My SANS Purple Team Series: Threat-Informed Detection Engineering Webinar with @jorgeorchilles is on YouTube!
Video: https://t.co/m856BQGemj
Blog post: https://t.co/knrcyYDAQk
Pretty interesting: retrieves the command-and-control (C2) domain from a blockchain smart contract. Instead of hardcoding the server address... queries multiple Polygon RPC endpoints defined in CONTRACT_CONFIG.RPC_HOSTS
https://t.co/rELa0eKtI0
Dropping a new tool today: TTPRunner
- One-click Vectr deploy
- Give it a threat report, PDF, or just plain-english instructions and it'll build an execution & simulation plan for you
- Executions are tracked via notes and automatically sync'd with Vectr
Works great with: https://t.co/48oPMtajG1
Check it out! 🔽
https://t.co/sHV0TQmyaU
Can LNK files ever be trusted?
⚡ My latest blog post demonstrates several new LNK abuse methods, allowing you to fully spoof the target shown in Explorer. It also introduces tools to create your own LNKs, and detected spoofed ones yourself.
🐬 https://t.co/VZYVaEfO07
“Benchmarked frontier AI models on realistic SecOps tasks using Cotool’s agent harness and the Splunk BOTSv3 dataset. GPT-5 achieved the highest accuracy (63%), while Claude Haiku-4.5 completed tasks the fastest with strong accuracy.“
https://t.co/JJGyPW6Op0
PowerShell has a list of suspicious keywords. If found in a script block an automatic 4104 event will be generated regardless of logging policy :) (True for both PWSH 5/7)
Look for EID 4104 with Level 3 (Warning)
Full List: https://t.co/eWcUwACBtr
🎄 It’s time! The 2025 SANS Holiday Hack Challenge is officially OPEN!
Something’s off in the neighborhood… disappearing items, strange sightings, a chill in the air. ❄️
Can you uncover what’s really going on?
Play now 👉 https://t.co/J1nXesKONh
#HolidayHackChallenge
If you have Active Directory Certificate Services (ADCS) in your environment, run Locksmith now!
In Active Directory Security Assessments, we have found critical security issues in *most* ADCS configurations.
The great thing about Locksmith is that it doesn't just highlight the security issues in your ADCS environment, but also provides the command to remediate it!
If you're a pentester/red teamer, Locksmith is great for you to provide remediation recommendations to your customers.
https://t.co/vvtBeeMLuR
#ActiveDirectorySecurityTip
Microsoft is aware of active attacks targeting on-premises SharePoint Server customers, exploiting a variant of CVE-2025-49706. This vulnerability has been assigned CVE-2025-53770.
We have outlined mitigations and detections in our blog. Our team is working urgently to release a security update and will share more details as they become available. Read the full guidance in our blog: https://t.co/KE912glIHy