Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @mattifestation
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @mattifestation
-
How sure are you that "(Verified) Microsoft Windows" refers to a program that actually originates from Microsoft? Code Signing Certificate Cloning Attacks and Defenseshttps://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec …
Thanks. Twitter will use this to make your timeline better. Undo -
My OCD is triggering really hard that I can't specify that a specific set of Sysmon RegistryEvent rules only fire when the EventType is SetValue.
Thanks. Twitter will use this to make your timeline better. Undo -
Matt Graeber Retweeted
[Get-Doppelgangers] - Powershell script to detect process and dll doppelganging https://gist.github.com/dezhub/6d2a3ced01aaf081da841f4761455c5f … thx
@hasherezade for the poc!Thanks. Twitter will use this to make your timeline better. Undo -
Matt Graeber Retweeted
UPDATE: If you clean install RS4+ and have compatible hardware VBS/HVCI is now automatically enabled!! This means the Windows kernel now enforces by default: Kernel code integrity, runtime ACG, and control flow integrity via VBS. Huge for Windows security. Checkout WIP builds!https://twitter.com/dwizzzleMSFT/status/935657242413510656 …
Thanks. Twitter will use this to make your timeline better. Undo -
Matt Graeber Retweeted
Shellcode running cleanly in kernel mode on a Windows 10 machine from a 0day vuln I found. Some serious PagedPool shaping involved. Come check out my talk
@BlueHatIL to hear all about it! http://www.bluehatil.com/ pic.twitter.com/2ukIwdgwuS
Thanks. Twitter will use this to make your timeline better. Undo -
Another seriously amazing agenda this year. I can't wait to present on my expanded research into code signing attacks and defense!https://twitter.com/BlueHatIL/status/943498216087212032 …
Thanks. Twitter will use this to make your timeline better. Undo -
Holy crap I'm looking forward to the result of this project.https://twitter.com/hexwaxwing/status/943261509865607169 …
Thanks. Twitter will use this to make your timeline better. Undo -
You'll have a hard time finding a more mature methodology for developing _robust_ detections than
@cryps1s and his colleagues at@PalantirTech.https://twitter.com/cryps1s/status/943223410318041090 …Thanks. Twitter will use this to make your timeline better. Undo -
#LazyWeb Does anyone know if MSFT publishes a canonical list of what it considers to be weak crypto algorithms. Reference: CERT_CHAIN_POLICY_SSL_F12 in CertVerifyCertificateChainPolicy (https://msdn.microsoft.com/en-us/library/windows/desktop/aa377163(v=vs.85).aspx …)Thanks. Twitter will use this to make your timeline better. Undo -
Why do computers work?
Thanks. Twitter will use this to make your timeline better. Undo -
And yes, I'm starting to take advantage of the 280 char limit by posting anticipated responses to tweets.
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Not being much of a Python guy, I was super impressed by malware decrypting and running modules entirely in-mem with marshal.load. "Bro, I've been talking about this for years. Check out my sweet Python RAT."
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Many of our professional lives revolve around the defense of systems that were never designed to be defensible. As such, a massive industry exists to fill that void.https://twitter.com/midnite_runr/status/943123013809164288 …
Thanks. Twitter will use this to make your timeline better. Undo -
Matt Graeber Retweeted
I think most people forget that avoiding detection usually creates artifacts that you were attempting to avoid detection. I like creating a logging/detection scenario where the attacker avoiding detection acts as an actionable signal whether through logs or other sensors.
Thanks. Twitter will use this to make your timeline better. Undo -
Attackers love executing PowerShell at the command line and regardless of PS version used, the free command line logging you get in "Windows PowerShell" EID 400 is the gift that keeps on giving. "But I can easily bypass that!" "Yes, I know you can..."
Thanks. Twitter will use this to make your timeline better. Undo -
Matt Graeber Retweeted
Wrote a quick thing about setting up
@Centurion's DetectionLab. TL;DR - It's very cool. Read the README.https://www.psattack.com/articles/20171218/setting-up-chris-longs-detectionlab/ …Thanks. Twitter will use this to make your timeline better. Undo -
The most pragmatic offensive security researchers spend time considering the impact of their research and spend time developing usable detection/prevention strategies.
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
The most pragmatic security managers don't resort to fear and blame when new attack research comes out. They view it simply as a task item to improve their posture. They manage security. They acknowledge that security is not a problem to be solved.
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Matt Graeber Retweeted
My book's finally here, just in time for Xmas. Thanks to
@billpollock and@nostarch for all their time and effort as well as my friend@k8em0 for doing the forward. Hope anyone who's bought it are seeing final copies arriving. And it's a dog on the cover BTW
pic.twitter.com/0aApanm1nL
Thanks. Twitter will use this to make your timeline better. Undo -
Matt Graeber Retweeted
Browser/mitigation people, I feel you. Cc
@parityzero@justinschuh@epakskape@tavisopic.twitter.com/vGaJFlw26a
Thanks. Twitter will use this to make your timeline better. Undo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.