Tom Hegel · Distinguished Threat Researcher · SentinelLABS Research Lead
I expose the cyber operations shaping events in the real world.
I find consequential adversary activity, lead the investigations that make it legible, and build intelligence systems that help defenders act on the evidence.
The work begins with evidence and ends with consequence: adversaries understood, defenders equipped, institutions briefed, and decisions improved, whether the work remains private or enters the public record.
01
Find
Surface the first signal, recognize why it matters, and stay with it long enough to find the operation behind the artifact.
02
Lead
Frame the intelligence question, assemble the right expertise, challenge the evidence, and carry the work through disclosure.
03
Equip
Turn findings into detections, response, private decisions, public understanding, and systems that compound future research.
01 / Selected investigations
Original findings. Real consequences.
CASE 01
India · Bhima Koregaon 16 · Fabricated evidence · 2022
ModifiedElephant
I found the thread, spent months reconstructing it back to 2012, and led the research that named ModifiedElephant. My investigation was the first to connect forensic findings surrounding the Bhima Koregaon 16 prosecutions to a decade-long advanced persistent threat (APT) campaign, showing that incriminating files used to imprison defendants were delivered as part of a coordinated effort to compromise and frame high-risk individuals, not a series of isolated intrusions.
Liberty · Due process · Integrity of digital evidence
CASE 02
Ukraine · Destructive malware · 2024
AcidPour
I found a previously unknown Linux wiper active in Ukraine and led the investigation that established it as AcidPour. Its input/output control wiping logic, recursive deletion, and expanded flash-storage and Device Mapper support connected it to AcidRain and Russian military-intelligence activity tracked under the Sandworm construct. Built to disable embedded networking, RAID, SAN/NAS, and potentially industrial control systems, it appeared while multiple Ukrainian telecom operators were enduring sustained disruption.
I led the work that identified and publicly exposed Chinese state-sponsored reconnaissance, a ShadowPad intrusion through an employee hardware-logistics provider, and North Korean infiltration attempts directed at SentinelOne itself. We turned attacks on a top-tier security target into an intelligence advantage, prevented compromise, and mapped related China-nexus operations across more than 70 organizations.
PurpleHaze · ShadowPad · 360 personas · 1,000+ applications
Consequence
SentinelOne · Customers · The security supply chain
CASE 04
Global · Industrialized crime · 2025
FreeDrain
With researchers at Validin, I helped turn one victim's loss of roughly $500,000 in bitcoin into a purpose-built collection system that mapped 38,000+ lure sites. We exposed how FreeDrain industrialized seed-phrase theft through SEO manipulation, free publishing platforms, cloud hosting, and layered redirects, making a years-old criminal system visible at internet scale.
I lead research for SentinelLABS while remaining an investigator, not a manager watching the work from a distance.
I shape research priorities, identify the questions worth pursuing, connect researchers with data and outside expertise, raise the evidentiary bar, and help carry difficult findings into detections, private briefings, product decisions, and the public record.
Increasingly, I build the systems around the investigator: collection pipelines, enrichment, historical correlation, and AI-assisted workflows that preserve provenance and analytical judgment.
Research agendaAnalytical rigorTeam developmentGovernment coordinationAI-era tradecraftOperational impact
Defense practice / Pro bono
Protection where the risk is highest.
Through SentinelLABS and trusted partners, I built and operate a pro bono global telemetry collection and defense network for people and organizations facing disproportionate exposure to advanced threats.
It extends telemetry, threat hunting, incident response, and coordinated defense to public institutions, private organizations, NGOs, media, critical infrastructure, and individuals targeted because of where they live or the work they do.
These are environments pursued by the world's most sophisticated state and mercenary actors. Most outcomes remain private by design; the measure is whether people and institutions are safer.
Protected environments
Public · Private · NGO · Media · Critical infrastructure · Individual
My responsibility is larger than my byline: the agenda, conditions, and standards behind a program that repeatedly produces consequential work. The researchers own their discoveries; I am accountable for leading the system that helps those discoveries happen and matter.
