Toni Ruhanen
Hi, I'm Toni, a security engineer from Finland. By day, I work in security operations and incident response. Outside of that, I do independent security research and build the odd tool. This is where I write about what I find interesting, mostly offensive and defensive security, OSINT, and the occasional over-engineered side projects.
Writing
Combating phishing with Autopatrol
5 min readAutopatrol is our automated security monitoring system that helps us to monitor different online assets and company brands for possible security threats such as phishing.
Overengineering OSINT: Uncovering a gas station's location from insecure CCTV
5 min readIn March 2025, I found a publicly accessible CCTV feed from a Finnish gas station. I used the footage and a bit of overengineering to find the location of the gas station. This blog post describes the process and the tools used to find the location.
Analyzing Fake Captcha Malware - Vidar
Updated:4 min readIn December 2024, we discovered a malware campaign using fake captchas and Win+R to trick users into running malicious code and installing Vidar malware. This post provides an analysis of the campaign and IOCs related to it.
Projects
Phoenix
3 min readEven more advanced SIEM with endpoint monitoring, automation with many integrations and more.
Log Analysis Tool
1 min readSimple UI tool for querying and analyzing log files from various sources.
Vanguard
3 min readFull-fledged SIEM with endpoint agents, SOAR, integrations and attack surface monitoring.
RQL
1 min readPowerful library designed to simplify the process of querying, filtering, sorting, and aggregating large amounts of data.
urlcheck
2 min readTool for scanning websites that might contain malicious content. Made especially for handling phishing sites.
SilverBullet
1 min readSmall and stealthy C2 made for red teaming, that bypasses many enterprise level EDRs.