Tom Hegel · Distinguished Threat Researcher · SentinelLABS Research Lead

I expose the cyber operations shaping events in the real world.

I find consequential adversary activity, lead the investigations that make it legible, and build intelligence systems that help defenders act on the evidence.

Portrait of Tom Hegel

The work begins with evidence and ends with consequence: adversaries understood, defenders equipped, institutions briefed, and decisions improved, whether the work remains private or enters the public record.

01

Find

Surface the first signal, recognize why it matters, and stay with it long enough to find the operation behind the artifact.

02

Lead

Frame the intelligence question, assemble the right expertise, challenge the evidence, and carry the work through disclosure.

03

Equip

Turn findings into detections, response, private decisions, public understanding, and systems that compound future research.

01 / Selected investigations

Original findings.
Real consequences.

02 / Leadership

The work is personal.
The outcome is collective.

I lead research for SentinelLABS while remaining an investigator, not a manager watching the work from a distance.

I shape research priorities, identify the questions worth pursuing, connect researchers with data and outside expertise, raise the evidentiary bar, and help carry difficult findings into detections, private briefings, product decisions, and the public record.

Increasingly, I build the systems around the investigator: collection pipelines, enrichment, historical correlation, and AI-assisted workflows that preserve provenance and analytical judgment.

Research agendaAnalytical rigorTeam developmentGovernment coordinationAI-era tradecraftOperational impact

Defense practice / Pro bono

Protection where the risk is highest.

Through SentinelLABS and trusted partners, I built and operate a pro bono global telemetry collection and defense network for people and organizations facing disproportionate exposure to advanced threats.

It extends telemetry, threat hunting, incident response, and coordinated defense to public institutions, private organizations, NGOs, media, critical infrastructure, and individuals targeted because of where they live or the work they do.

These are environments pursued by the world's most sophisticated state and mercenary actors. Most outcomes remain private by design; the measure is whether people and institutions are safer.

Protected environments
Public · Private · NGO · Media · Critical infrastructure · Individual
Operational support
Telemetry · Hunting · Incident response · Coordination
Threat class
Nation-state · Mercenary · Criminal

Program outcomes under my leadership

What the research program makes possible.

My responsibility is larger than my byline: the agenda, conditions, and standards behind a program that repeatedly produces consequential work. The researchers own their discoveries; I am accountable for leading the system that helps those discoveries happen and matter.

Historical APT research · Strategic sabotage

2005 → 2026

fast16

A previously undocumented sabotage framework, built five years before Stuxnet to corrupt high-precision calculations in memory. Its target-pattern overlaps include LS-DYNA, simulation software publicly tied to suspected Iranian nuclear-weapons modeling, raising the possibility that fast16 was aimed at nuclear-program workloads. SentinelLABS recovered the operation from historical samples, then turned it into a demanding benchmark for long-horizon AI analysis.

Read the fast16 research

AI research · Analyst systems

Models → evidence

AI beyond the demo

From LLM-enabled malware and exposed Ollama infrastructure to threat-intelligence knowledge extraction and autonomous reverse-engineering benchmarks, the program is establishing where AI changes the threat and where it can responsibly extend the analyst.

Explore the AI research program

Global intelligence · Operational response

Actors → institutions

APT research at consequence scale

The program repeatedly exposes China-, North Korea-, Russia-, Iran-, and mercenary-linked operations across active wars, supply chains, critical infrastructure, high-risk communities, and the security industry itself.

Read the program review

Conference building · Research community

Committee · Organizer · Speaker

LABScon

I help shape LABScon as a program committee member and organizer, and have contributed from the stage as a speaker and keynote presenter, building a venue where original research, not product marketing, sets the agenda.

View LABScon

Expanding the practice

Building beyond the report.

Applying the same research discipline to new analytical systems, the responsible use of AI, and the strategic problems of early-stage security companies.

01

Applied AI for threat intelligence

Designing analyst-centered workflows for extraction, enrichment, historical correlation, malware analysis, and agent memory, using models to expand reach while preserving provenance, uncertainty, and human judgment.

02

Research systems

Turning one-off investigations into durable collection, evidence, and analysis systems that make the next finding faster without lowering the evidentiary bar.

