Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @subTee
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @subTee
-
Pinned Tweet
True Vendor Call Our software protects you from buffalo overflows. Me:Excuse me, What? o_O Buffalo Overflows. Me: OKpic.twitter.com/4Sm54hehbb
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
Another instance where
@mattifestation encourages us to rethink our views on digital signature validation.https://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec …Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
I don't know that it's possible to authentically simulate the best APT groups. You can target the same victims and data, but they have nation state funding to innovate. You can get as close as yesterday.
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
FYI: 17 years into my career, still trying to become an expert at something! While I've still got stuff to learn, and still need to get better at things, the effort/process/learnings all take me to wonderful places and meeting with great people. Attitude and aptitude are key!
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
Periodic reminder: all non-trivial platforms have had serious, exploitable vulnerabilities found in them from time to time. Having a vulnerability discovered in your product isn’t in and of itself shameful. But responding badly by lashing out when one is found definitely is.
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
ASLRA: Statistical tool specially designed to measure all parameters that determine quality of ASLR https://cybersecurity.upv.es/tools/aslra/aslr-analyzer.html … [patches for paxtest ; see also OpenBSD KARL https://twitter.com/daniel_bilar/status/882902304860581888 … but "how would do you sign such a kernel"?]pic.twitter.com/sqVFT5fIoE
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
Take a look at ShmooCon Labs. We've rebooted things a bit with a much larger focus on operations and analysis. If you want to learn more about security operations, malware analysis, and incident response, take a look at Labs.https://twitter.com/shmoocon/status/943156021362556929 …
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
We've open sourced our framework for developing alerting and detection strategies for incident response. We have also included several internal strategies as examples to spur greater sharing and collaboration with defenders.https://medium.com/@palantir/alerting-and-detection-strategy-framework-52dc33722df2 …
Thanks. Twitter will use this to make your timeline better. Undo -
My "scrap" or junk code as an experiment. This was me writing a quick PoC hook to grab TLS Req/Resp from PowerShell memory, instead of with a proxy https://github.com/caseysmithrc/memMITM … Take a look, experimental PoC only. May be helpful/interesting. Feedback Welcome. Still more to do...
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
Makes me wonder what the "average security team" Detect Ops look like.https://twitter.com/rseroter/status/942819250301034496 …
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
I can attest to RWX standing out. We got to run
@jaredcatkinson's Get-InjectedThread at scale recently!
Thanks. Twitter will use this to make your timeline better. Undo -
Fixed a minor x86, x64 issue.https://gist.github.com/anonymous/3fb8c0a3a8d157ef77f0b9d082fd3056 …
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Oh Wow, this was a blast to write. In Memory SSL Intercept ;-). Thanks again mavinject! All your Encrypted PowerShell WebRequests Are Belong To Us ;-) https://gist.github.com/anonymous/00c281d0dd4aa5af5b4e6027f2dd706b … Have Fun!pic.twitter.com/TFvaQtb2Ad
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
[Good Read] Windows Inline Function Hookinghttps://blog.nettitude.com/uk/windows-inline-function-hooking …
Thanks. Twitter will use this to make your timeline better. Undo -
Simple DLL Inject UserMode Hook Example: https://gist.github.com/anonymous/b25cb82c4b3d40648f0b589fa242577f … Nice Complimentary pairing with mavinject.exe
In this example, we hook CreateProcess and prevent cmd.exe/taskmgr.exe
PoC only, but you get the idea.
More interesting would be to hook sspicli!EncryptMessage ;-)pic.twitter.com/qeSIUba24V
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
My book's finally here, just in time for Xmas. Thanks to
@billpollock and@nostarch for all their time and effort as well as my friend@k8em0 for doing the forward. Hope anyone who's bought it are seeing final copies arriving. And it's a dog on the cover BTW
pic.twitter.com/0aApanm1nL
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
Is there any possibility of Windows moving sensitive logging into a hypervisor-protected container? I don’t know how that would even work, just curious.
Thanks. Twitter will use this to make your timeline better. Undo -
Sysmoney! Thanks mavinject.exe! Details probably never.
#DFIRpic.twitter.com/8YQ9GTNFY4
Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
This evening's post on
@sans_isc diary, http://bit.ly/DetectionLab , provides more well deserved attention for@PalantirTech's Chris Long's (@Centurion) Detection Lab with: Windows 2016 DC Windows 2016 WEF/WEC server Win10 non-server endpoint Ubuntu 16.04 logger A lab for defenders!Thanks. Twitter will use this to make your timeline better. Undo -
Yeah,
@Hexacorn was looking at this over a year ago.https://twitter.com/gN3mes1s/status/941316054193721344 …Thanks. Twitter will use this to make your timeline better. Undo -
Casey Smith Retweeted
Using MavInject32.exe (Microsoft Corp Signed) to load any dll in a running process. > "C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe" <PID> /INJECTRUNNING <PATH DLL> cc:
@Oddvarmoe@Hexacorn@mattifestation@subTee@tifkin_pic.twitter.com/9b26fP03A9
Show this threadThanks. Twitter will use this to make your timeline better. Undo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.