Christina Lekati
@christinalekati.bsky.social
๐ค 3495
๐ฅ 93
๐ 111
#SocialEngineering
,
#Psychology
,
#HUMINT
&
#OSINT
intertwined for the sake of security.
pinned post!
Beyond excited to share that one of our most fun, interactive & knowledge-dense classes returns, this time at @BlackHatEvents Europe! ๐ The talented @OSINTgeek & I will be teaching our "Fundamentals of Cyber Investigations & Human Intelligence" class on the 9-10th of December in London!
about 1 year ago
1
2
0
3 resources in 1 post: Open AI has released a new report outlining the ways in which threat actors used their generative AI products to support their social engineering attack operations. They provide the case studies.
openai.com/global-affai...
Why is this useful? ๐งต
loading . . .
Disrupting malicious uses of AI: June 2025
Our latest report featuring case studies of how weโre detecting and preventing malicious uses of AI.
https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-june-2025/
4 months ago
1
5
1
Happy news!! This September at @brucon we will be taking a deep dive into
#socialengineering
and
#OSINT
through a 3-day, hands-on training class! I SO look forward to it and to meeting the participants!! ๐คฉ๐ฉ๐ปโ๐ป Full class content & details:
www.brucon.org/training-det...
5 months ago
0
4
0
Very grateful for last week spent at X33fcon in Poland! It started with 2 days full of
#socialengineering
&
#OSINT
training where I had the privilege to teach a class that was present, curious, and ready to try things out. Big bonus: reconnecting with friends during the conference days afterwards๐
6 months ago
1
4
1
reposted by
Christina Lekati
Agentic AI has opened new frontiers for adversaries looking to automate and scale attacks. I wrote an article explaining what Agentic AI really is & how it can shape the future of the social engineering threat landscape.
christina-lekati.medium.com/when-ai-goes...
loading . . .
When AI Goes Rogue: How Agentic AI Will Reshape Social Engineering Attacks
Cyber criminals are rarely late to the game when it comes to new technologies. In fact, theyโre often among the first ones to experimentโฆ
https://christina-lekati.medium.com/when-ai-goes-rogue-how-agentic-ai-will-reshape-social-engineering-attacks-b795838c1aaa
7 months ago
0
0
2
Agentic AI has opened new frontiers for adversaries looking to automate and scale attacks. I wrote an article explaining what Agentic AI really is & how it can shape the future of the social engineering threat landscape.
christina-lekati.medium.com/when-ai-goes...
loading . . .
When AI Goes Rogue: How Agentic AI Will Reshape Social Engineering Attacks
Cyber criminals are rarely late to the game when it comes to new technologies. In fact, theyโre often among the first ones to experimentโฆ
https://christina-lekati.medium.com/when-ai-goes-rogue-how-agentic-ai-will-reshape-social-engineering-attacks-b795838c1aaa
7 months ago
0
0
2
There are a few things different this time around. ๐๐ป New class modules: ๐ธ๏ธState-Sponsored social engineering schemes ๐ธ๏ธUsing AI for OSINT tasks (responsibly) ๐ธ๏ธHow attackers are using AI to supercharge their SE. Hands-on, practical & realistic. See you at x33fcon in only 4 weeks! ๐ฑ๐ฅณ
add a skeleton here at some point
7 months ago
0
0
0
If you are using
#HUMINT
techniques in your
#CTI
process, this is a talk worth watching. Eliska & Julien do a great job in breaking down important concepts, risks, benefits & analytical aspects of using HUMINT tactics in a CTI workflow โฌ๏ธ
youtu.be/o1TTO5d1DXQ?...
loading . . .
It's so overt it's covert: leveraging classic HUMINT tactics in CTI investigations
YouTube video by SANS Digital Forensics and Incident Response
https://youtu.be/o1TTO5d1DXQ?si=ScY3uyG63ixNl2Zs
7 months ago
1
0
0
reposted by
Christina Lekati
Dutch_OsintGuy
8 months ago
New blog: The Slow Collapse of Critical Thinking in OSINT due to AI "OSINT used to be a thinking game. Now itโs becoming a trusting game and that should terrify you."
#OSINT
#OSINT4good
#AI
Read the blog here:
www.dutchosintguy.com/post/the-slo...
