"Every lie we tell incurs a debt to the truth. Sooner or later that debt is paid."
This salient line from the brilliant Chernobyl series has been occupying my thoughts since hearing it. It is worth pondering.
I'm excited to get my latest blog post about purple team efficacy out into the wild! You may feel like the point I'm making is obvious, but I'd argue that a lot of concepts seem obvious only when you're faced with an argument on it's behalf.
https://t.co/JvH82OW6Kj
Last night, @jaredcatkinson and @jsecurity101 dove into Windows API functions and how they can be used and potentially abused by attackers - the final result was using a series of functions to impersonate the SYSTEM token. The full session is available on https://t.co/N4KxCBoUhq!
@curi0usJack For home assistant, it currently is causing more problems than solutions in the community help forums and they have implemented a rule not to use it if you don’t already have the knowledge. https://t.co/TgIbHjULzp
Starting today, ChatGPT and AI systems are no longer welcome as tools to write answers when helping people in the Home Assistant community. Intentions are good, the results are not.
More info 👇
https://t.co/zBTyqjA1r3
I've always thought that in order for Defenders to be truly effective, it is vital they know where the telemetry they are leveraging is coming from.
Today I am releasing a project called TelemetrySource that is meant to support that cause.
Blog: https://t.co/jYPB40q3EF
@jsecurity101 and I have started a blogpost series providing a defensive knowledgeable for commonly attacked technologies - we started with the Windows Registry which was released today - check it out over at the @SpecterOps Medium! https://t.co/5JLCRob3vg
1/ In the upcoming episode of @dcpthepodcast; @jsecurity101, @v3r5ace, and I sit down to discuss the axiomatic system that I apply to the Detection and Response process. Feedback and criticism welcome and we will go into each axiom in more depth on Monday's episode! 🧵
We're one week away from our next Adversary Tactics: Red Team Operations training! Be sure to register this week if you're planning to attend.
https://t.co/SvEhGgI3Yn
Our Targeted Operations team recently looked to improve their knowledge management strategy. @L1NKD34D provides a behind-the-scenes look at how Obsidian has been customized and evaluated as a solution. Bonus! It's available to as an open-source resource.
https://t.co/uHiIhxU2Fq
Determining which attack path holds the most criticality is essential to successful entity-based detection engineering.
Check out my post on utilizing BloodHound Enterprise for alert prioritization and detection control.
https://t.co/hPV5Jd0E3I
We've got new content on the blog this week!
Check out the latest posts from @jaredcatkinson and @djhohnstein. Jared shows us the importance of identification in detection engineering, and Dwight dives into 1Password secret retrieval.
Read more here:
https://t.co/2VLBT3v1Zn
Check out my new blog post about the importance on IDENTIFYING the events that are relevant to your detection engineering efforts. This is a critical portion of the process that is often overlooked. https://t.co/KTwlPZtUyv
Episode 10 is LIVE! We wrap the season with @jaredcatkinson and @jsecurity101 recapping their favorite discussions and topics from Season 1. https://t.co/CfO0cRSpGS