Response | Part 1: Collecting Device, File & System Data

    macOS Incident Response | Part 1: Collecting Device, File & System Data

  • Lazarus APT Targets Mac Users with Poisoned Word Document

    Lazarus APT Targets Mac Users with Poisoned Word Document