03

Startup advisory

Advising early-stage security companies on research strategy, product direction, market intelligence, and translating differentiated technical capability into durable customer value. My current public advisory work is with Validin.

Current advisory work

03 / About

The range behind
the research.

For more than twenty years, I have moved from hands-on hardware and IT through offensive security, defense, digital forensics and incident response, network and endpoint visibility, threat research, geopolitical analysis, and global threat-intelligence leadership.

That range is now one of my core investigative advantages. I can move from a low-level artifact and intrusion mechanics across defensive surfaces, then connect technical behavior to infrastructure, organizations, intent, and geopolitical consequence.

The constant is simple: find something important, prove it carefully, and make it useful to the people who can act, privately or publicly.

2005–09

Hardware first, down to the board

My career began with long term Network Engineering and Security training at a dedicated technical school while still in high school, followed by hands-on IT work throughout college. The work went well below assembly: diagnosing board-level faults, repairing motherboards, soldering components and traces, and doing bench work at near-microscopic scale. That habit of reasoning from physical failure upward became the foundation for how I investigate systems today.

2009–15

Across the security stack

Moved from full-time IT into offense, defense, incident response, forensics, network security, endpoint visibility, and security operations. That breadth taught me how the same system looks to builders, operators, defenders, and attackers.

2015–19

ProtectWise / 401TRG

Directed threat research across full-fidelity network telemetry, led a five-person research team, and turned live intrusions into durable actor intelligence.

2019–21

AT&T Alien Labs + Lacework

Built intelligence programs across telecommunications and cloud environments, connecting original research directly to detection and product decisions.

2021–now

SentinelLABS

Senior → Principal → Distinguished Threat Researcher + Research Lead, setting the agenda, staying hands-on, and making the entire research program more consequential.

04 / Evidence plates

Inside the evidence.

Public reporting compresses months of investigation into a few conclusions. These releasable fragments show the record underneath: operator tasking, control-server logs, actor-supplied source, infrastructure relationships, and commercial offerings. Each had to be authenticated, challenged, and placed in context before it could support a judgment.

Appin operator request and approval chain for purchasing a phishing and executable-delivery domain
E-01 · Elephant Hunting / Appin

Operator tasking becomes infrastructure

An internal request and approval chain for acquiring a domain explicitly designated for phishing and executable delivery.

Command-and-control server data-exfiltration logs with victim IP addresses redacted
E-02 · Elephant Hunting / Appin

Collection visible at the command server

Control-server logs documenting file retrieval from compromised systems; victim IP addresses are deliberately redacted.

Source-code snapshot delivered by a mercenary actor showing USB propagation logic
E-03 · Elephant Hunting / Appin

The actor's source, not an inference

A source-code snapshot delivered by the mercenary actor, exposing custom USB propagation logic and internal development details.

Infrastructure relationship graph connecting domains, an IP address, and payloads associated with ScarCruft
E-04 · Comrades in Arms?

ScarCruft infrastructure link

A relationship graph connecting an address, operational domains, and campaign payloads associated with ScarCruft activity.

Infrastructure map showing overlaps between JumpCloud indicators, a GitHub security alert, and North Korean threat activity
E-05 · JumpCloud intrusion

Attribution through overlap

A confidence-scored map connecting JumpCloud indicators and a GitHub security alert to infrastructure controlled by a North Korean threat actor.

Translated Hacknet-Service offerings and prices for access to email, social-media, and corporate accounts
E-06 · Void Balaur / Hacknet-Service

Intrusion sold by the account

A translated excerpt of Hacknet-Service offerings, pricing access to email, social-media, and corporate accounts.

05 / Operational record

From first signal to operational consequence.

A sample public archive: 24 investigations I originated, led, or materially shaped. These are evidence of the practice, not a complete list; many of the most consequential outcomes remain in private briefings, response, detection, product decisions, and partner coordination.

