Hariharan M

Cyber Threat Intelligence

I find what’s exposed and who’s exploiting it, then build what keeps finding them.

External attack surface · Digital Risk Protection · Dark web · Financial cybercrime · HUMINT · Detection engineering · Security R&D

Cyber threat intelligence is the core, worked from the outside in: the exposure an organisation does not know it has, the brands and infrastructure impersonating it, and the actors profiting. Then the collection and detection systems that keep surfacing it, the products those become, and the proofs of concept that prove them.

Confirmed link Inferred link Illustrative model · hover a node
  • 156,413 UPI IDs mapped to 598 fraud websites MeasuredF2Mon dataset, computed from source workbook · Saptang Labs
  • 4,055 abused government URLs across 3 SEO-poisoning campaigns MeasuredRummy Circle 2,041 · A23 1,051 · Adda52 963
  • 102 money-mule sites clustered from one template fingerprint Observed~100 host and IP nodes · Alibaba Cloud allocations
  • 38,728 scam advertisements discovered MeasuredWith 6,455 fake customer-care URLs and 3,385 vishing numbers

About about.md

Based in India

Core

Cyber Threat Intelligence · Cybercrime Intelligence

Specialisations

Dark Web · Financial Cybercrime · Digital Risk Protection · Attack Surface Management · Threat Research

Engineering

Detection · Collection · Infrastructure · Automation

Business

Product research & specification · Technical PoCs · Pre-sales support

I work on the part of cybercrime that has infrastructure behind it. A scam is not one website, it is an advertising estate, a set of look-alike domains, a Telegram channel recruiting mules, and a chain of accounts moving money. My job is to find that structure, establish what connects to what and with what confidence, and hand it to the people who can act on it.

The investigation and the engineering are the same job for me. Every system on this page exists because a manual process could not run at the rate the problem demanded: collection across twenty-odd underground sources, certificate monitoring that catches a look-alike domain the day it is issued, reconnaissance across the public IPv4 space. I build the tooling because I am the analyst who has to use it.

I care about intelligence that changes something. The work I am most pleased with is not the largest dataset, it is the indicators that reached I4C and NPCI and the complaint system a cybercrime unit actually uses. Where a claim on this site cannot be independently checked, it says so.

Connect on LinkedIn /in/hariharanmathan

Evidence

Case studies llms-full.txt

4 investigations  ·  2023–2026

Four systems, each with the problem it solved, what I personally built, and how the result was measured. Attribution is stated on every one.

Case study / CTI-001  ·  Financial Cybercrime Intelligence

Money Mule Identification System

The problem

Investment scams, betting platforms and lottery frauds across India and Southeast Asia move victim money through mule accounts. The first hop is the one that matters: once funds leave it, tracing and recovery collapse. Catching those accounts meant finding them in the window between creation and first use.

Why it mattered

Banks and government agencies could act on a mule account, but only if someone handed them one they could act on. The bottleneck was never enforcement. It was identification at a rate and a confidence level that justified acting.

What I built

A collection and correlation system spanning 20+ underground forums, marketplaces and Telegram channels, combined with direct threat actor engagement under OPSEC procedure to map infrastructure passive collection could not reach. Output was a dataset of actor identifiers referable to national fraud-response channels.

Referral I4C · NPCI 598 SCAM SITES GATEWAY OPERATORS MULE ACCOUNTS many few · rotating VPAs 156,413 UPI IDs
156,413

UPI IDs mapped to 598 fraud websites, alongside 224,978 VPA-handle records and 212,226 phone records across 107 countries. Structured for referral to national fraud-response channels.

Detail
What I investigated
OSINT, HUMINT and social engineering across crypto scams, lottery and gambling schemes and money mule networks, including threat actor engagement under OPSEC procedure to verify leaked data and establish modus operandi.
Collection scope
20+ underground forums, dark web marketplaces and Telegram channels, tracking ransomware groups and scam operations and mapping adversary TTPs to MITRE ATT&CK.
What the system produced
156,413 UPI IDs mapped to 598 source websites across 36 identified site clusters; 224,978 VPA-handle records across 103 handles; 212,226 phone records across 107 countries; 2,209 IFSC-derived bank records resolved to bank, city and state.
Outcome
Established that the payment gateway, not the scam site, owns the rotating UPI IDs, harvested from part-time-job victims at a 7% commission. Recovered gateway API documentation, a test merchant credential and a live order-response schema exposing payee UPI, bank account, IFSC and recipient name.
Who it went to
I4C and NPCI, plus law enforcement and regulatory investigations into financial fraud, terrorist funding and extremist networks.

