Sometimes I wonder how many hours of life have been wasted because thousands of independent researchers were trying to reverse the exact same Windows internals thing, and nobody bothered to publish their findings.
@LAripping Depends if you’re taking it for the certification or learning. If learning, then there are better options available. One of the best Detection Eng + Threat Hunting course ik is from Specterops. Their Detect. eng and Tradecraft Analysis (this is a gem) is something id recommend.
Kinda funny how I did Rust for n00bs and C# for n00bs, then TCM did Rust 101 and now C# 101. I was working on Assembly for n00bs but don't think I'll bother now, TCM can have it.
🚀 Say hello to the new & improved phidata 🚀
Build, ship, and monitor Agents with blazing-fast memory, knowledge, tools & reasoning 🔥
⚡️ 70% faster memory & knowledge
🛠 100+ tools
🧠 Reasoning Agents
🤝 Multi-agent collaboration
📊 Built-in monitoring and Agent UI
Join us at #AISummit in Las Vegas on Sept 8-9 for exclusive access to a full day of hands-on #AI workshops w/ @bettersafetynet@_bromiley@domenicacrognal, and more!
Here are the afternoon workshops — which one would you choose?
View Agenda & Register: https://t.co/O0E3a0J5r8
Introducing Claude Engineer 2.0, with agents! 🚀
Biggest update yet with the addition of a code editor and code execution agents, and dynamic editing.
When editing files (especially large ones), Engineer will direct a coding agent, and the agent will provide changes in batches.
Batches are smartly selected based on file complexity.
The code execution agent will run the code and check for issues.
It can even start processes (like live servers) and end them.
It's insanely powerful! 🔥
I think it's time for the security industry to realize it no longer suffices to do 2 years of basic web app pentests then read a book on AD and apply for a RT position.
Do you know why cross device authentication with a passkey requires an internet connection?
It's a challenge to transfer a few KB of data over BLE.
So the phone establishes a tunnel to the cloud and starts broadcasting a BLE advert containing an identifier for its cloud server and a nonce.
The laptop then uses the identifier to connect to the cloud and the nonce to establish the handshake and they start talking to each other over the tunnel.
The BLE advert proves the phone is physically next to the device.
Pretty cool. Also explains why it takes a few seconds when you are trying to sign in.
This reminds me. I need to finish my passkey infographic showing how cross device auth works.
If you want to learn more, this is a really good podcast episode about the history and inner workings of passkeys. 👇
https://t.co/ARLG0Er8ZH
I regularly have chats with our clients about security solutions that cause us friction during our RT projects, and make recommendations on where they can invest budget to improve their defences. Here's one solution I'll be warning everyone to avoid like the plague. Aside from the "developer" being pretty unstable, he seems to have little clue about malware. Watch out for snake oil folks, it's slippery.
John Sherchan, Red Team Security Researcher at CW Labs (@cyberwarefarelabs) presented talk titled "Assembly.Load: Writing One Byte to Evade AMSI Scan” at #BlueHatIndia. During his talk, John discussed how the bypass is unique, AssemblyNative::LoadImage, CLR.DLL AmsiScan, Writing One Byte, and implementation.
Spent some time updating the TelemetrySource project.
- Updated mappings for the Threat-Intelligence provider
- Added a folder for the Threat-Intelligence provider + added a README
A lot more updates coming soon!
Project link: https://t.co/GxnVIhX5s4
Been working on this for almost 2 years now, come along way. Research has been fun, every day I know less. But it feels so good when stuff work, This will be a first finally using the framework on real engagements and I am getting great results!! Break time!??
#redteam
Infosec Twitter has become so cringe these days, that the moment I open it, I leave it within 1-2 minutes of scrolling. I know a lot wont like what I write, but why does majority of the defensive side think they are batman of infosec community when their contribution is near to nil? Only reason I open up twitter is to post about BRc4 because this is where I started, but now its just cringe.