2025.10Ukraine · Humanitarian and government targetingPhantomCaptchaLead investigation · Ukraine responseTechnical recordWeaponized PDFs led through a fake Cloudflare CAPTCHA into a three-stage PowerShell chain and WebSocket remote-access trojan (RAT); infrastructure pivots exposed an additional Android collection path.Why it matteredMapped a six-month operation that went live for a single day against the International Committee of the Red Cross, UNICEF, war-relief nongovernmental organizations, and Ukrainian regional government before its infrastructure disappeared.
2025.05Global · Cryptocurrency theftFreeDrain UnmaskedCo-investigation lead · Collection designTechnical recordPurpose-built collection mapped SEO poisoning, free-tier publishing, cloud-hosted phishing, layered redirect chains, and more than 38,000 lure subdomains.Why it matteredTurned one victim's roughly $500,000 bitcoin loss into the exposure of a years-old, industrialized seed-phrase theft system operating at internet scale.
2025.04China and North Korea · Security-company targetingTop Tier TargetResearch lead · Public disclosureTechnical recordCombined direct intrusion evidence with a North Korean hiring pipeline of roughly 360 fake personas and more than 1,000 applications, alongside crimeware and nation-state probing.Why it matteredMade the security vendor itself visible as a strategic attack surface: a route to customer telemetry, detection knowledge, software, and trusted access.
2025.02Belarus and Ukraine · State-aligned espionageGhostwriterLead researcherTechnical recordTracked weaponized XLS and RAR lures, live command infrastructure, and adaptations of PicassoLoader across a campaign prepared for months before activation.Why it matteredDocumented Ghostwriter targeting Belarusian opposition activists directly for the first time, alongside Ukrainian military and government organizations.
2024.11North Korea and China · Sanctions evasionNorth Korean IT worker front companiesResearch lead, with Dakota CaryTechnical recordUsed web fingerprints, copied brands, hosting history, and domain clusters to connect seized sites with still-active software front companies created in China.Why it matteredExpanded the map of a sanctions-evasion pipeline funding the North Korean regime. Subsequent U.S. actions charged Chinese facilitators and seized additional companies, domains, and financial infrastructure.U.S. enforcement action
2023.10Iran and the Middle East · State-sponsored operationsThe Israel–Hamas War: cyber domainImmediate response · Research leadTechnical recordResolved actor-name overlap and assembled an operational watchlist across Hamas-, Hezbollah-, and Iran-aligned clusters while separating state activity from hacktivism and information noise.Why it matteredGave defenders an evidence-based map of the actors most capable of producing real-world effects during the first weeks of a rapidly evolving war.
2023.09China and Africa · State-sponsored espionageCyber Soft PowerOriginated · Research lead · Working-group founderTechnical recordConnected BackdoorDiplomacy and Operation Tainted Love intrusions across African telecom, finance, and government targets to the Chinese government's wider strategic posture.Why it matteredMade cyber operations in Africa legible as instruments of state influence and launched the Undermonitored Regions Working Group to close a global intelligence blind spot.
2023.08North Korea and Russia · Defense-sector espionageComrades in Arms?Discovery · Research lead, with Aleksandar MilenkoskiTechnical recordIdentified simultaneous ScarCruft and Lazarus compromises, including the OpenCarrot backdoor, inside NPO Mashinostroyeniya's sensitive internal infrastructure.Why it matteredRevealed rare adversary-on-adversary espionage: North Korea inside a sanctioned Russian producer of missiles and military spacecraft, likely seeking technology for its own weapons program.
2023.07North Korea · Supply-chain intrusionJumpCloud intrusionAttribution · Infrastructure analysisTechnical recordPivoted from JumpCloud's released indicators through passive DNS records, certificates, hosting, and domain-construction patterns to connect the supply-chain intrusion with North Korean infrastructure.Why it matteredPut North Korean attribution around an intrusion into a cloud identity and device-management provider capable of opening downstream access to high-value customers.
2023.03Russia and Belarus · Government espionageWinter VivernResearch leadTechnical recordExpanded partner observations into previously unknown credential-phishing and malicious-document campaigns using tailored loaders against government and telecom targets.Why it matteredRestored visibility into an underreported, resource-limited but creative espionage actor aligned with Russian and Belarusian objectives across Europe and India.
2022.09Russia and global targets · Commercial hackingVoid BalaurLead researcherTechnical recordMapped a sprawling mercenary infrastructure selling access to email, social, messaging, and corporate accounts, including attack paths designed to work around MFA.Why it matteredExpanded the public record of a commercial intrusion service targeting political and business interests across Russia, Ukraine, the United States, and beyond.
2022.07China and Russia · State-sponsored espionageChinese APTs target RussiaDiscovery · Lead researcherTechnical recordConnected Royal Road exploit documents, Bisonal backdoors, lure themes, and infrastructure into a new China-nexus espionage cluster targeting Russian organizations.Why it matteredShowed that Russia's invasion had intensified Chinese intelligence collection against Russian targets alongside operations directed at Ukraine.
2022.03China and Ukraine · State-sponsored espionageScarab enters the Ukraine warDiscovery · Lead researcherTechnical recordLinked UAC-0026's HeaderTip backdoor and reused command infrastructure to the Chinese-speaking Scarab APT with high confidence.Why it matteredIdentified the first publicly reported Chinese APT targeting Ukraine after Russia's full-scale invasion, changing the industry's picture of who was collecting inside the conflict.
2021.01India and South Asia · State-aligned espionageA Global Perspective of SideWinderLead researcherTechnical recordConnected malware, infrastructure, lure documents, and campaign history into a global view of a South Asian espionage actor, with a separate public detection and IOC corpus.Why it matteredMoved SideWinder beyond region-by-region snapshots and gave defenders a reusable body of evidence for historical hunting and future detection.
2019.07Europe and North Africa · Selective espionageNew StrongPity operationsLead researcherTechnical recordIdentified previously unknown StrongPity activity built around trojanized software installers, watering-hole delivery, new malware variants, and associated infrastructure.Why it matteredExtended visibility into a selective espionage actor that compromised trusted software-download behavior to reach carefully chosen targets.
2017.10China · State-sponsored intrusionWinnti / LEAD updateLead researcherTechnical recordDocumented BeEF-assisted infection, Cobalt Strike lateral movement, a Google Web Bug malleable C2 profile, and continued theft of credentials, internal records, and signing certificates.Why it matteredCaptured the shift from bespoke malware toward commodity tooling without losing the continuity of the operator, infrastructure, and mission.
2017.10Russia · State-sponsored espionageTurla watering holesLead researcherTechnical recordUsed full-packet network evidence to trace compromised websites, visitor profiling, and selective delivery across Turla watering-hole activity observed in 2016 and 2017.Why it matteredTurned a stealthy web-delivery mechanism into a defensible campaign record that organizations could hunt retrospectively.
2017.07China · State-sponsored intrusionWinnti evolves toward open sourceLead researcherTechnical recordTracked the actor's adoption of public offensive-security tooling inside gaming-sector intrusions while preserving its recognizable access, movement, and collection patterns.Why it matteredShowed defenders why actor tracking could not depend on a bespoke malware family: the mission persisted even as the toolchain became widely available.

