

Threat Research
About Netskope Threat Labs
A team of security researchers tracking, reverse-engineering, and reporting on AI-enabled attacks, cloud-enabled attacks, web threats, and malware.
Netskope Threat Labs is a team of security researchers who track, reverse-engineer, and report on the threats that matter most to enterprise organizations, from malware and ransomware to the abuse of everyday cloud and AI services.
We work alongside engineers, data scientists, and security practitioners from across Netskope who regularly contribute research, analysis, and detection engineering to our reports and blog posts.
Our researchers track malware campaigns, phishing and social-engineering techniques, ransomware groups, and the rapid growth of generative and agentic AI, publishing findings to help defenders detect and respond to threats faster.
Our research is based on anonymized telemetry from the Netskope One platform, which processes tens of billions of events daily across thousands of enterprise customers worldwide.
What we research
- Malware delivery, execution, and reverse engineering
- Phishing, credential theft, and social engineering
- Ransomware groups, extortion tactics, and infrastructure
- Abuse of legitimate cloud apps for delivery and command-and-control
- Generative AI, shadow AI, and agentic AI risk
- Supply chain and open-source ecosystem compromise
The Team
Meet the people behind our research — a core Threat Labs team working alongside collaborators from across Netskope.
Past Conferences
Conferences and security events where our researchers have presented original research.






BlackHat USA 2025: Your Traffic Doesn't Lie: Unmasking Supply Chain Attacks via Application Behaviour
Colin Estep, Dagmawi Mulugeta