7
58
25
Surprise! Really excited to announce that the next "๐บ๐๐๐๐๐ ๐ฌ๐๐๐๐๐๐๐๐๐๐ & ๐ถ๐๐๐-๐๐๐๐๐๐ ๐ฐ๐๐๐๐๐๐๐๐๐๐๐ ๐๐๐ ๐บ๐๐๐๐๐๐๐ ๐ป๐๐๐๐" open class will be happening at x33fcon in Gdynia, Poland!! This is an intensive, 2-day training ๐งต
8 months ago
1
3
2
Not that hotel rooms have the best locking mechanisms, but leaving a room fully accessible after exiting is a whole other level. Check your doors when you leave, people.
loading . . .
9 months ago
0
2
0
reposted by
Christina Lekati
dell cameron
9 months ago
A WIRED must-read today on Boeing by
@laurensmiley.bsky.social
:
loading . . .
The Worst 7 Years in Boeingโs Historyโand the Man Who Wonโt Stop Fighting for Answers
Fatal crashes. A door blowout. Grounded planes. Inside the citizen-led, obsessive campaign to hold Boeing accountable and prevent the next disaster.
https://www.wired.com/story/boeing-whistleblower-737-max/
2
181
42
reposted by
Christina Lekati
Patrick C Miller
9 months ago
Switzerland mandates 24-hour cyberattack reporting for critical infrastructure operators from April
loading . . .
Switzerland mandates 24-hour cyberattack reporting for critical infrastructure operators from April
Switzerland Mandates 24-hour Cyberattack Reporting for Critical Infrastructure, Effective April 1, with Fines Starting October 1.
https://buff.ly/n36FiSZ
0
1
2
How can HUMINT be leveraged in Cyber Threat Intelligence? The Dark Overlord investigation is an interesting report showcasing how HUMINT helps better understand threat actor activities, and even infiltrate their inner circles to uncover real identities. Some notes ๐งต
nightlion.com/wp-content/u...
10 months ago
1
0
0
reposted by
Christina Lekati
hakan
10 months ago
โher threat hunters detected the Chinese government goons in federal networks before the far-reaching espionage campaign against people's telecommunications providers had been found and attributed to Salt Typhoon.โ
www.theregister.com/2025/01/15/s...
loading . . .
Salt Typhoon spies spotted on US govt networks before telcos
We are only seeing 'the tip of the iceberg,' Easterly warns
https://www.theregister.com/2025/01/15/salt_typhoon_us_govt_networks/
0
10
5
reposted by
Christina Lekati
"๐พ๐๐๐, ๐ฐโ๐ ๐๐๐ ๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐ ๐๐ ๐๐๐๐๐ ๐๐๐๐, ๐๐๐โฆ" Used in social engineering, intelligence collection, & negotiations, elicitation is the subtle art of extracting sensitive information during a seemingly regular conversation. Read more in my new blog:
christina-lekati.medium.com/elicitation-...
loading . . .
ELICITATION TECHNIQUES
Covert Information Collection From Human Sources
https://christina-lekati.medium.com/elicitation-techniques-74be36e212f8
11 months ago
2
13
6
reposted by
Christina Lekati
The new year has come around and we kick it off with 2 new online classes! ๐น On the 21st of January I will be giving a 4-hour online class on
#Elicitation
๐ง๐ฒ๐ฐ๐ต๐ป๐ถ๐พ๐๐ฒ๐. ๐น On the 28th of January
@osintgeek.de
will be teaching
#Telegram
๐๐ป๐๐ฒ๐๐๐ถ๐ด๐ฎ๐๐ถ๐ผ๐ป๐. โฌ๏ธ๐งต
11 months ago
1
2
3
"๐พ๐๐๐, ๐ฐโ๐ ๐๐๐ ๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐ ๐๐ ๐๐๐๐๐ ๐๐๐๐, ๐๐๐โฆ" Used in social engineering, intelligence collection, & negotiations, elicitation is the subtle art of extracting sensitive information during a seemingly regular conversation. Read more in my new blog:
christina-lekati.medium.com/elicitation-...
loading . . .
ELICITATION TECHNIQUES
Covert Information Collection From Human Sources
https://christina-lekati.medium.com/elicitation-techniques-74be36e212f8
11 months ago
2
13
6
The new year has come around and we kick it off with 2 new online classes! ๐น On the 21st of January I will be giving a 4-hour online class on
#Elicitation
๐ง๐ฒ๐ฐ๐ต๐ป๐ถ๐พ๐๐ฒ๐. ๐น On the 28th of January
@osintgeek.de
will be teaching
#Telegram
๐๐ป๐๐ฒ๐๐๐ถ๐ด๐ฎ๐๐ถ๐ผ๐ป๐. โฌ๏ธ๐งต
11 months ago
1
2
3
Snapshots from
#BlackHatEurope
! Spent the week giving our 2-day training to a largely diverse class, strolling around London, celebrating a birthday (thanks to
@osintgeek.de
who is the best work buddy you can have), and attending the conference! You can say it was a real FULL week.
