Back to @MsftSecIntel's profile

Microsoft Threat Intelligence engagement report

@MsftSecIntel - 198K followers on X

Measured over 13 original posts from a 30-day window, last computed on September 15, 2026.

Engagement

Middle of its size range
Per follower
0.078%
of 198K followers
Per impression
0.904%
17K views on a typical post
Reach
8.63%
of its followers see a post
Typical post
154
interactions (median)
Saved
0.288%
49 bookmarks on a typical post
Posting rate
0.5/day
active 40% of days
Peak time
17:00 UTC
Wednesday

A typical post picks up 154 interactions against 198K followers, an engagement rate of 0.078%. Measured over 13 original posts, its engagement rate beats 52% of 15,519 tracked accounts of a similar size, which puts it in the middle of its size range rather than at either end. Posts are seen about 17K times each, and 0.904% of those impressions turn into an interaction. That is about 8.61% of the follower count, which is the gap between an audience on paper and an audience in a timeline. Posting runs at about 0.5 post a day over the last 30 days, though only 40% of days saw any activity at all. Most posts go out around 17:00 UTC, and Wednesday is the busiest day of the week. Of the 13 posts sampled, 38% carry an image or video and 85% link out. The account's strongest tracked post pulled 1.5K interactions, about 9.6x its own typical post.

Measured over 13 original posts from a 30-day window, last computed on September 15, 2026.

Compared with accounts its own size

Microsoft Threat Intelligence's engagement rate beats 52% of the tracked X accounts closest to it in follower count (15,519 accounts, accounts of similar size (decile 8 of 10)). A percentile is spread evenly by construction, so 50 really is the middle of that group and 90 really is its top tenth.

On engagement per impression rather than per follower it beats 41% of the same group. When those two numbers disagree, the gap is about how far its posts travel rather than how people react to them.

Where this sits in the catalog

At 0.078%, Microsoft Threat Intelligence sits above the 25th percentile of the 157,374 accounts in this comparison. That places it in the below the median band, which runs 0.022% to 0.128%.

p100.003%
p250.022%
p50 (median)0.128%
p750.604%
p902.32%
p9983.4%
Engagement rate as a share of followers, across the 157,374 accounts we have scanned enough to measure. The axis is logarithmic, because the top and bottom of this population are about 26,055 times apart and a linear axis would flatten everything below the median into a single point.
Show the percentile table
Engagement rate percentiles
PercentileEngagement rate
10th percentile0.003%
25th percentile0.022%
50th percentile0.128%
75th percentile0.604%
90th percentile2.32%
99th percentile83.4%

This ruler is the whole measured catalog, not a size-matched group: it shows where the raw rate falls across every account we can measure, all of which are large. For a like-for-like comparison, read the size-band percentile above instead. See how the bands are built

Posting timing

This account posts most often around 17:00 UTC, and Wednesday is its busiest day of the week. The bars below are the catalog-wide pattern, with this account's own busiest slot marked. They do not show how this account performs at each hour: we keep one aggregate per account, not one per hour, so that measurement does not exist in our data.

Engagement by hour posted, UTCTwenty-four bars, one per UTC hour. Each bar shows how posts published in that hour compare with their own authors' median engagement. Bars above the centre line ran higher than the median, bars below ran lower. A marker flags Busiest hour: 17:00 UTC.
0003060912151821
Above the authors' own mediansBelowScale: plus or minus 111%Busiest hour: 17:00 UTC
Show engagement by hour posted, utc as a table
Engagement by hour posted, UTC
Hour (UTC)Vs author medianPosts
00:00 UTC-1%89K
01:00 UTC-2%90K
02:00 UTC-3%88K
03:00 UTC-4%94K
04:00 UTC-5%76K
05:00 UTC-4%75K
06:00 UTC-5%86K
07:00 UTC-5%93K
08:00 UTC-4%108K
09:00 UTC-4%124K
10:00 UTC-3%129K
11:00 UTC-3%141K
12:00 UTC-3%154K
13:00 UTC-3%167K
14:00 UTC-4%173K
15:00 UTC-2%176K
16:00 UTC-3%171K
17:00 UTC-3%159K
18:00 UTC-2%149K
19:00 UTC-2%141K
20:00 UTC-1%131K
21:00 UTC0%116K
22:00 UTC-2%100K
23:00 UTC-1%90K
Engagement by day of weekSeven bars, one per weekday, Sunday first. Each bar shows how posts published on that day compare with their own authors' median engagement. Bars above the centre line ran higher than the median, bars below ran lower. A marker flags Busiest day: Wednesday.
SunMonTueWedThuFriSat
Above the authors' own mediansBelowScale: plus or minus 111%Busiest day: Wednesday
Show engagement by day of week as a table
Engagement by day of week
DayVs author medianPosts
Sunday+5%393K
Monday+1%483K
Tuesday-2%520K
Wednesday-3%472K
Thursday-2%430K
Friday-3%447K
Saturday+2%393K
See what moves engagement across the whole catalogWhat counts as a good engagement rate at this size

Formats this account uses

Its own posting mix on the left, and what each of those formats does across every account we track on the right. Only formats where the effect clears our publish test appear here, so an empty row is a format we could not measure rather than one that does nothing.

