A bunch of nerds: Your code needs to be memory safe to move the industry forward
Every CVE in 2024: if you add a funny character to this URL parameter you can execute commands as root
@domchell @sardaukar_77 @anthemtotheego@Jhaddix@HackingLZ Exactly this ^
TI reports are often against tiny orgs or massive lumbering orgs with crappy EDR and politics. RT is often in the echo chamber in the middle :)
@HackingLZ Most red team people have no clue on how to build enterprise cyber resiliency at scale.
They believe bypassing EDR is the be all and end all. It's an enabling action.
Most clients treat RT as point in time activities rather than 'how _could_ this play out'.
I'm going to release a realistic red teaming course where we just read Confluence, wikis, shares, and git repos all day and write reports for several hours at the end.
Scaling detection and response operations at Coinbase part 2 & 3:
🔍 Driving context into detection logic with machine and user profiles
🔧 Codifying automatic remediation for high-risk detections
📫 Automating alert triage with employees via Slackbot
https://t.co/vEUEWvZ6K4
I’ve just publicly released SQLRecon v3.3. This release includes many features that were used privately by the @xforcered Adversary Services team on real-world red team operations. Please share, enjoy, and use responsibility. Hmu if you have any questions! https://t.co/lACpTXx94o
Introducing ETWHash!
ETWHash is a new method and tool by @lefterispan for consuming SMB events from Event Tracing for Windows (ETW) and extracting NetNTLMv2 hashes for cracking offline.
https://t.co/wLmsQf71J8