06 / Field notes

How serious cyber research actually gets done.

Working position / 01

Intelligence is not a feed.

The job is not to process more reporting. It is to preserve enough context to recognize what changed, what connects, and what matters.

Working position / 02

Attribution is a model, not a name.

Actor labels are useful until they hide the ecosystem: contractors, shared infrastructure, overlapping tasking, and evolving missions.

Working position / 03

AI needs an evidence discipline.

Models can accelerate collection and correlation. They cannot be allowed to turn claims into facts or proximity into proof.

07 / Reach

The work travels.

Tom Hegel delivering a trusted intelligence briefing at The Hague TIX
The Hague TIX · TLP-governed briefing

Briefing rooms

Government · Information Sharing and Analysis Centers · Executive leadership · Research partners

Intelligence shared directly with the institutions and practitioners responsible for defense, response, policy, and operational decisions.
Tom Hegel presenting original threat research on a public conference stage
Public stage · Original threat research keynote

Public stages

Black Hat USA ×2 · CYBERWARCON · LABScon · PIVOTcon

Original investigations and tradecraft presented to technical and national-security audiences worldwide.
Tom Hegel discussing cyberattacks on United States water systems on NBC News
NBC News · Critical-infrastructure analysis

News and analysis

CNN · NPR · NBC · Reuters · WIRED · Forbes · The Times · WSJ · Politico · Washington Post

Context on consequential cyber events for major international and specialist outlets.

08 / Contact

For consequential work and serious conversations.

Research collaboration, private briefings, selective advisory work, and the future of intelligence systems.