Historical APT research · Strategic sabotage
2005 → 2026
fast16
A previously undocumented sabotage framework, built five years before Stuxnet to corrupt high-precision calculations in memory. Its target-pattern overlaps include LS-DYNA, simulation software publicly tied to suspected Iranian nuclear-weapons modeling, raising the possibility that fast16 was aimed at nuclear-program workloads. SentinelLABS recovered the operation from historical samples, then turned it into a demanding benchmark for long-horizon AI analysis.
From LLM-enabled malware and exposed Ollama infrastructure to threat-intelligence knowledge extraction and autonomous reverse-engineering benchmarks, the program is establishing where AI changes the threat and where it can responsibly extend the analyst.
The program repeatedly exposes China-, North Korea-, Russia-, Iran-, and mercenary-linked operations across active wars, supply chains, critical infrastructure, high-risk communities, and the security industry itself.
I help shape LABScon as a program committee member and organizer, and have contributed from the stage as a speaker and keynote presenter, building a venue where original research, not product marketing, sets the agenda.
Applying the same research discipline to new analytical systems, the responsible use of AI, and the strategic problems of early-stage security companies.
01
Applied AI for threat intelligence
Designing analyst-centered workflows for extraction, enrichment, historical correlation, malware analysis, and agent memory, using models to expand reach while preserving provenance, uncertainty, and human judgment.
02
Research systems
Turning one-off investigations into durable collection, evidence, and analysis systems that make the next finding faster without lowering the evidentiary bar.
03
Startup advisory
Advising early-stage security companies on research strategy, product direction, market intelligence, and translating differentiated technical capability into durable customer value. My current public advisory work is with Validin.
For more than twenty years, I have moved from hands-on hardware and IT through offensive security, defense, digital forensics and incident response, network and endpoint visibility, threat research, geopolitical analysis, and global threat-intelligence leadership.
That range is now one of my core investigative advantages. I can move from a low-level artifact and intrusion mechanics across defensive surfaces, then connect technical behavior to infrastructure, organizations, intent, and geopolitical consequence.
The constant is simple: find something important, prove it carefully, and make it useful to the people who can act, privately or publicly.
2005–09
Hardware first, down to the board
My career began with long term Network Engineering and Security training at a dedicated technical school while still in high school, followed by hands-on IT work throughout college. The work went well below assembly: diagnosing board-level faults, repairing motherboards, soldering components and traces, and doing bench work at near-microscopic scale. That habit of reasoning from physical failure upward became the foundation for how I investigate systems today.
2009–15
Across the security stack
Moved from full-time IT into offense, defense, incident response, forensics, network security, endpoint visibility, and security operations. That breadth taught me how the same system looks to builders, operators, defenders, and attackers.
2015–19
ProtectWise / 401TRG
Directed threat research across full-fidelity network telemetry, led a five-person research team, and turned live intrusions into durable actor intelligence.
2019–21
AT&T Alien Labs + Lacework
Built intelligence programs across telecommunications and cloud environments, connecting original research directly to detection and product decisions.
2021–now
SentinelLABS
Senior → Principal → Distinguished Threat Researcher + Research Lead, setting the agenda, staying hands-on, and making the entire research program more consequential.
04 / Evidence plates
Inside the evidence.
Public reporting compresses months of investigation into a few conclusions. These releasable fragments show the record underneath: operator tasking, control-server logs, actor-supplied source, infrastructure relationships, and commercial offerings. Each had to be authenticated, challenged, and placed in context before it could support a judgment.
E-01 · Elephant Hunting / Appin
Operator tasking becomes infrastructure
An internal request and approval chain for acquiring a domain explicitly designated for phishing and executable delivery.
E-02 · Elephant Hunting / Appin
Collection visible at the command server
Control-server logs documenting file retrieval from compromised systems; victim IP addresses are deliberately redacted.
E-03 · Elephant Hunting / Appin
The actor's source, not an inference
A source-code snapshot delivered by the mercenary actor, exposing custom USB propagation logic and internal development details.
E-04 · Comrades in Arms?
