A threat-hunting pipeline uses TLSH fuzzy hashes in Velociraptor to identify executables resembling known malware despite changes that defeat exact hash matching. The Windows.EventLogs.SysmonProcessEnriched artifact enriches Sysmon Event ID 1 process-creation telemetry with Authenticode and TLSH data, while filesystem globbing can calculate TLSH values for files discovered on endpoints.
The collected telemetry is sent to Bifract, which compares hashes against Magonia Research's CelesTLSH known-malicious database. Example matches included fatedier/frp and a file closely resembling Mythic C2; neither fuzzy-hash result alone establishes maliciousness. Analysts should prioritize matches that also exhibit corroborating indicators, particularly an untrusted Authenticode signature, before escalating or alerting.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Signal Sleuth described a threat-hunting pipeline that enriches Sysmon process-creation telemetry and filesystem scans with TLSH and Authenticode data, then compares hashes in Bifract against Magonia Research's CelesTLSH known-malicious database. Example hunting results included an exact TLSH match to fatedier/frp and a distance-32 match to Mythic C2, both requiring investigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
signalsleuth.io
Open sourceblog.ecapuano.com
Open sourcedocs.velociraptor.app
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.