This account's posting mix compared with catalog-wide effects
FormatThis accountCatalog effect95% intervalAccounts behind it
Image or video38% of posts+111%+108% to +115%34K
Outbound link85% of posts-41%-42% to -40%32K
Typical length-+15%+14% to +16%32K
  • 38% of this account's sampled posts carry an image or video. Across the catalog, posts with an image or video run 111% above the same accounts' other posts.
  • 85% of its posts carry a link off X. Across the catalog, posts with an outbound link run 41% below the same accounts' other posts, so a large share of this account's output sits in the weakest bucket we measure.
  • Its average post runs 937 characters, which falls in the over 280 characters band. Across the catalog, posts over 280 characters run 15% above the same accounts' other posts.

These are catalog-wide differences applied to this account's own posting mix, not a measurement of how each format performs for this account specifically. We keep one median per account, not one per format per account, so the second thing is not something this data can tell you.

Best tweets

  • Aug 4, 20269.6x their median

    Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware. Compromised packages (confirmed malicious) include: - [email protected] - [email protected] - [email protected] - [email protected] - qlik/[email protected] - cacheable/memory, /utils, /net - 17+ servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.) In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js. The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases. Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens. Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”

    1.1K24044461.3M viewsView on X
  • Aug 7, 20262.3x their median

    On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor. Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use. StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory. While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026. Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption. https://t.co/9M5JmnGWWL In this new activity, Storm-1175’s post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz. This threat actor is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days. Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible. Microsoft Defender Antivirus detects StormEncryptor (SHA-256: c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054) as Ransom:Win64/StormEncryptor. Microsoft Defender for Endpoint detects this activity through multiple alerts, including “Hands-on-keyboard attack involving multiple devices” and “Potential human-operated malicious activity”.

    281616728K viewsView on X
  • Aug 19, 20261.7x their median

    Microsoft Defender is monitoring the active exploitation of the CVE-2026-65400 improper authentication vulnerability on a limited number of macOS devices, with telemetry showing successful root account network sign-ins through Screen Sharing. Microsoft urges customers to immediately apply security updates and to investigate related Microsoft Defender alerts and detections. After gaining access, the attackers transferred files (scripts and a Secure Shell (SSH) public key) to the devices through Screen Sharing, established SSH persistence, removed histories and logs, modified Packet Filter settings, and deployed the cryptocurrency miner XMRig 6.26.0. They copied and ad-hoc signed XMRig as a hidden .config/sysmond binary, masqueraded it as com[.]apple[.]airportd, and persisted it with a KeepAlive LaunchDaemon. Indicators of compromise (IOCs): - SHA-256: 84006055916e267f7c2f9324f1848563e589e4526a296d4e9e9ce8e2112d357c (customized XMRig binary produced on multiple affected devices after the stock miner binary was copied, renamed to sysmond, and ad-hoc signed) - /private/var/root/.config/sysmond (hidden path used for the customized miner) - /Library/LaunchDaemons/com.xmr.miner.plist (malicious RunAtLoad and KeepAlive persistence) - exec -a com[.]apple[.]airportd (command-line masquerading used to present the miner as an Apple process) - 4AUZ9XNsffcPn13Yjk5yWAaZg8x5Fgu9cL9kWwDCnmACUFLuwrLg41WU31qiKfmo9ee62mVbwG9F5G82Ko8vck8nCtxdicj (Monero wallet reused across the observed deployments) - auto[.]c3pool[.]org:443 (mining-pool endpoint used by the miner; treat as contextual because mining pools may also receive legitimate traffic) The stock XMRig binary and its legitimate GitHub release URL should not be treated as malicious without the surrounding adversary technique context. Microsoft Defender alerts and detections: - 'CoinMiner' malware was prevented (Investigate retained SSH access, hidden miner copies, and com.xmr.miner.plist, even when quarantine succeeds) - Suspicious file or content ingress (Inspect the responsible process, destination, signing state, and nearby persistence) - Suspicious connection to remote service (Investigate unexpected root SSH sessions and sshd-session -i -R) When hunting, higher-confidence signals combine root-level Screen Sharing file transfer activity through SSFileCopyReceiver with writes to privileged .ssh, /private/etc, hidden /private/var/tmp, or LaunchDaemon paths. Microsoft recommends updating macOS to at least Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9; disabling unnecessary Screen Sharing; blocking untrusted TCP/5900 access; inspecting SSH keys and LaunchDaemons; removing unauthorized persistence; and rotating affected credentials.

