What is Beaconator C2?
w/ @Shammahwoods introducing a C2 framework and set of adversarial emulation tools at @defcon demo labs to provide a robust management console with a wide range of beacon payloads, including payload options for win/MacOS/Linux.
https://t.co/qIcRZc4uvV
⚠️ Developers, please be careful when installing Homebrew.
Google is serving sponsored links to a Homebrew site clone that has a cURL command to malware. The URL for this site is one letter different than the official site.
A PSA to start the day. Not all ports and services are created equal. If you are overwhelmed protecting all of them, maybe just start with making sure the most commonly exploited are squared away. Here is a cheat sheet a few of us published a while back, to get you started, for anyone new to host hardening and network segmentation:
https://t.co/tY4ZMznodr
If you are working on microsegmentation, remember that Application Ring Fencing is only part of the equation. You also need to implement User Ring Fencing, to define the activities and origination locations for admins and power users. A perfect security posture is frustrating to attackers, and seamless to users and administrators.
#microsegmentation #networking #firewall @Guardicore #applicationringfencing #remoteaccess
Oh crap, is it CactusCon already? Its a free hacker event at the Mesa convention center this Friday and Saturday.
Come meet your favorite hackers like...anonymous 1,2, AND 3. See you there!
https://t.co/FA7SugUFhW
Ever wonder what it takes to launch a career as a CISO? Or, consider how to succeed at the job once you get there? Come out to @CactusCon 11 this Friday and see our talk on the road to CISO (in Career Village Track 1 w/ @Andy_J_Jordan at 2pm). https://t.co/TpXC6PrCfR
The Hacker Tracker team deserves a @defcon Uber badge for all the work they do. It became a key tool for navigating the con years ago. R/T if you agree.
Join me on Saturday, August 13 at 10am for my presentation at the DEF CON Groups Virtual Reality Event @ DEF CON 30! You can join me in AltSpace VR (code KUD156) or you can watch the stream of the AltSpace event on Twitch. See the image below for both links. Hope to see you!
Just wanted to share this great @offsectraining podcast with @drmonthie and Lester Godsey discussing fun topics such as election security, disinformation, and how our roles and strategies evolve due to social platforms.
https://t.co/GMF2VZMo9A
Have a surprise for our SOC team on our next in-office day. Look forward to loads of fun playing @BHinfoSecurity Backdoors and Breaches, including the some of the newest members of our team.
Special thanks to @DebRadcliff and Christian Taillon for the fun and engaging conversation about software dependency, supply-chain risk, and what steps we can take to improve the situation (e.g., SBOM, dependency mapping, etc).
https://t.co/LwIsCN022L
It has now been three weeks now since Log4Shell streaked across our horizon like a surface-to-air missile, perfectly aimed at shooting down Santa’s Sleigh. Where does that leave us today? https://t.co/ftDM1dLg11
Yeah, we know, it's sad that CactusCon 9 is over, and we're sure you're missing us already. So come hang out in @discord! Our Community server is up and rocking year round! https://t.co/qD8AH8tIBF
CactusCon 2021 update! All activities will be virtual and will take place February 5-7. The CFP is still open for you to submit talks and workshops: https://t.co/wE3rwgeaF9. Virtual details TBA.