Just had to gate check a bag I've carried on your planes many times. Other bags of similar or larger sizes were allowed. Fix your ridiculously small overhead bins and enforce the carry on size fairly. Not sure why I continue to fly with you guys.
@SouthwestAir
Need to go under the radar downloading #mimikatz (and other suspect payloads)? Then newly discovered #lolbin "C:\Windows\System32\Cmdl32.exe" (signed by MS) is for you. It's like a new certutil.exe but absolutely unheard of by any antivirus software!
You can capture process-id and thread-id for each packet with Winshark, a Wireshark extension.
Here is a simple ping example.
https://t.co/UhVwOS1vzJ
Credits go to CSIRT team of Airbus
This is big! Using this will mitigate a common exfil path when people attempt to setup isolated networks on AWS or otherwise attempt to restrict network egress.
I described the DNS exfil trick here: https://t.co/RQJS4Ccarc
New tool: SunburstDomainDecoder
It parses #SUNBURST#DNS queries and prints decoded domain fragments, grouped by victim GUID value.
#SolarWinds#Solorigate
https://t.co/l58TcKCj14
Malicious cyber actors are using two sets of #TTPs to access protected data in the #cloud. Detect and mitigate against this activity by reviewing our latest #cybersecurity advisory: https://t.co/scmnGlM7cP
Supply Chain compromise of #SolarWinds provides Dark Halo actor with unauthorized remote access to select targets. @Volexity has also observed this group using novel methods to bypass 2FA. New research just posted to our blog: https://t.co/qAuOPRJo1o #threatintel#dfir#infosec
Did you know that there are five types of API gateways on AWS? Check out @andreaswittig's comparison on the @CloudcraftCo blog. https://t.co/Izze23WFqM #awscommunity
The interview question thing . . .
✖️ “What side projects are you working on?”
✔️ “If you had 20% of your time at work to dedicate to a project of your choosing, what would it be?”
You should be screening for passion, interests, abilities
. . . not for life circumstances.
I have been waiting for YEARS for this. Here you have it, the man who coined the term #AdvancedPersistentThreat. My writing has danced around his identity all this time. Col Rattray was one of my profs at @AF_Academy and we did a little work together at #airintelligenceagency.
In recent months, we built a profile of 2 prominent exploit developers — Volodya and PlayBit.
Our blog post details our methodology and explains how we were able to fingerprint their exploits to ultimately track 16 Windows LPE exploits sold by them.
https://t.co/xSMlLCZxX6
Quickly check if your IP is exposing any ports to the Internet by visiting https://t.co/suJA6fndpX
If you see a 404 page then you don't have anything exposed!
Perusing the @TalosSecurity paper on detecting Cobalt Strike, by @nickmavis.
Would love to see impact analysis as a follow-on:
"Cobalt Strike accounted for 66 percent of all ransomware attacks Cisco Talos Incident Response responded to this quarter."
https://t.co/YXGzlLawyw
#DailyDFIR 250: Have a long command on Linux that you're trying to make sense of? Check out explainshell!
🔗 https://t.co/Nbhv1bGj5Z
I think the interface is really nice and like the hover interactions. It was definitely part of my inspiration for Unfurl. #DFIR#bash#Linux