Case study / CTI-002  ·  Attack Surface Intelligence

Internet-Scale Scanning Infrastructure

The problem

Attack surface management is only useful if the picture is current. A survey of the global IPv4 HTTPS surface that takes weeks describes a world that has already moved. The requirement was full coverage on a cadence short enough that findings were still true when a client read them.

Why it mattered

Everything downstream inherits the freshness of the scan beneath it: exposure monitoring, fingerprinting, secret-leakage detection, and the client reporting built on top of them.

What I built

Scanning infrastructure provisioned with Terraform on AWS. ZMap performs stateless host discovery, zgrab2 completes the application-layer handshake to collect banners and certificates, and results are indexed in Elasticsearch for analysis.

banner certificate indexed PUBLIC IPv4 PLANE PER RESPONDING HOST stateless discovery · ZMap zgrab2 · Elasticsearch
IPv4

internet-scale reconnaissance with ZMap and zgrab2 on Terraform-provisioned AWS, feeding asset discovery, service fingerprinting and secret-leakage detection.

Detail
What I built
Internet-scale scanning infrastructure on AWS, provisioned with Terraform, using ZMap for host discovery and zgrab2 for application-layer banner collection, with results indexed in Elasticsearch.
What it feeds
Asset discovery, exposure monitoring, service fingerprinting and secret-leakage detection, supporting AI attack surface management work.
How the output reached clients
I redesigned ASM reporting into separate executive and technical tracks, so the person who signs and the person who remediates each get the document they actually need.
Where it was used commercially
Technical proofs of concept during customer evaluations, run alongside pre-sales to demonstrate attack surface, dark web and ransomware monitoring capability.

Case study / CTI-003  ·  Detection Engineering

PhishSquat — Phishing Domain Intelligence Platform

The problem

Manually finding and investigating look-alike domains is slow and incomplete. By the time a customer reports a phishing site the campaign has run for days, and hand-built findings arrive without the evidence an analyst needs to defend a takedown.

Why it mattered

A takedown request has to be explainable. Someone must be able to say why this domain is malicious and that one is a legitimate partner. Without a scoring model, every candidate becomes a manual investigation and the queue never clears.

What I built

A four-module pipeline with defined file contracts between stages: AntiSquat (Gemini-driven permutation generation plus PhishTank), DNSTwist (DNS fuzzing with registration verification), TypoSquat (Go, misspelling and homoglyph generation, then A-record, parking and MX triage), and the analysis engine that scores what survives.

brand.com homoglyph insertion deletion substitution TLD swap prefix suffix combo A · PARK · MX HIGH 55–100 MEDIUM 30–54 LOW 0–29 PERMUTATIONS WEIGHTED CONFIDENCE favicon 25 · title 25 · age 25 content 15 · captcha 15 · redirect 10
0–100

weighted confidence model across six independent signals, deliberately capped so no single indicator can max the score. A verdict needs convergent evidence, which is what makes it defensible to a registrar.

