Husband & father. Leadership at DivisionHex. DEF CON C&E goon. Costco hot dogs, coffee, brazilian jiu jitsu, food, and Gator football š
Formerly @XForce
I just reverse engineered the YellowKey BitLocker bypass
Microsoft shipped code that checks for a flag called "FailRelock" in every Windows 11 recovery image. When it's set to 1, after recovery unlocks your BitLocker drive, it never relocks it. All you need is a USB stick.
This code only exists in the recovery environment. Not in normal Windows. They left an entire debug testing framework in production.
I do wonder when someone is going to implode a companys internal network with a pentest agent. I'm not against the idea of using agents, but people lack observability, guardrails, and are just yoloing random GitHub projects.
https://t.co/cXUnklYdOQ
Japanese industrial giant Mitsubishi Electric intends to acquire U.S. cybersecurity company Nozomi Networks in a deal valued at about $1 billion
https://t.co/w4ZWooyC6B
Today we unveil BadSuccessor - a new no-fix Active Directory privilege escalation technique.
We will explore the recently introduced dMSA feature, and show how it enables turning a very common, seemingly benign permission, into a full domain take over.
https://t.co/k4roTZE36T
I'm hiring! As @coalfire continues to grow, I'm looking for multiple consultant-level application pentesters. If you, or someone you know, is interested, check out this posting: https://t.co/NWUiDgamPX
Multi-factor authentication works. From the indictment: 1 of the Chinese hacking teams was unsuccessful in breaking into email accounts of Defense Intelligence Agency & Commerce employees. The indictment listed MFA as a factor in the Commerce case:
https://t.co/BRoS7jlxAZ
I wrote an article outlining why the directive to stop tracking Russian cyber threat actors is impractical and frankly dangerous, outlining some second order effects of the directive. Enjoy.
https://t.co/Cywr7GSjLC
Christopher HadnagyĀ engaged in aĀ pattern of harassment and retaliationĀ againstĀ meĀ after I left his company,Ā Social-Engineer, LLC. Here are the key actions he took against me, including things not currently written into Def Conās documentation/exhibits. Note: I simply quit my job.
Chris Hadnagy vs. DEF CON Lawsuit update
2025/02/24
Itās been a while since our last update - a lot has been going on behind the scenes - and with the discovery phase complete we have filed a motion for summary judgement asking the court to dismiss his lawsuit. In it we reveal some of the identities of those who testified regarding their experiences with Chris, and I would like to personally thank them for standing up for our community when remaining silent would have been easier.
The legal standard for evaluating a summary judgement motion means giving the benefit of the doubt to the nonmoving party (Hadnagy) on all disputed facts. Because of this we focused on the undisputed facts, including the documents and deposition testimony, that Chris canāt deny.
Should this motion fail then we would start preparing for trial, and end up arguing over the disputed facts as well. Both sides will be done with briefing in approximately one month. After briefing is complete we expect the judge to rule on the motion within a couple weeks to a couple months.
Thank you everyone for continuing to support DEF CON, and a special thank you to all those who came forward in the ongoing lawsuit.
Jeff Moss, President, DEF CON Communications.
#defcon #defconlegal @humanhacker
Motion for Summary Judgement
https://t.co/X18cmO3AAo
Full records here:
https://t.co/7kkGYTcT5d
Iām hiring a Director of Threat Hunting to help us build and manage a client facing hunt program at Coalfire. If you are the person I should hire, or know someone I should, hit the link below.
https://t.co/gJGSpl3DuF
I'm getting tired of vendors trying to build security products that do everything. Seriously, pick something and do that. The rest is a distraction for you and friction for me.
The US has the capability to stop the cyber criminal groups (even specific individuals) that target critical infrastructure. Itās time for those capabilities to be used.
Trump's exec order on international cartels is a start, but we need more.
What about cybercriminals attacking hospitals or phishing employees? It's time for tougher measures - sanctions & indictments for nations enabling cyberterrorism.
As the number of breaches utilizing some amount of social engineering increases, that would seem to signal that other security controls are working -- causing the adversary to shift.
Itās my mom. I donāt talk about my personal life on here a lot, okā¦ever, but in this case itās my mom. Sheās been battling breast cancer, isnāt able to work, and weāre trying to get her some help. Thanks to anyone who can donate, we really appreciate it.
https://t.co/QIDusHUnf5