    184636544K viewsView on X
  • Jul 28, 20261.5x their median

    Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS). An authenticated, low-privileged attacker with network access could manipulate certificate enrollment to impersonate a Domain Controller, potentially enabling privileged operations and full domain compromise. Exploitation requires no administrative privileges or user interaction, but does require network access and a valid domain account. The publication of proof-of-concept code increases the likelihood of exploitation attempts, so we recommend customers prioritize installing the July 2026 security update as soon as possible. Microsoft has observed researcher testing activity but has not confirmed active exploitation by threat actors. In response to these early signs of activity, we are sharing detection and hunting guidance to help defenders identify potential exploitation attempts, particularly in environments where the security update has not yet been applied. Microsoft Defender detects malicious certificate requests associated with this vulnerability and generates the alert: - “Potential Certighost (CVE-2026-54121) AD CS abuse.” - "Active Directory Certificate Services attack tool activity " Other alerts, including the following, may also appear during the attack chain. These signals support investigation but are not independently specific to Certighost. - Security principal reconnaissance (LDAP) - Suspicious Active Directory Certificate Services abuse tool activity - Suspected suspicious Kerberos ticket request - DCSync attack (replication of directory services) Customers should apply the July 14, 2026 security update to every server running an Enterprise Certification Authority (CA). The security update provides the primary protection by validating the enrollment chase target before the CA contacts it, preventing invalid or attacker-controlled systems from influencing certificate issuance. Customers who can't apply the July 14, 2026 security update immediately for all affected servers, should consider configuring the following audit logs to enable the mentioned detections and forensic: - Enable Certification Services auditing for both successful and failed operations. - Configure the CA audit filter to capture certificate lifecycle activity. - Monitor Security events 4886 and 4887 for anomalous certificate requests and issuance. - Investigate certificates requested through machine templates that contain unexpected Domain Controller identity information.

    187442227K viewsView on X
  • Jun 17, 20261.5x their median

    Microsoft has identified a supply chain attack on the Mastra-AI npm ecosystem, with 80+ packages compromised through npm account takeover. The attacker introduced a phantom dependency into the compromised packages. The malicious dependency was published by a single anonymous maintainer less than 24 hours ago. The compromised [email protected] adds the dependency easy-day-js@^1.11.21 (typosquat of "dayjs"), which resolves to v1.11.22. The post-install script runs node setup.cjs, which downloads and executes a remote payload. The post-install script in [email protected]: 1. Bypasses TLS: Disables SSL verification (NODE_TLS_REJECT_UNAUTHORIZED=0) to communicate with attacker C2 without certificate errors 2. Writes tracking files: Creates ~/.pkg_history (infected machine path) and ~/.pkg_logs (XOR-encoded marker) to prevent re-infection 3. Downloads hidden payload: Fetches second-stage .js from 23[.]254[.]164[.]92:8000/update/49890878 4. Executes as invisible process: Spawns downloaded payload with C2 endpoint 23[.]254[.]164[.]123:443 passed as argument, runs detached and hidden (windowsHide=true) 5. Covers tracks: Deletes setup.cjs to remove all evidence of initial infection This attack affects [email protected], mastra/pg, mastra/mcp, mastra/schema-compat, mastra/ai-sdk, mastra/rag, and 80+ other packages. Microsoft Defender for Endpoint customers should monitor and act on alerts with Trojan:JS/ObfusNpmJs in the title. Customers can also check for the following IOCs: - ls ~/.pkg_history ~/.pkg_logs - random .js files in home/temp directory Users are advised to downgrade to previous versions immediately, use [email protected] explicitly, and use lockfiles.

    165451312115K viewsView on X
  • Sep 2, 2026

    Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel & abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution & C2. https://t.co/DXLX2CVukP After establishing access, the attackers use trusted tooling to perform reconnaissance, capture screenshots, execute follow-on payloads, and move laterally toward domain controllers, certificate authorities, and other high-value systems. Organizations should restrict Teams external access to trusted domains, reinforce user education, and harden systems against social engineering. Read the blog for analysis, Microsoft Defender coverage, indicators, hunting queries, and mitigation guidance.

