Daniel López

Cyber Threat Researcher

About Me

I am a Cyber Threat Researcher with a background spanning identity threat research, phishing investigations, incident response, threat hunting and security operations. Since 2017, I have helped international organizations in a wide range of sectors investigate, contain and remediate threats across diverse environments.

I also build open security tools. I enjoy turning noisy data into practical intelligence with AI, cloud services and APIs.

Projects

TweetFeed

tweetfeed.live

An open feed of indicators shared by the security community

TweetFeed collects and organizes indicators of compromise posted on X. It focuses on URLs, domains, IP addresses and file hashes, and publishes them as an open feed.

phishunt

phishunt.io

Suspicious phishing sites, captured and enriched

phishunt identifies and monitors suspicious phishing sites. It captures them, enriches them with hosting, certificate and network context, and publishes the results as an open feed.

Experience

Okta

Cyber Threat Researcher

Jun. 2024 - Present

okta.com

Part of Okta’s Identity Threat Research team, researching identity-focused threats and attacker tactics, techniques and procedures.

A few pieces of research published on the Okta Threat Intelligence blog:

Cloud Software Group

Sr. Security Engineer

Oct. 2020 - Jun. 2024

cloud.com

Worked in Cloud Software Group’s global Security Operations Center, handling 24/7 incident response, threat hunting and detection tuning.

Key Responsibilities:

  • Analyzed, contained and remediated malware, malicious email campaigns, fraud and abuse, insider threats and data-loss incidents
  • Hunted threats and researched malware and phishing campaigns, translating findings into concrete mitigations
  • Partnered with SIEM and Detection Engineering to tune alerts, reduce noise and improve detection performance

Banco Santander

Global SOC Security Analyst

Aug. 2018 - Oct. 2020

bancosantander.es

Worked in Banco Santander’s Global SOC, providing 24/7 monitoring and an on-call service to the bank’s entities worldwide.

Key Responsibilities:

  • Performed in-depth investigation and mitigation of security incidents
  • Monitored web traffic and critical SWIFT assets, investigating malware, phishing, DDoS and brute-force activity
  • Supported fraud prevention across phishing, suspicious email, compromised cards, mule accounts, data leaks and impersonation

Deloitte

CyberSOC Security Analyst

Aug. 2017 - Aug. 2018

deloitte.com

Worked in Deloitte’s CyberSOC, delivering managed security services for national and international clients.

Key Responsibilities:

  • Conducted initial triage of SIEM alerts to identify potential threats
  • Applied playbooks and immediate containment or remediation measures when required
  • Escalated potential incidents with the context and evidence needed for further investigation

Education

Universidad de Sevilla

Master's Degree in Telecommunications Engineering

2015 - 2019

Advanced study of telecommunications networks and systems, including network architecture, signal processing, wireless communications and network security.

Universidad de Sevilla

Bachelor's Degree in Telecommunications Engineering

2011 - 2015

Foundations in telecommunications engineering, computer science and software development.

Certifications and Courses

  • GIAC Security Essentials (GSEC) / SANS SEC401 [badge]
  • MITRE ATT&CK Defender™ - Fundamentals Badge Training [badge]
  • MITRE ATT&CK Defender™ - Cyber Threat Intelligence Certification Training [badge]
  • MITRE ATT&CK Defender™ - SOC Assessments Certification Training [badge]
  • Security Engineering on AWS
  • Architecting on AWS - Accelerator
  • ITIL Foundation [badge]

In the News

  • Telenotícies migdia [TV3 - midday TV news (~32:15)]
  • Telenotícies migdia [TV3 - midday TV news (~27:48)]
  • Se ofrece ciberataque gratis en Telegram: el nuevo anzuelo de los robos ‘online’ [elconfidencial.com]
  • Siguen las campañas de phishing suplantando a la Agencia Tributaria, ahora también por SMS [ESET blog]
  • Están suplantando la web de Correos con kits vendidos en Telegram que usan sus bots para recopilar contraseñas. Y hay muchos kits así [genbeta.com]
  • Así pueden estafarte con la declaración de la Renta [elcorreo.com]
  • Telegram abre paso a la venta de kits para suplantar webs como la de Correos a través de bots [mundodeportivo.com]
  • phishunt.io, cazando phishings [derechodelared.com]
  • Suplantan la identidad de tenistas como Rafa Nadal para incentivar la descarga de vídeos con malware [20minutos.es]
  • El ciberataque vía Youtube que ha suplantado a Nadal o a Djokovic durante Wimbledon [escudodigital.com]
  • Continúan los SMS con falsos envíos de FedEx: cómo identificarlos y eliminar esta amenaza [ESET blog]
  • FedexBanker: El nuevo troyano bancario para Android que utiliza tus paquetes para robarte las credenciales [hispasec.com]
  • Los timos con criptomonedas que usan imágenes de famosos continúan muy activos [ESET blog]
  • How does a modded crypto wallet steal credentials of an user? [@themalwarebug - medium.com]
  • Aplicación maliciosa para Android se hace pasar por una versión de la cartera de criptomonedas MetaMask [ESET blog]
  • Best Cyber Threat Intelligence Feeds [silentpush.com]

A Little More About Me