<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://kh4lifa0x.github.io/blogs/</id><title>Ahmed Khalifa</title><subtitle>Threat research, malware analysis, and adversary infrastructure hunting.</subtitle> <updated>2026-08-02T23:43:29+03:00</updated> <author> <name>Ahmed Khalifa</name> <uri>https://kh4lifa0x.github.io/blogs/</uri> </author><link rel="self" type="application/atom+xml" href="https://kh4lifa0x.github.io/blogs/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://kh4lifa0x.github.io/blogs/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Ahmed Khalifa </rights> <icon>/blogs/assets/img/favicons/favicon.ico</icon> <logo>/blogs/assets/img/favicons/favicon-96x96.png</logo> <entry><title>From Windows Telemetry to Arrest: How Microsoft’s GDID Helped Connect the Dots</title><link href="https://kh4lifa0x.github.io/blogs/posts/from-windows-telemetry-to-arrest-how-microsofts-gdid-helped-connect-the-dots/" rel="alternate" type="text/html" title="From Windows Telemetry to Arrest: How Microsoft’s GDID Helped Connect the Dots" /><published>2026-07-08T15:38:36+03:00</published> <updated>2026-08-02T22:57:27+03:00</updated> <id>https://kh4lifa0x.github.io/blogs/posts/from-windows-telemetry-to-arrest-how-microsofts-gdid-helped-connect-the-dots/</id> <content type="text/html" src="https://kh4lifa0x.github.io/blogs/posts/from-windows-telemetry-to-arrest-how-microsofts-gdid-helped-connect-the-dots/" /> <author> <name>Ahmed Khalifa</name> </author> <category term="Threat Intelligence" /> <summary>Executive Summary The arrest and extradition of an alleged Scattered Spider member drew attention for more than the charges themselves. The most revealing detail appeared inside the court documents: Microsoft telemetry associated with a Global Device Identifier, or GDID, helped investigators connect online activity to a specific Windows installation. According to the complaint, Microsoft reco...</summary> </entry> <entry><title>Inside Modern Supply Chain Intrusions: From CI/CD Abuse to Ecosystem-Wide Compromise</title><link href="https://kh4lifa0x.github.io/blogs/posts/inside-modern-supply-chain-intrusions-from-ci-cd-abuse-to-ecosystem-wide-compromise/" rel="alternate" type="text/html" title="Inside Modern Supply Chain Intrusions: From CI/CD Abuse to Ecosystem-Wide Compromise" /><published>2026-06-02T12:42:53+03:00</published> <updated>2026-08-02T23:14:26+03:00</updated> <id>https://kh4lifa0x.github.io/blogs/posts/inside-modern-supply-chain-intrusions-from-ci-cd-abuse-to-ecosystem-wide-compromise/</id> <content type="text/html" src="https://kh4lifa0x.github.io/blogs/posts/inside-modern-supply-chain-intrusions-from-ci-cd-abuse-to-ecosystem-wide-compromise/" /> <author> <name>Ahmed Khalifa</name> </author> <category term="Supply Chain Security" /> <summary>Modern supply chain intrusions are attacks that compromise trusted software development systems, including CI/CD pipelines, package registries, GitHub repositories, developer tools, and cloud environments. Instead of attacking one organization directly, threat actors abuse trusted dependencies, automation workflows, and stolen developer credentials to spread across entire software ecosystems. ...</summary> </entry> <entry><title>Crypto Money Laundering</title><link href="https://kh4lifa0x.github.io/blogs/posts/crypto-money-laundering/" rel="alternate" type="text/html" title="Crypto Money Laundering" /><published>2026-02-25T10:59:36+02:00</published> <updated>2026-02-25T10:59:36+02:00</updated> <id>https://kh4lifa0x.github.io/blogs/posts/crypto-money-laundering/</id> <content type="text/html" src="https://kh4lifa0x.github.io/blogs/posts/crypto-money-laundering/" /> <author> <name>Ahmed Khalifa</name> </author> <category term="Threat Intelligence" /> <summary>Crypto Money Laundering: Definition, Stages, and Common Techniques Money laundering is the process of concealing illegally obtained funds to make them appear legitimate. In crypto, laundering has evolved because digital assets can move quickly across borders and between platforms, often with limited identity context unless strong compliance controls are in place. Crypto doesn’t make launderin...</summary> </entry> <entry><title>The Ransomware Ecosystem: Roles, Tools, and How Modern RaaS Attacks Work</title><link href="https://kh4lifa0x.github.io/blogs/posts/the-ransomware-ecosystem-roles-tools-and-how-modern-raas-attacks-work/" rel="alternate" type="text/html" title="The Ransomware Ecosystem: Roles, Tools, and How Modern RaaS Attacks Work" /><published>2026-02-09T08:45:05+02:00</published> <updated>2026-08-02T22:57:27+03:00</updated> <id>https://kh4lifa0x.github.io/blogs/posts/the-ransomware-ecosystem-roles-tools-and-how-modern-raas-attacks-work/</id> <content type="text/html" src="https://kh4lifa0x.github.io/blogs/posts/the-ransomware-ecosystem-roles-tools-and-how-modern-raas-attacks-work/" /> <author> <name>Ahmed Khalifa</name> </author> <category term="Ransomware" /> <summary>Ransomware is no longer just a malicious program deployed by a single attacker — it has evolved into a complex, profit-driven ecosystem operating much like a legitimate business model. Today’s ransomware operations involve multiple specialized actors, automated platforms, and underground services working together to maximize impact and financial gain. From Initial Access Brokers selling compro...</summary> </entry> <entry><title>Smishing Triad Targets Egypt’s Financial Sector and Postal Services</title><link href="https://kh4lifa0x.github.io/blogs/posts/smishing-triad-targets-egypts-financial-sector-and-postal-services/" rel="alternate" type="text/html" title="Smishing Triad Targets Egypt’s Financial Sector and Postal Services" /><published>2025-11-24T14:50:17+02:00</published> <updated>2026-08-02T23:14:26+03:00</updated> <id>https://kh4lifa0x.github.io/blogs/posts/smishing-triad-targets-egypts-financial-sector-and-postal-services/</id> <content type="text/html" src="https://kh4lifa0x.github.io/blogs/posts/smishing-triad-targets-egypts-financial-sector-and-postal-services/" /> <author> <name>Ahmed Khalifa</name> </author> <category term="Threat Intelligence" /> <summary>Recently, during one of our threat hunting operations, our squad identified multiple malicious domains impersonating major Egyptian service providers, including Fawry, the Egypt Post, and Careem. These domains were likely established to support fraud, phishing campaigns, and other malicious activities targeting users and organizations. Before we begin our analysis, we will provide an overview ...</summary> </entry> </feed>
