Hi, I’m hiring a Director of Detection Engineering and Threat Hunting. It’s my role, so if your work history is like mine you might be a good candidate.
Read more: https://t.co/jICl5bHCq1
I have an open spot on my team for a Principal Threat Intelligence Analyst here at @HuntressLabs !
You will be able to help lay the foundation for our CTI program going forward. We have a lot of interesting telemetry and some hard problems to solve:
https://t.co/lMkXG6tUJ0
A team of champions at @Blackwelladv have completed 150 climbs to raise money for a neat all-terrain wheelchair, to give folks the best time in the great outdoors. they defo deserve our support! (https://t.co/2a3b274e3U) video of their good work here: https://t.co/STKnZkvViF
This time, we venture into RedSun, BlueHammer, and UnDefend!
https://t.co/ur5fj4VDte
As always, it's a pleasure to work with @RussianPanda9xx; banger work by the SOC crew @wbmmfq and @Curity4201 that helped document and raise the flag on this internally as well!
Found some very common adware quietly killing antivirus products. Then we found an unregistered update domain, and anyone with $10 could have pushed any payload to 25,000+ endpoints, AV already disabled.
So we registered it first.
https://t.co/WMSaym7yOu
Big thanks to @_rdowd
With the noose tightening on a lot of the RMM trials, over the past month, we’ve seen a clear uptick in fake RMM deployments.
Some have been Telegram bots; others have been custom RATs that deploy follow-on tooling.
At the end of the day… RMMs are just glorified RATs 😆
Parts 1–4: built detections for LDAP-based AD recon. Felt good. 😃
Then a threat actor ran geT-aDcompUTER -PROPErTieS * and walked out with everything. 🥴 None of my rules fired. 🤬
Part 5A is the story of why…
https://t.co/FvYbn5XodJ
You can now build macOS firewalls/network tools via Endpoint Security - no Network Ext. needed! 🤯
Reversing macOS 24.6’s new ES_EVENT_TYPE_RESERVED_* ES events shows some are network auth/notify hooks
Read: “Building a Firewall…via Endpoint Security!?”
https://t.co/gR4t6dPbbr
Going to be spinning up a little series of posts with some Blue Team specific Claude tips - follow along with
#ClaudeForBlueTeam
First tip - ATT&CK can be downloaded as a JSON file, which Claude loves to work with. Remember, ATT&CK has a Data Source component - use Claude to ask some questions like "What logs do I need to detect X" or "What data source do I need to enable to cover the most techniques"
Thoughts & SecOps/IR workflows for Agentic AI: https://t.co/G8C219J3LU
This mostly just consolidates a heavy period of "mess around" I've been in with AI into some tangible takeaways and real world systems.
🧑💼"Your Outlook has an issue. Let me help you fix it."
@HuntressLabs Threat Hunting and Tactical Response teams join forces to open new pages on an old playbook, leading to custom Havoc agent deployment via sophisticated DLL side-loading.
https://t.co/j3AxpvjgSU
We promised and we delivered 🔥 Teamed up with my Binja (IDA supremacy but we don't need to talk about that rn 😂) buddy @sudo_Rem 💙 to exorcise this lil Demon 😈
From the spam bombing and fake Outlook patches all the way down to the Havoc Demon. DLL side-loading, Hell's Gate, Halo's Gate... detours... this one had it all. Go give it a read 👇
We're looking for a Principal Threat Intel Incident Commander here at @HuntressLabs ! Do you love to:
🔍 Conduct #DFIR analysis?
👀 Track threat actors?
🕸️ Work with others across different departments?
✍️ Write about your findings?
👩💼 Present your work?
👇