Detail
Discovery
The Gemini API generates homoglyphs, typos, keyboard-adjacent errors and prefix/suffix patterns from the protected brand, expanded across TLD variants. dnstwist adds bit-flip, transposition and insertion permutations with registration verification. PhishTank supplies already-confirmed phishing for immediate action.
Triage before analysis
Three sources are merged and deduplicated, then filtered on A-record presence, parking detection and MX lookup. Mail-enabled look-alikes are separated into their own output because a look-alike with MX records is a business email compromise risk, not just a phishing risk.
Seven-step analysis per domain
Redirect chain, favicon comparison by perceptual hash, page content, WHOIS and domain age, structural analysis, tag generation, then confidence scoring.
Scoring model
Favicon similarity 25, title similarity 25, domain age 25, content keywords 15, CAPTCHA presence 15, redirect suspicion 10. Bands: High 55–100, Medium 30–54, Low 0–29. Favicon match threshold 0.85 perceptual similarity; a domain under 90 days old is tagged new; three or more hops is a long redirect chain.
Ten-tag risk taxonomy
favicon_match, brand_title_match, content_match, captcha_protected, new_domain, suspicious_redirect, long_redirect_chain, close_typo, homoglyph, risky_tld. Tags are what turn a score into a reason.
Analyst triage path
High to takedown, legal or blocklist. Medium to the analyst queue. Low to watchlist. Single-command run with selective step-skipping, so a re-run does not repeat expensive discovery.
Detection rule authoring
Separately, a Sigma/IOK rule matching sites reusing Bank BRI page titles while excluding the legitimate hostname produced six confirmed detections, including clones hosted on *.vercel.app and *.pages.dev.

Case study / CTI-004  ·  Independent Initiative

Cybercrime Complaint & Case Management Platform

The problem

A local cybercrime response unit was taking citizen complaints through unstructured channels. Details arrived incomplete, cases were tracked manually, and investigators spent time on collection and collation rather than investigation.

Why it mattered

Complaint handling is the front door to cybercrime response. If intake is slow and unstructured, the investigation starts late and starts incomplete, which for financial fraud is the difference between recoverable and not.

What I built

A WhatsApp-based intake and case-tracking system: structured complaint capture, centralised case records, and triage so investigators can prioritise. Designed and deployed independently, on personal time, for a local cybercrime response unit.

Intake 01 Triage 02 Evidence 03 Assignment 04 Resolution 05 returned for further evidence escalation CASE LIFECYCLE
~75%

Estimated reduction in manual complaint-handling workload, with improved triage and response times. Independent initiative, unaffiliated with any employer.

Detail
Why this matters professionally
It demonstrates ownership outside assigned responsibilities: identifying an operational bottleneck, designing a workflow around how investigators actually work, and deploying it.
Attribution
Designed and deployed independently on personal time. Not employer work, and labelled as such throughout this site.
Measurement
The workload reduction is an estimate based on the manual steps removed from intake and collation, not an instrumented measurement.

Tools and platforms

  • TorDark web collection
  • ShodanExposed service discovery
  • CensysCertificate and host intelligence
  • VirusTotalReputation and detonation
  • urlscan.ioPage render and redirect chains
  • SecurityTrailsPassive DNS and history
  • FOFAInfrastructure fingerprinting
  • Silent PushPhishing infrastructure pivots
  • MaltegoEntity relationship mapping
  • TelegramChannel monitoring and HUMINT
  • AWSScanning and pipeline infrastructure
  • DockerService deployment
  • PythonCollection and detection tooling
  • MongoDBIndicator storage
  • CeleryDistributed task queues
  • ElasticsearchScan result indexing
  • ClaudeAnalysis and tooling assistance
  • ChatGPTAnalysis and tooling assistance
  • CursorDevelopment environment
  • LinuxDaily driver
  • KaliInvestigation tooling
  • WiresharkTraffic inspection
  • Burp SuiteWeb request analysis
  • FastAPITelescribe API
  • ReactAnalyst dashboards
  • ViteFrontend build
  • TryHackMeSkills practice