12 months ago
1
11
2
Cyber Monday has come around and this is the last chance to invest in learning and developing new skills for a 30% off ALL of our classes! If you have been wanting to learn OSINT, HUMINT, Elicitation techniques or investigating Telegram, this is a very good chance. More details below โฌ๏ธ Enjoy!
add a skeleton here at some point
about 1 year ago
0
1
1
reposted by
Christina Lekati
Digital Trails Academy
about 1 year ago
๐จ It's here! Our ONLY SALE of the year! ๐จ Get 30% OFF ALL of our courses-including the new ones! ๐คฏ This Sale Ends on Cyber Monday: 2 December 2024 at 23:59 CET! Code: WHISPERS Let's see an overview of the classes included ๐งต
#BlackFriday
#OSINT
#SOCMINT
#HUMINT
#OpenSourceIntelligence
#Training
loading . . .
1
5
5
Tale (almost) as old as the hacker space ๐ Not just with China...
add a skeleton here at some point
about 1 year ago
0
1
0
reposted by
Christina Lekati
Joseph Cox
about 1 year ago
New from 404 Media: Bluesky may have said it won't use user data to train generative AI, but someone else just published a dataset of million Bluesky posts for "machine learning research". Already very popular dataset, your data may be scraped
www.404media.co/someone-made...
loading . . .
Someone Made a Dataset of One Million Bluesky Posts for 'Machine Learning Research'
A Hugging Face employee made a huge dataset of Bluesky posts, and itโs already very popular.
https://www.404media.co/someone-made-a-dataset-of-one-million-bluesky-posts-for-machine-learning-research/
117
1578
1201
reposted by
Christina Lekati
Baptiste Robert
about 1 year ago
On January 30, 2025, Iโm hosting an online GEOINT workshop! Join this 4-hour training session to learn how to geolocate images and videos effectively Get all the details and register here:
www.eventbrite.fr/e/predicta-l...
0
6
2
Our 2-day training at
#DeepSec
is a wrap! It was the first time I delivered a deep-dive focusing entirely on the
#psychology
interplaying in social engineering & HUMINT operations at a cybersecurity conference. It is very energizing to have a class full of curious minds!
about 1 year ago
1
16
0
reposted by
Christina Lekati
If you are reading this post , do take a few minutes to run a quick OSINT check on documents and files that might expose your organization... (Why? Read in the thread below) Here is an article I wrote on how to conduct an initial research on your own:
medium.com/@christina-l...
loading . . .
OSINT Techniques for Sensitive Documents That Have Escaped Into The Clear Web
I have been working full-time in this industry for about 8 years. Part of my work involves conducting vulnerability assessments forโฆ
https://medium.com/@christina-lekati/osint-techniques-for-sensitive-documents-that-have-escaped-into-the-clear-web-6659f29e6010
over 1 year ago
1
5
3
There it is! The bookmark function! ๐
add a skeleton here at some point
about 1 year ago
1
3
1
reposted by
Christina Lekati
OSINT-Research ๐ต๏ธ
about 1 year ago
Made an
#OSINT
starter pack with many OSINT people from all over.
go.bsky.app/TSvKc6o
Let me know who I missed!
add a skeleton here at some point
21
123
54
Less than 2 weeks left to register for the class: โLook What You Made Me Doโ: The Psychology behind Social Engineering & Human Intelligence Operations - taking place at DeepSec in Vienna on the 19th & 20th of November!
deepsec.net/speaker.html...
about 1 year ago
1
0
0
LLMs for parts of OSINT, not LLMs for all
#OSINT
. Hallucinations are part of their output - and this will most probably not go away. Take our your thin toothed comb, evaluate, and verify LLM output through additional souces.
futurism.com/the-byte/ope...
loading . . .