ScarCruft infrastructure link
A relationship graph connecting an address, operational domains, and campaign payloads associated with ScarCruft activity.
E-05 · JumpCloud intrusion
Attribution through overlap
A confidence-scored map connecting JumpCloud indicators and a GitHub security alert to infrastructure controlled by a North Korean threat actor.
E-06 · Void Balaur / Hacknet-Service
Intrusion sold by the account
A translated excerpt of Hacknet-Service offerings, pricing access to email, social-media, and corporate accounts.
05 / Operational record
From first signal to operational consequence.
A sample public archive: 24 investigations I originated, led, or materially shaped. These are evidence of the practice, not a complete list; many of the most consequential outcomes remain in private briefings, response, detection, product decisions, and partner coordination.
2025.10Ukraine · Humanitarian and government targetingPhantomCaptcha ↗Lead investigation · Ukraine responseTechnical recordWeaponized PDFs led through a fake Cloudflare CAPTCHA into a three-stage PowerShell chain and WebSocket remote-access trojan (RAT); infrastructure pivots exposed an additional Android collection path.Why it matteredMapped a six-month operation that went live for a single day against the International Committee of the Red Cross, UNICEF, war-relief nongovernmental organizations, and Ukrainian regional government before its infrastructure disappeared.2025.06China · State-sponsored espionageFollow the Smoke / PurpleHaze ↗Research lead, with Aleksandar MilenkoskiTechnical recordConnected reconnaissance against SentinelOne, a ShadowPad intrusion through an employee hardware-logistics provider, and related PurpleHaze activity spanning 70+ organizations.Why it matteredShowed how China-nexus actors work around a top-tier security target by attacking its ecosystem, then converted a defended intrusion into public intelligence for the entire industry.2025.05Global · Cryptocurrency theftFreeDrain Unmasked ↗Co-investigation lead · Collection designTechnical recordPurpose-built collection mapped SEO poisoning, free-tier publishing, cloud-hosted phishing, layered redirect chains, and more than 38,000 lure subdomains.Why it matteredTurned one victim's roughly $500,000 bitcoin loss into the exposure of a years-old, industrialized seed-phrase theft system operating at internet scale.2025.04China and North Korea · Security-company targetingTop Tier Target ↗Research lead · Public disclosureTechnical recordCombined direct intrusion evidence with a North Korean hiring pipeline of roughly 360 fake personas and more than 1,000 applications, alongside crimeware and nation-state probing.Why it matteredMade the security vendor itself visible as a strategic attack surface: a route to customer telemetry, detection knowledge, software, and trusted access.2025.02Belarus and Ukraine · State-aligned espionageGhostwriter ↗Lead researcherTechnical recordTracked weaponized XLS and RAR lures, live command infrastructure, and adaptations of PicassoLoader across a campaign prepared for months before activation.Why it matteredDocumented Ghostwriter targeting Belarusian opposition activists directly for the first time, alongside Ukrainian military and government organizations.2024.11North Korea and China · Sanctions evasionNorth Korean IT worker front companies ↗Research lead, with Dakota CaryTechnical recordUsed web fingerprints, copied brands, hosting history, and domain clusters to connect seized sites with still-active software front companies created in China.Why it matteredExpanded the map of a sanctions-evasion pipeline funding the North Korean regime. Subsequent U.S. actions charged Chinese facilitators and seized additional companies, domains, and financial infrastructure.U.S. enforcement action ↗2024.03Russia and Ukraine · Destructive military operationAcidPour ↗Discovery · Investigation lead, with Juan Andrés Guerrero-SaadeTechnical recordReversed a stripped x86 ELF wiper using direct syscalls, self-deletion, IOCTL device wiping, recursive deletion, and new UBI and Device Mapper targeting for embedded flash and RAID-scale storage.Why it matteredLinked a more capable AcidRain variant to Russian military-intelligence activity and the Sandworm construct while Ukrainian telecom networks were under sustained disruption.2023.11India · Hack-for-hire operationsElephant Hunting / Appin ↗Technical investigation leadTechnical recordCorrelated rare internal operator communications with control-server logs, actor-supplied source code, malware, domains, hosting, and certificates to reconstruct more than