How to get URL link on X (Twitter) App
https://twitter.com/1ZRR4H/status/1655014346307559428...you don't know what normal looks like.


Using Action1, they are seen executing commands, scripts and binaries. To do that, they must first create a "policy" or an "app". The name of those will show up in the command line during execution:

@TheDFIRReport Looking into the code of the HTML file, we notice a couple of layers of obfuscation. Without much effort, we decoded the content. The script element contains URL and Base64 encoded code that will be executed by the browser.