OpenAI Research Finds That Even Its Best Models Give Wrong Answers a Wild Proportion of the Time
OpenAI has released a new benchmark dubbed "SimpleQA" to measure the accuracy of its AI models. The results are damning.
https://futurism.com/the-byte/openai-research-best-models-wrong-answers
about 1 year ago
0
0
0
It's a happy Saturday! Kicking off BSides Berlin with a new presentation "In Deception We Trust" - the modern social engineering exploits against centuries-old human vulnerabilities ๐ญ
about 1 year ago
0
4
0
North Korea attacked the Diehl Defense (a weapons manufacturer specializing in advanced military technology) through a
#socialengineering
campaign. The pretext? Emails impersonating U.S. arms suppliers offering lucrative job offers.
www.spiegel.de/netzwelt/web...
loading . . .
Diehl Defence: Hacker aus Nordkorea zielen auf Mitarbeiter des Rรผstungskonzerns
Die deutsche Firma Diehl Defence stattet das sรผdkoreanische Militรคr mit dem Lenkflugkรถrper Iris-T aus. Nun sind Mitarbeiter ins Visier der staatlichen Hacker von Nordkoreas Diktator Kim Jong Un gerate...
https://www.spiegel.de/netzwelt/web/diehl-defence-hacker-aus-nordkorea-zielen-auf-mitarbeiter-des-ruestungskonzerns-a-8735f440-670c-40df-9e46-06c620fe9be6
about 1 year ago
0
1
0
Beyond excited to share that one of our most fun, interactive & knowledge-dense classes returns, this time at @BlackHatEvents Europe! ๐ The talented @OSINTgeek & I will be teaching our "Fundamentals of Cyber Investigations & Human Intelligence" class on the 9-10th of December in London!
about 1 year ago
1
2
0
With summer taking over and as things naturally slow down these weeks, it is my favorite time for rest, research, and going down some rabbit holes! Expect interesting new things and new classes coming from September on! ๐ค๐๐ What are you doing this summer? ๐
over 1 year ago
0
0
0
Highly recommended book for the ones interested in how advanced threat actors operate and in the dynamics around cyberwarefare and state-sponsored attacks. Some very good case studies are included! Summer is here and it's my time to tackle a long reading list:)
over 1 year ago
0
2
0
reposted by
Christina Lekati
Layer 8 Conference and Podcast
over 1 year ago
Are you doing phishing testing? Are you doing it badly? On this week's Layer 8 Podcast, Rebecca Markwick explains what we do wrong, how it causes harm and how to do them better.
podcasters.spotify.com/pod/show/lay...
loading . . .
Episode 104: Why Phishing Simulations Suck with Rebecca Markwick by Layer 8 Podcast
Bex Markwick joins us today to tell us what she feels is wrong about the way we do phishing testing today. We'll talk about some of the areas where those might not go in the right direction and why, b...
https://podcasters.spotify.com/pod/show/layer-8-podcast/episodes/Episode-104-Why-Phishing-Simulations-Suck-with-Rebecca-Markwick-e2g7lq3
0
1
1
If you are reading this post , do take a few minutes to run a quick OSINT check on documents and files that might expose your organization... (Why? Read in the thread below) Here is an article I wrote on how to conduct an initial research on your own:
medium.com/@christina-l...
loading . . .
OSINT Techniques for Sensitive Documents That Have Escaped Into The Clear Web
I have been working full-time in this industry for about 8 years. Part of my work involves conducting vulnerability assessments forโฆ
https://medium.com/@christina-lekati/osint-techniques-for-sensitive-documents-that-have-escaped-into-the-clear-web-6659f29e6010
over 1 year ago
1
5
3
reposted by
Christina Lekati
Sector035
over 1 year ago
Another Monday filled with interesting articles, tips and news. This Week in
#OSINT
is brought to you by:
@mwosint.bsky.social
@bashinho.de
@fs0c131y.com
@christinalekati.bsky.social
@nixintel.bsky.social
sector035.nl/articles/202...
loading . . .
Week in OSINT 202410
Welcome to another very lengthy update from the world of OSINT, with some Google searches, strategy and a hint of Insta and Snaps... One of
https://sector035.nl/articles/2024-10
0
11
8
reposted by
Christina Lekati
Digital Trails Academy
almost 2 years ago
๐จ New class alert! Join us as we explore some of the darkest digital trails through our new training, "Investigating Shadows: Researching Telegram" Date: 24 May 2024 Live online, interactive webinar from 09:00 - 14:00 CET Class details & registration:
digital-trails.academy/p/investigat...
loading . . .
