@lennyzeltser Your post reminded me of a past post I've written myself on the subject of communications skills, and what common obstacles I've encountered time & time again, which hampered the path to problem solving an IT problem.
https://t.co/RFmTDd6iVR
@khanofkhans11_ I swear - when he talked about royalty, I thought the camera would pan to Princess Di, and he'd say something like:
"Dirty Diana
It's Dia-aa-aa... come on!" ๐
Abusing Cortex XDR Live Terminal as a C2 - interesting post by #InfoGuardLabs. ๐
Turns out they could abuse the agent to send its reverse shell ("Live Terminal" feature) traffic to to an attacker server of their choosing (a Cortex XDR server tenant of their own, in this case).
@MalwareJake Sorry to learn you have PTSD and are triggered by the Epic Fury military operation.
I'm writing this while in a safe room with my family in Israel, with sirens going off every 12 min. A nation in a PTSD state ever since 10.7, and particularly by Iran. Coin got more than 2 sides..
@cpt_depression_@TheKiffness Was it a story about a massacre that took place during a music festival on October 7th? Where Jews and Muslims alike were murdered in cold blood?
How are apps still doing this? Companies: stop asking users to upload their address books. And everyone else: refuse to upload your address book to random apps and social media platforms.
The contacts in your phone are not your data. Itโs other peopleโs data.
@mikko@duolingo The annoying thing about all this, is that even if you are privacy-savvy and KNOW not to upload contact lists to these apps - they keep nudging you; until one day, you accidentally hit the wrong button - and *whoops!*... all you contacts get sucked out into the app. ๐ก ๐ฟ
Last quarter I rolled out Microsoft Copilot to 4,000 employees.
$30 per seat per month.
$1.4 million annually.
I called it "digital transformation."
The board loved that phrase.
They approved it in eleven minutes.
No one asked what it would actually do.
Including me.
I told everyone it would "10x productivity."
That's not a real number.
But it sounds like one.
HR asked how we'd measure the 10x.
I said we'd "leverage analytics dashboards."
They stopped asking.
Three months later I checked the usage reports.
47 people had opened it.
12 had used it more than once.
One of them was me.
I used it to summarize an email I could have read in 30 seconds.
It took 45 seconds.
Plus the time it took to fix the hallucinations.
But I called it a "pilot success."
Success means the pilot didn't visibly fail.
The CFO asked about ROI.
I showed him a graph.
The graph went up and to the right.
It measured "AI enablement."
I made that metric up.
He nodded approvingly.
We're "AI-enabled" now.
I don't know what that means.
But it's in our investor deck.
A senior developer asked why we didn't use Claude or ChatGPT.
I said we needed "enterprise-grade security."
He asked what that meant.
I said "compliance."
He asked which compliance.
I said "all of them."
He looked skeptical.
I scheduled him for a "career development conversation."
He stopped asking questions.
Microsoft sent a case study team.
They wanted to feature us as a success story.
I told them we "saved 40,000 hours."
I calculated that number by multiplying employees by a number I made up.
They didn't verify it.
They never do.
Now we're on Microsoft's website.
"Global enterprise achieves 40,000 hours of productivity gains with Copilot."
The CEO shared it on LinkedIn.
He got 3,000 likes.
He's never used Copilot.
None of the executives have.
We have an exemption.
"Strategic focus requires minimal digital distraction."
I wrote that policy.
The licenses renew next month.
I'm requesting an expansion.
5,000 more seats.
We haven't used the first 4,000.
But this time we'll "drive adoption."
Adoption means mandatory training.
Training means a 45-minute webinar no one watches.
But completion will be tracked.
Completion is a metric.
Metrics go in dashboards.
Dashboards go in board presentations.
Board presentations get me promoted.
I'll be SVP by Q3.
I still don't know what Copilot does.
But I know what it's for.
It's for showing we're "investing in AI."
Investment means spending.
Spending means commitment.
Commitment means we're serious about the future.
The future is whatever I say it is.
As long as the graph goes up and to the right.
One red herring that threw me off, was the fact that I managed to send a request and get a "Werkzeug Debugger" page, which included a "secret" key parameter; and I thought perhaps I needed to use it to get to the flag.
I did not.
Wondering if this was intentional, @edskoudis ?
The "Rogue Gnome" proved to be quite the challenge! Took me ~7 hours to figure out; much harder than 2 snowflakes. ๐ตโ๐ซ
But that sweet feeling when you finally find the flag... ๐คฉ
Plus, I learned a thing or two about Json Web Tokens and jwks. ๐ค
#HolidayHack#ctf@SANSInstitute
@Carlos_Perez Sounds like too many CISOs and CEO are drinking the AI Kool-Aid and believing the marketing hype, instead of understanding that what they *should* be doing is letting the blue-team *use* AI in an intelligent and efficient manner.
Hey there friends! Have you played #HolidayHack yet at https://t.co/ptqUf0VbVl? Itโs up and running, and weโd love for you to check it out. Itโs the fun, FREE SANS cyber range where youโll learn all kinds of useful skills: pen testing, post-quantum crypto, forensics, & more!
A Rust-based tool which creates a benign PE file (Windows EXE) that contains the patterns on which a chosen Yara rule alerts on. Strings and hex patterns are embedded (but cannot be executed) in the PE file, letting you run a sanity-check which will return a result.
Ever got 0 results in a Yara scan, but wondered if the scan ran correctly? Wouldn't it be good to find 1 result that shows that the rule is syntactically valid and the scanning tool works?
Meet "Guilty-As-Yara": an EICAR for Yara!
https://t.co/AZRPsek22u
#DFIR#Yara#BlueTeam
Cool new tool by @TwoSevenOneT !
Rushed to try it in my own org. To my happy dismay - the EDR caught its behavior and terminated the operation of running WerFaultSecure (when I tried to freeze the EDR or the AV).
As part of the #Blueteam- you must learn the #Redteam tactics. โบ๏ธ
Detailed analysis of the techniques used in the EDR-Freeze tool and how the #securityvulnerability of Windows Error Reporting is exploited to halt the operation of #antimalware#cybersecurity
https://t.co/48Ll9Ftzju