I wrote a high-level analysis on an ongoing phishing scam in Kenya targeting NTSA users. I think it's worth checking out and find out how to protect your data in case you fall victim. Stay vigilant!
https://t.co/JZWSddlX7E #NTSAKenya#phishing
I wrote a fun write-up on ADCS exploitation, including explanations and custom built examples of practical exploitation for all 13 ESC vulnerabilities. It's available on my blog: https://t.co/zZReyPgeMi
Hope this helps anyone who's interested in #activedirectory security :)
I just published Ransomware Network Analysis -BTLO. This is a walkthrough of the challenge from @BlueLabsOnline that tests your threat hunting skills and touches on a bit of static malware analysis.https://t.co/bsgxkmalpE
I just published an article on Threat Hunting and Threat Hunting Frameworks. This is an exciting topic and a very crucial aspect of cyber security. Check it out and let me know what you think. https://t.co/m8WYT7pBhF
Okay, I've created an "awesome repository" that lists all the GPTs related to cybersecurity. Take a look – the list is continuously growing and there are already many use cases! Feel free to add yours 👇#gpt#infosec#Agents
https://t.co/MqKmMlD4D0
Dear Cyber Security Wannabe, Here is How to Break into Cyber and Work from Home in 6 Months with a breakdown of hours.
There are very few fields like Cyber Security where you can create your own path to enter. These are the two most important things to do:
1. Gain Knowledge 📚
2. Get Hired 🤝
Let's talk about the first one, knowledge gain. No one cares how you gain the knowledge, but I'm going give you a push start. Here are steps on gaining knowledge.
✅ Learn how to analyze packets. You must understand what is inside a network packet for both offensive and defensive security. Learn how to determine the source, destination, and the information that's in it. A great start to this would be with a free tool called Wireshark.
✅ Learn how to discover. I typically would use another free tool such as Nmap to do recon. Learn about different operating systems and the ports and services that go with them as well as what they do. You should be able to simply look at what ports and services are open and make a determination of what type of system it is and what it is running.
✅ Learn what a vulnerability is and how to exploit it. Scanners such as OpenVas or Nessus will help you determine what vulnerabilities exist. Tools like Metasploit are used to exploit those vulnerabilities. Practice with test labs only. If you understand offense, you will better understand how to defend.
✅ Learn and understand how SIEM tools work. For example, learning Splunk will give you some hands on.
All of this above falls under KNOWLEDGE GAIN.
In parallel, NOT AFTER, you should be working toward a plan of Getting Hired. No, you aren't ready for a position as soon as you start your knowledge gain journey, but you should already be preparing. So how to do you prepare to get hired? You get your face out there. 😁
In order to get hired you must start preparing now. Do this by building your brand on LinkedIn. Show your enthusiasm. Share the knowledge you are gaining on your journey. Connect with others in the cyber community. Tweak your profile to all of the knowledge you are gaining. Engage with others in the community. This all falls under GETTING HIRED.
If you go hard at this for 6 months and do both of these things in parallel, you can change your career in 6 months or less. A suggestion would be:
3 Hours a Day
15 Hours a Week
60 Hours a Month
360 Total hours in 6 months
Dividing these into two categories would look like:
180 Hours into Knowledge Gain
180 Hours into Getting Hired.
If you do this, you may have recruiters lining up before you are even ready.
Want to Work with Me? There are Two Ways I can Help:
1. Want a Career in Cyber? Let's talk at ➡https://t.co/GcdJet8jHq⬅.
2. If you're already in Cyber but feel stuck, let's talk. ⬆
#cybersecurity #infosec #informationsecurity #security
Earlier this morning we spoke with Lockbit ransomware group administrative staff. We asked why there has been a significant decrease in victim postings and blog activity.
They informed us they're currently on holiday and enjoying the nice summer weather.
¯\_(ツ)_/¯
I just published Automating the Malware Analysis Process using Jupyter Notebooks https://t.co/tDN8hbjNh1 . Big shout out to @mttaggart and @HuskyHacksMK for the PMAT labs and introducing me to the tool