Homepage
https://digital-trails.academy/p/investigating-shadows
0
2
2
My presentation โPhysical Security, Artificial Intelligence & Open-Source Intelligence for Nuclear Facilitiesโ - delivered at the World Institute for Nuclear Security is now public. โ๏ธDisclaimer: This is an edited version:some slides/details have been omitted.
www.wins.org/wp-content/u...
almost 2 years ago
0
1
0
Today, the German Federal Office for the Protection of the Constitution (BvF) & South Korea's National Intelligence Service once again issue a warning about 2 North Korean threat actors. They warn primarily about economic espionage in the arms industry.
www.verfassungsschutz.de/SharedDocs/k...
loading . . .
Counter-intelligence
Spionage- und Proliferationsabwehr
https://www.verfassungsschutz.de/SharedDocs/kurzmeldungen/EN/2024/2024-02-19-joint-cyber-security-advisory.html
almost 2 years ago
0
0
0
A new and very interesting social media campaign for HUMINT recruitment was published on the CIA's Youtube Channel. From a social engineering aspect, the video employs an interesting mix of empathy, history, and nostalgia, clearly targeting disaffected officials:
www.rusi.org/explore-our-...
loading . . .
Poking the Bear: Social Media and Human Intelligence Recruitment
Recent CIA social media campaigns have shown how the past can be weaponised to encourage modern-day potential agents to work with the West. The UKโs intelligence agencies would do well to take note.
https://www.rusi.org/explore-our-research/publications/commentary/poking-bear-social-media-and-human-intelligence-recruitment
almost 2 years ago
0
1
0
Last week I had the honor to be invited by the World Institute for Nuclear Security to present my research on how
#OSINT
coupled with
#AI
can impact the physical security of nuclear facilities. Thank you for inviting me,I had a great time learning from others & meeting everyone!
almost 2 years ago
0
0
0
There has been quite some conversation around this lately. My take: Large Language Models (LLMs) like ChatGPT cannot be treated as an OSINT tool simply because...they do not get the job done. On multiple levels. (๐งต)
almost 2 years ago
1
1
1
reposted by
Christina Lekati
Digital Trails Academy
almost 2 years ago
If you are into true crime, then you are probably as excited as we are that season 2 of The Europol Podcast officially launched!
www.europol.europa.eu/media-press/...
loading . . .
The Europol Podcast | Europol
The Europol Podcast is the official podcast of the EUโs agency for law enforcement cooperation. In this series, we shine a light on some of the biggest operations Europol has supported, and how we c...
https://www.europol.europa.eu/media-press/europol-podcast/
0
2
1
reposted by
Christina Lekati
Digital Trails Academy
almost 2 years ago
The latest SIRIUS EU Electronic Evidence Situation Report by Europol is showcasing that the most valuable criminal evidence is being found within social media platforms
#OSINT
#SOCMINT
Criminals leave digital trails that are left to be found by those who know how.
0
4
4
If you have some time during the holidays, this podcast series is very worth listening to! ๐๐ป
add a skeleton here at some point
almost 2 years ago
1
1
0
reposted by
Christina Lekati
Digital Trails Academy
almost 2 years ago
Read in this incredible story how hitmen working for a criminal group active in Montenegro and Serbia used open-source intelligence techniques to track down and kill the leader of a rival clan as he hid out in Greece.
www.occrp.org/en/balkan-co...
loading . . .
How a Montenegrin Gang Used Open-Source Intelligence to Kill - OCCRP
Hitmen working for a criminal group active in Montenegro and Serbia used open-source intelligence techniques, poring over apartment listing sites, satellite images, and tourist photos posted online...
https://www.occrp.org/en/balkan-cocaine-wars/how-a-montenegrin-gang-used-open-source-intelligence-to-kill
0
3
2
In a few months @OSINTgeek and I will be returning to Singapore for another training at Black Hat Asia! However... this time, in addition to the updates we have made, there will also be a little surprise, something we have never done before ๐คญ๐คซ
almost 2 years ago
0
3
2
What a prime example of blending in. In the little more elaborate
#socialengineering
schemes, a big part of the job often involves finding a pretext through which you can pretend to be part of the "business as usual" Proofpoint describes how TA4557 did it
www.proofpoint.com/us/blog/thre...
loading . . .
Security Brief: TA4557 Targets Recruiters Directly via Emailย ย ย | Proofpoint US
What happenedย Since at least October 2023, TA4557 began using a new technique of targeting recruiters with direct emails that ultimately lead to malware delivery. The initial emails are benign and.....
https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta4557-targets-recruiters-directly-email
almost 2 years ago
0
1
0
Load more
feeds!
log in