Had a blast working with my buddy @max__grim creating this badge! Thanks to @OutflankNL and @MDSecLabs for the conf. It was a blast again ❤️ Looking forward to the next one!
Who’s the real #GrimResource? Spoiler: It’s us! 😏
Here's our latest blog on using MSC files for initial access: https://t.co/aQ0Of11pU8
Fun fact: @elastic’s post on this technique came from a sample caught by a blue team, originally used by a red team through our OST offering.
@gijs_h wrote a short #FalconFriday blog on detecting MMC abuse, based on the great blog from Elastic Research Lab on the #GrimResource technique. Today’s FalconFriday includes 3 custom detections that can be used in Microsoft Defender. Happy reading!
https://t.co/H05BLibflT
Attackers collect and analyze data from Active Directory to navigate their target environments. In this #FalconFriday we show you how to detect suspicious data collection attempts that are an indicator of an adversary in your environment. Happy hunting!
https://t.co/Sap8lYhfUx
Got a special serial number from a special person! Amazing glow in the dark coin 🤩 thank you brother, may we void many more warranties together! @jilles_com
1 year ago @max__grim and I built our first badge! This year we went full rocket engineer mode and design this beast for our OOO internal conf. This badge is based on a ESP32-S2 running CircuitPython7. You even can hook up more sensors on the launchpad 🚀🐮
I published a technical blog post about using Nim for offensive tooling, focusing on my Nimplant project. It includes many lessons learnt and tips & tricks. The blog setup is quite different than what I'm used to writing, so let me know if you like it!
https://t.co/QYhiUIB0pN