a decade of Appin operations and successor activity.Why it matteredExposed the inner workings of a commercial hacking operation whose customers targeted journalists, activists, litigants, government entities, businesses, and private individuals worldwide. The findings triggered legal threats and a court-ordered takedown; SentinelOne publicly stood by the research.2023.10Iran and the Middle East · State-sponsored operationsThe Israel–Hamas War: cyber domain ↗Immediate response · Research leadTechnical recordResolved actor-name overlap and assembled an operational watchlist across Hamas-, Hezbollah-, and Iran-aligned clusters while separating state activity from hacktivism and information noise.Why it matteredGave defenders an evidence-based map of the actors most capable of producing real-world effects during the first weeks of a rapidly evolving war.2023.09China and Africa · State-sponsored espionageCyber Soft Power ↗Originated · Research lead · Working-group founderTechnical recordConnected BackdoorDiplomacy and Operation Tainted Love intrusions across African telecom, finance, and government targets to the Chinese government's wider strategic posture.Why it matteredMade cyber operations in Africa legible as instruments of state influence and launched the Undermonitored Regions Working Group to close a global intelligence blind spot.2023.08North Korea and Russia · Defense-sector espionageComrades in Arms? ↗Discovery · Research lead, with Aleksandar MilenkoskiTechnical recordIdentified simultaneous ScarCruft and Lazarus compromises, including the OpenCarrot backdoor, inside NPO Mashinostroyeniya's sensitive internal infrastructure.Why it matteredRevealed rare adversary-on-adversary espionage: North Korea inside a sanctioned Russian producer of missiles and military spacecraft, likely seeking technology for its own weapons program.2023.07North Korea · Supply-chain intrusionJumpCloud intrusion ↗Attribution · Infrastructure analysisTechnical recordPivoted from JumpCloud's released indicators through passive DNS records, certificates, hosting, and domain-construction patterns to connect the supply-chain intrusion with North Korean infrastructure.Why it matteredPut North Korean attribution around an intrusion into a cloud identity and device-management provider capable of opening downstream access to high-value customers.2023.03Russia and Belarus · Government espionageWinter Vivern ↗Research leadTechnical recordExpanded partner observations into previously unknown credential-phishing and malicious-document campaigns using tailored loaders against government and telecom targets.Why it matteredRestored visibility into an underreported, resource-limited but creative espionage actor aligned with Russian and Belarusian objectives across Europe and India.2023.01Russia · State-backed disruptionNoName057(16) ↗Research lead, with Aleksandar MilenkoskiTechnical recordExposed DDOSIA's Python and Go implementations, command-and-control (C2) and target configuration, Telegram recruitment, volunteer payments, and politically timed targeting of NATO critical infrastructure.Why it matteredEstablished an early operational picture later reflected in multinational disruption, arrest warrants, U.S. charges, and public identification of the group's covert ties to a Russian state organization.U.S. indictment and attribution ↗2022.09Russia and global targets · Commercial hackingVoid Balaur ↗Lead researcherTechnical recordMapped a sprawling mercenary infrastructure selling access to email, social, messaging, and corporate accounts, including attack paths designed to work around MFA.Why it matteredExpanded the public record of a commercial intrusion service targeting political and business interests across Russia, Ukraine, the United States, and beyond.2022.07China and Russia · State-sponsored espionageChinese APTs target Russia ↗Discovery · Lead researcherTechnical recordConnected Royal Road exploit documents, Bisonal backdoors, lure themes, and infrastructure into a new China-nexus espionage cluster targeting Russian organizations.Why it matteredShowed that Russia's invasion had intensified Chinese intelligence collection against Russian targets alongside operations directed at Ukraine.2022.03China and Ukraine · State-sponsored espionageScarab enters the Ukraine war ↗Discovery · Lead researcherTechnical recordLinked UAC-0026's HeaderTip backdoor and reused command infrastructure to the Chinese-speaking Scarab APT with high confidence.Why it matteredIdentified the first publicly reported Chinese APT targeting Ukraine after Russia's full-scale invasion, changing the