Experience resume.md

3+ years  ·  2 companies

2025
  • Built internet-scale reconnaissance on AWS and Terraform using ZMap and zgrab2, indexing exposed-asset results in Elasticsearch.
  • Led Digital Risk Protection investigations for enterprise clients: phishing campaigns, brand impersonation, rogue applications, exposed infrastructure and dark web threats.
  • Ran technical PoCs during customer evaluations across ASM, dark web and ransomware monitoring and brand protection, partnering with pre-sales to demonstrate capability.
  • Engineered phishing monitoring from Certificate Transparency logs, typosquatting analysis and domain intelligence, enriched via VirusTotal and URLScan.io for early detection and IOC triage.
  • Designed a Telegram intelligence platform monitoring hundreds of channels and groups for collection and enrichment.
  • Authored the team's SOPs for persona management and brand-impersonation investigations, standardising OPSEC practice across the CTI team.
  • Conducted AI security research into asset discovery, exposure monitoring, fingerprinting and secret-leakage detection.
  • Redesigned ASM reporting into separate executive and technical tracks, and contributed to the DRP product roadmap.
2023
  • Built the money mule and scam intelligence system: 156,413 UPI IDs mapped to 598 fraud websites, plus 224,978 VPA records and 212,226 phone records, structured for referral to I4C and NPCI.
  • Led OSINT, HUMINT and social engineering investigations across crypto scams, lottery and gambling schemes and mule networks.
  • Monitored 20+ underground forums and Telegram channels, mapping TTPs to MITRE ATT&CK and producing 80+ intelligence reports.
  • Detected phishing sites, cloned APKs and impersonation campaigns, including 2,000+ SEO-poisoned .gov.in pages and 10,000+ fraudulent customer-care numbers on YouTube.
  • Conducted threat actor engagements under OPSEC procedure to verify data leaks and establish modus operandi.
  • Supported law enforcement and regulatory investigations into financial fraud, terrorist funding and extremist networks.
Ongoing
  • Dark web research and on-chain analysis. Independently tracked illicit dark web services and criminal infrastructure, including carding platforms and cloned-card marketplaces. Clustered sites by hosting and template similarity to attribute shared operators, and traced cryptocurrency flows back to identified actors.
  • Hacktivist and disinformation network tracking. Collaborated with fellow OSINT researchers to track coordinated hacktivist collectives and disinformation campaigns across Telegram and social platforms during a period of regional geopolitical conflict, profiling propaganda dissemination channels and cross-platform attack infrastructure.
  • Cybercrime complaint and case management platform. Designed and deployed a WhatsApp-based complaint intake and case-tracking system for a local cybercrime response unit, cutting manual complaint-handling workload by an estimated 75% while improving triage and response times.

Published

Research

4 research reports  ·  19 articles

Threat intelligence research published under the Redhunt Labs byline, plus security writing on Medium. Authorship is stated on each piece.

Company research

Blog & articles on Medium

Everything above is public. Read more on Medium.

Projects

6 shipped  ·  14 stars

Public tooling and reference material for threat intelligence work.

Cryptic Grove

★ 11

TypeScript · SCSS · Docker

A public cyber security knowledge base: study notes and reference material for threat intelligence and security work, published openly. The most-starred thing I maintain, and the one other people actually found useful.

ReconEye

Python · Selenium · Celery · MongoDB · Docker

An external attack surface management system: distributed collection workers discover and track an organisation's internet-facing assets, queue enrichment through Celery, and persist findings for exposure monitoring over time.

TeleScribe dashboard showing Telegram channel analysis

Telescribe

Python · FastAPI · React/TypeScript · Vite

Builds an OSINT relationship map between Telegram channels by extracting the t.me links shared in a channel's messages, on the premise that a channel linking to another signals a real connection.

  • AI-classifies messages for threat relevance and generates channel summaries
  • Surfaces IOCs (domains, IPs, file hashes) for fast source triage
  • FastAPI backend; React dashboard with Details, AI Overview, Network and IOC views
Forums Bank searchable repository of cybercrime forums

Forums Bank

OSINT · Curated source repository

A curated, searchable repository of cybercrime forums, marketplaces, leak sites and underground communities for faster threat research. I contributed multiple dark web forums to its source list, expanding coverage across underground communities.

Also built, outside security

Zenblock browser extension landing page

Zenblock

Firefox & Chrome extension

A distraction-blocking browser extension: site blocking, daily time limits and scheduled access controls, with category filtering, focus mode, customisable block pages and usage tracking.

Linux Rice Catalogue gallery of desktop customisations

Linux Rice Catalogue

★ 3

JavaScript · Python

A community platform for discovering and sharing Linux desktop customisations across distributions, themes and window managers, with search, submissions, screenshot galleries and authentication.

Skills skill.md

21 capabilities  ·  17 linked to evidence

Grouped the same way the work is: investigation at the core, then what makes it repeatable, the standards around it, and where it meets the business. Every entry links to the evidence for it.

