Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @sixdub
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @sixdub
-
Pinned Tweet
New blog post that I co-authored with
@StephenHinck on some threat research the team at@icebrgdotio has donehttps://www.icebrg.io/blog/footprints-of-fin7-tracking-actor-patterns …Thanks. Twitter will use this to make your timeline better. Undo -
Want to read more on true attribution. I am a fan of this post by
@RobertMLee : http://www.robertmlee.org/the-problems-with-seeking-and-avoiding-true-attribution-to-cyber-attacks/ …Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Dismissing the value of "attribution" is common in the commercial space, typically referring to "true attribution". It is valuable for people to understand that there are diff types of attribution. IMO, associating threat activity w/known campaigns or TTPs is useful tactically
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Everyone go read this! Detection strategy is a super interesting area of research/study. I love the idea of this framework and documentation to ensure better knowledge of detection capability.https://twitter.com/cryps1s/status/943223410318041090 …
Thanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
Our CEO
@wepIV serving chicken and waffles this morning at ICEBRG HQ.pic.twitter.com/65z6Mcof8v
Thanks. Twitter will use this to make your timeline better. Undo -
Love it! I have talked to several red teams, about the concept of "counter intel" where they monitor popular Intel sources and feeds for the presence of their indicators as a tip off. Addtl training audience and value. Helps ensure real bad guys might not be getting tips...https://twitter.com/gentilkiwi/status/939270526551445504 …
Thanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
It’s Q4. If you are in a pentest sweat shop questioning if your work is valued while you double book your time through the holidays, know there are better options. Our pentesters matter, we take our findings seriously, and we work as a team. https://careers.walmart.com/results?q=penetration&o=0&sort=rank&jobCategory=all …
Thanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
Analytic trust is critical. Analysts and enterprises must trust their analytics for them to be useful. One component of that trust is outcome transparency - why did it do what it did? Can the outcome be validated?
#Analytics#analysis#datascience#BigData#MachineLearningThanks. Twitter will use this to make your timeline better. Undo -
I love looking at a histogram of activity to C2 servers during an IR and seeing the dip on the weekends. There really are humans on the other side! They too have habits and flaws.
Thanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
As a red teamer, if you ever have the opportunity to work a threat hunting or IR engagement, you should jump at the opportunity! You will be humbled by the challenges defenders deal with at scale and you will gain valuable insight into how they baseline normal and triage alerts.
Thanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
Atomic Sysmon configs individually mapped to the ATT&CK Matrix anyone? https://github.com/Cyb3rWard0g/ThreatHunter-Playbook/tree/master/attack_matrix/windows/sysmon_configs …
@Cyb3rWard0g is on fire! All this now requires is a little code to enable selective merging of technique detections. Detection unit testing FTW!#DFIR /cc@subTeeThanks. Twitter will use this to make your timeline better. Undo -
Seriously everyone... Read this thread. It is extremely insightful and reminds me in many ways of the eye opening experiences I had early on. Also, it's a fun read!https://twitter.com/cglyer/status/936416543914758144 …
Thanks. Twitter will use this to make your timeline better. Undo -
Been working a lot with Scala and Spark. Just when I got comfortable with it, I had to analyze some PowerShell and realized how much I missed it.
#PoSh4lyfe#VerbNounFever#JealousOfTheAdversaryThanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
The British forging German ration cards and dropping them over Germany during WW2 is my new favorite attack. Subversive exploitation of human nature to target the state. Clever af
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
{Blog} https://www.darkoperator.com/blog/2017/11/20/some-comments-and-thoughts-on-tradecraft … Some Comments and Thoughts on Tradecraft
#RedTeam#BlueTeamThanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
Cypher – the SQL for Graphs – Is Now Available for Apache Spark https://neo4j.com/blog/cypher-for-apache-spark/ … https://github.com/opencypher/cypher-for-apache-spark …pic.twitter.com/Iy5t8Ln86X
Thanks. Twitter will use this to make your timeline better. Undo -
Great post with some thoughts on detection authoring using Apache Struts as an example. We saw it used in the wild but current sigs weren't detecting... Credit to
@dancaselden@b0n0n@StephenHinck@icebrgdotiohttps://goo.gl/2aDw9DThanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
Huge thanks to a great group from
@icebrgdotio who worked literally until dusk today restoring the urban forest at Delridge and Myrtle!#restoration#seattle#pnw#conservation#greenseattle@greenseattlepic.twitter.com/uLVAXTGgSy
Thanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
SMB and dce_rpc support finally coming to Suricata!
#SuriConThanks. Twitter will use this to make your timeline better. Undo -
I typically only use this for infosec stuff but ... Must give a shout out to a friends restaurant, Sadies BBQ in Pearl City, Oahu. If you like local style Korean food and are in HI, check it out!pic.twitter.com/g5skoj4eIy
Thanks. Twitter will use this to make your timeline better. Undo -
Justin Warner Retweeted
Most PE files under System32 and SysWOW64 are hard links to the real file under \Windows\WinSxS\. This query finds files that do not match that pattern - defenders, you might want to take a closer look at these across your fleet.https://twitter.com/MSwannMSFT/status/929035557153382401 …
Thanks. Twitter will use this to make your timeline better. Undo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.