industry's picture of who was collecting inside the conflict.2022.02India · Surveillance and evidence fabricationModifiedElephant ↗Originated · Investigated · Research leadTechnical recordCorrelated ten years of spearphishing, NetWire and DarkComet RAT activity, exploit documents, keyloggers, and rotating infrastructure across hundreds of targets.Why it matteredConnected the digital evidence used against Bhima Koregaon defendants to a coordinated APT campaign built to surveil and frame human-rights defenders, lawyers, academics, and activists.2021.01India and South Asia · State-aligned espionageA Global Perspective of SideWinder ↗Lead researcherTechnical recordConnected malware, infrastructure, lure documents, and campaign history into a global view of a South Asian espionage actor, with a separate public detection and IOC corpus.Why it matteredMoved SideWinder beyond region-by-region snapshots and gave defenders a reusable body of evidence for historical hunting and future detection.2019.07Europe and North Africa · Selective espionageNew StrongPity operations ↗Lead researcherTechnical recordIdentified previously unknown StrongPity activity built around trojanized software installers, watering-hole delivery, new malware variants, and associated infrastructure.Why it matteredExtended visibility into a selective espionage actor that compromised trusted software-download behavior to reach carefully chosen targets.2018.05China · State-sponsored and commercial operationsBurning Umbrella / Winnti ↗Originated · Lead researcherTechnical recordUsed years of full-fidelity network telemetry to connect previously separate Chinese operations, infrastructure, spearphishing, Cobalt Strike tradecraft, and code-signing-certificate theft.Why it matteredEstablished that 'Winnti' was not one group but an umbrella of cooperating teams and missions. This work helped establish the model the industry adopted for understanding the actor ecosystem.2017.10China · State-sponsored intrusionWinnti / LEAD update ↗Lead researcherTechnical recordDocumented BeEF-assisted infection, Cobalt Strike lateral movement, a Google Web Bug malleable C2 profile, and continued theft of credentials, internal records, and signing certificates.Why it matteredCaptured the shift from bespoke malware toward commodity tooling without losing the continuity of the operator, infrastructure, and mission.2017.10Russia · State-sponsored espionageTurla watering holes ↗Lead researcherTechnical recordUsed full-packet network evidence to trace compromised websites, visitor profiling, and selective delivery across Turla watering-hole activity observed in 2016 and 2017.Why it matteredTurned a stealthy web-delivery mechanism into a defensible campaign record that organizations could hunt retrospectively.2017.07China · State-sponsored intrusionWinnti evolves toward open source ↗Lead researcherTechnical recordTracked the actor's adoption of public offensive-security tooling inside gaming-sector intrusions while preserving its recognizable access, movement, and collection patterns.Why it matteredShowed defenders why actor tracking could not depend on a bespoke malware family: the mission persisted even as the toolchain became widely available.
06 / Field notes
How serious cyber research actually gets done.
Working position / 01
Intelligence is not a feed.
The job is not to process more reporting. It is to preserve enough context to recognize what changed, what connects, and what matters.
Working position / 02
Attribution is a model, not a name.
Actor labels are useful until they hide the ecosystem: contractors, shared infrastructure, overlapping tasking, and evolving missions.
Working position / 03
AI needs an evidence discipline.
Models can accelerate collection and correlation. They cannot be allowed to turn claims into facts or proximity into proof.
07 / Reach
The work travels.
The Hague TIX · TLP-governed briefing
Briefing rooms
Government · Information Sharing and Analysis Centers · Executive leadership · Research partners
Intelligence shared directly with the institutions and practitioners responsible for defense, response, policy, and operational decisions.Public stage · Original threat research keynote
Public stages
Black Hat USA ×2 · CYBERWARCON · LABScon · PIVOTcon
Original investigations and tradecraft presented to technical and national-security audiences worldwide.NBC News · Critical-infrastructure analysis
News and analysis
CNN · NPR · NBC · Reuters · WIRED · Forbes · The Times · WSJ · Politico · Washington Post
Context on consequential cyber events for major international and specialist outlets.