    161583622K viewsView on X
  • Sep 9, 2026

    Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins are followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, and cloud data access. https://t.co/TdVviAPxQH The activity begins with identity-focused social engineering, progresses through authentication persistence and cloud reconnaissance, and is followed by targeted data access consistent with data collection and potential exfiltration. Microsoft Threat Intelligence assesses that the initial access activity observed in this campaign is used by multiple threat actors, including Storm-3121, Storm-3032, and others. Defenders should focus on the behavioral sequence rather than individual indicators. Monitor for unusual sign-ins, authentication method changes, Microsoft Graph reconnaissance, and abnormal cloud data access. Read the research for detections and hunting guidance.

    174472218K viewsView on X
  • Aug 28, 2026

    Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host. This TerminalFix campaign uses fake CAPTCHA verification prompts to facilitate user-executed PowerShell commands. Beyond the initial lure, this campaign uses DLL sideloading through LockScreenContentServer.exe, steganographic payload delivery, and persistence mechanisms. It then performs extensive reconnaissance to identify reachable systems and key infrastructure. Organizations should investigate devices where users interacted with suspicious CAPTCHA verification prompts and look for unusual execution of LockScreenContentServer.exe, hidden ProgramData folders, and outbound connections associated with the activity. Additional guidance and technical analysis will be published soon by Microsoft Security Research.

    164523319K viewsView on X
  • Sep 3, 2026

    Microsoft Security Researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt injection research as ASCII smuggling, to obscure financial lure words before email filters parsed them. https://t.co/RWGnm8a50r Microsoft telemetry linked the technique to a large-scale finance-themed phishing operation that persisted for months, using hundreds of rotating sender domains and consistent infrastructure patterns. The research shows how techniques popularized in AI security research can quickly cross into traditional phishing campaigns as threat actors adapt tradecraft across domains. Learn how to identify this activity and strengthen detection against similar tradecraft.

    161379520K viewsView on X
  • Aug 26, 2026

    The ransomware attack dubbed “JADEPUFFER”, one of the first documented cases of a threat actor using large language model (LLM) to conduct an end-to-end attack, offers a glimpse into how AI could shape future ransomware campaigns. https://t.co/FX87ickKFt While the attack relied on familiar techniques, it demonstrated how AI can rapidly iterate, adapt to failures, and continue progressing toward an objective. In this episode of the Microsoft Threat Intelligence Podcast, Elliot Volkman speaks with Michael Clark and Crystal Morin of Sysdig about the AI-driven activity, including its ability to generate and modify code, reason through errors, and work through technical obstacles that might slow a human operator. Despite its use of AI, JADEPUFFER relied on familiar weaknesses, including exposed services, unpatched vulnerabilities, and poor credential hygiene, highlighting the continued importance of exposure management and foundational security practices.

    126333417K viewsView on X

Ranked by total interactions across everything we have tracked for this account, which is a longer history than the 30-day window the rates above use. The multiple compares each post to this account's own median.

Buy or sell Twitter (X) accounts - escrow-protected

PlayerSells is an escrow marketplace for Twitter (X) accounts. Every deal is protected, with no middleman risk.

Reading these numbers

A typical post picks up 154 interactions against 198K followers, an engagement rate of 0.078%. Measured over 13 original posts, its engagement rate beats 52% of 15,519 tracked accounts of a similar size, which puts it in the middle of its size range rather than at either end. Posts are seen about 17K times each, and 0.904% of those impressions turn into an interaction. That is about 8.61% of the follower count, which is the gap between an audience on paper and an audience in a timeline. Posting runs at about 0.5 post a day over the last 30 days, though only 40% of days saw any activity at all. Most posts go out around 17:00 UTC, and Wednesday is the busiest day of the week. Of the 13 posts sampled, 38% carry an image or video and 85% link out. The account's strongest tracked post pulled 1.5K interactions, about 9.6x its own typical post.

What is Microsoft Threat Intelligence's engagement rate on X?
Microsoft Threat Intelligence (@MsftSecIntel) has an engagement rate of 0.078%, based on the median interactions across 13 original posts from the last 30 days against 197,846 followers. Replies, reposts and quote-posts of other people are excluded from that sample.
Is that a good engagement rate?
At 0.078%, Microsoft Threat Intelligence sits above the 25th percentile of the 157,374 accounts in this comparison. Those comparison accounts are all large ones, because our scanning cadence is weighted towards big accounts, so this is a ranking among peers of similar scale rather than a ranking across X.
Does @MsftSecIntel have real engagement?
Its engagement rate beats 52% of the tracked X accounts closest to it in follower count (15,519 accounts), which puts it in the middle of its size range group. Ranking inside a size band matters because engagement rate falls as accounts grow, so a raw rate would mostly re-measure the follower count. It is a starting point for a look at follower quality, not a verdict on it.
When does @MsftSecIntel post?
Most posts go out around 17:00 UTC, and Wednesday is its busiest day, at roughly 0.5 posts per day across the measured window.

Keep going