Tools and platforms

Collection & enrichment

Shodan · Censys · FOFA · SecurityTrails · DNSlytics · PublicWWW · VirusTotal · URLScan.io · urlquery · PhishTank · OpenPhish · PhishStats · StalkPhish · phishing_catcher · certstream · dnstwist · Maltego

Dark web & CTI platforms

StealthMole (Darkweb Tracker, Telegram Tracker, Compromised Data Set, Deface) · Ahmia · Kilos · Recon · Phobos · Ransomlook · Ransomfeed

Engineering

Python · Go · FastAPI · React/TypeScript · MongoDB · Elasticsearch · Celery · Selenium · Docker · Terraform · AWS · ZMap · zgrab2

Supporting

Meta Ads Library · Google Ads Transparency · Wayback Machine · archive.is · Burp Suite · Wireshark · Gemini API

Credentials

Education

B.Tech, Computer Science and Business Systems
Sri Eshwar College of Engineering · 2021–2025 · CGPA 8.61

Organised cybersecurity seminars, workshops and CTF events; competed with team NandBytes.

Writing & recognition

  • Medium: OSINT investigations, HackTheBox write-ups, CVEs
  • Co-authored the Payment Gateway Security Handbook
  • Smart Hack Challenge winner, 2022
  • Rajya Puraskar Award, 2019

Common questions

Answered directly

Who is Hariharan M?

Hariharan M is a Cyber Threat Intelligence professional based in India, specialising in financial cybercrime intelligence, OSINT and HUMINT investigation, dark web research, Digital Risk Protection and intelligence engineering. He has worked at Redhunt Labs as Cyber Threat Intelligence Researcher and at Saptang Labs as a Cyber Threat Intelligence Analyst, building the collection systems behind his own investigations.

What does Hariharan M specialise in?

He specialises in investigating the infrastructure behind cybercrime: money mule networks, phishing and typosquat estates, scam advertising, brand impersonation and dark web marketplaces. Alongside the investigation work he builds the collection, enrichment and detection systems that make that intelligence repeatable rather than manual.

What is Telescribe?

Telescribe is an open-source Telegram intelligence tool he built. It maps relationships between Telegram channels by extracting the t.me links shared in their messages, on the premise that a channel linking to another signals a real connection. It also classifies messages for threat relevance and extracts indicators for analyst triage.

How does phishing detection using Certificate Transparency work?

Every publicly trusted TLS certificate is logged to Certificate Transparency. Monitoring those logs surfaces newly issued certificates for look-alike domains within minutes of registration. Combining that stream with typosquatting analysis and domain intelligence, then enriching through VirusTotal and URLScan.io, turns manual domain hunting into scored, explainable takedown decisions.

What is internet-scale attack surface scanning?

It is surveying the whole public IPv4 space rather than a client's known assets. ZMap performs stateless host discovery at network speed, zgrab2 completes application-layer handshakes to collect banners and certificates, and the results are indexed for analysis. The point is finding exposure an organisation does not know it owns.

What threat intelligence tools does Hariharan M use?

Shodan, Censys, VirusTotal, URLScan.io, SecurityTrails, FOFA and Maltego for collection and enrichment; ZMap and zgrab2 for internet-scale reconnaissance; Python, FastAPI, Celery, MongoDB, Elasticsearch, Docker, Terraform and AWS for the pipelines and infrastructure behind them.

Disciplines

  • Cyber Threat Intelligence
  • OSINT
  • HUMINT
  • Dark Web Intelligence
  • Attack Surface Management
  • Brand Protection
  • Takedown Intelligence
  • Digital Risk Protection
  • Threat Actor Intelligence
  • Financial Cybercrime
  • Phishing Detection
  • Money Mule Networks
  • Infrastructure Attribution
  • Technical Pre-Sales
  • Product Specification
  • Security R&D
  • MITRE ATT&CK
  • On-Chain Analysis
  • Telegram Intelligence
  • Certificate Transparency
  • Intelligence Automation
  • Exposure Monitoring

Have an intelligence problem worth investigating?

Remote  ·  India

I am interested in Cyber Threat Intelligence, threat research, Digital Risk Protection and cybercrime intelligence roles where investigation and engineering intersect.