Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @xorrior
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @xorrior
-
Pinned Tweet
Empire v2.3 is out. Please see the changelog for detailshttps://github.com/EmpireProject/Empire/blob/master/changelog …
Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
How sure are you that "(Verified) Microsoft Windows" refers to a program that actually originates from Microsoft? Code Signing Certificate Cloning Attacks and Defenseshttps://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec …
Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Another instance where
@mattifestation encourages us to rethink our views on digital signature validation.https://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec …Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
[Get-Doppelgangers] - Powershell script to detect process and dll doppelganging https://gist.github.com/dezhub/6d2a3ced01aaf081da841f4761455c5f … thx
@hasherezade for the poc!Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
What if you can avoid all events ? Even the one saying you cleared all events ?
#mimikatz#notrace https://github.com/gentilkiwi/mimikatz/releases …pic.twitter.com/eZHfbsyd0YThanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
We've open sourced our framework for developing alerting and detection strategies for incident response. We have also included several internal strategies as examples to spur greater sharing and collaboration with defenders.https://medium.com/@palantir/alerting-and-detection-strategy-framework-52dc33722df2 …
Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Are you really ready for
#ThreatHunting? What does your data look like? Data Availability != Data Quality@SpecterOps@MITREattackhttps://posts.specterops.io/ready-to-hunt-first-show-me-your-data-a642c6b170d6 …Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Several weeks of research and several cease and desist letters later - the longest research paper I've ever written is now out. Read about the never-ending tale of OSX/Pirrit -https://www.cybereason.com/blog/targetingedge-mac-os-x-pirrit-malware-adware-still-active …
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Our February training offering of Adversary Tactics: Red Team Operations is officially sold out. Waitlist is available. More course offerings to be announced shortly.https://specterops-atrto.eventbrite.com
Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Today I'm releasing Detection Lab, a personal project that uses Packer & Vagrant to quickly stand up up a fully customizable Windows Active Directory loaded with security tooling and some logging best practices. Blog: https://medium.com/@clong/introducing-detection-lab-61db34bed6ae … Github:https://github.com/clong/DetectionLab …
Thanks. Twitter will use this to make your timeline better. Undo -
Chris RetweetedThanks. Twitter will use this to make your timeline better. Undo
-
Chris Retweeted
I did a quick write-up on my method of getting BadIntent for Android set up.http://blog.obscuritylabs.com/badintent-setup/ …
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
[blog] Designing Effective Covert Red Team Attack Infrastructurehttps://posts.specterops.io/designing-effective-covert-red-team-attack-infrastructure-767d4289af43 …
Thanks. Twitter will use this to make your timeline better. Undo -
Chris RetweetedThanks. Twitter will use this to make your timeline better. Undo
-
Chris Retweeted
New blog post up! https://www.nuix.com/blog/changing-phishing-tactics-require-closer-user-and-defender-attention …
Show this threadThanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Atomic Sysmon configs individually mapped to the ATT&CK Matrix anyone? https://github.com/Cyb3rWard0g/ThreatHunter-Playbook/tree/master/attack_matrix/windows/sysmon_configs …
@Cyb3rWard0g is on fire! All this now requires is a little code to enable selective merging of technique detections. Detection unit testing FTW!#DFIR /cc@subTeeThanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
As a follow-up to this experiment https://twitter.com/mattifestation/status/932043972263886848 …, I documented my process/experience/methodology developing the most secure Device Guard policy I could: "Adventures in Extremely Strict Device Guard Policy Configuration Part 1 — Device Drivers" https://posts.specterops.io/adventures-in-extremely-strict-device-guard-policy-configuration-part-1-device-drivers-fd1a281b35a8 …
Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Our resident application whitelisting breaker/expert,
@mattifestation shows us the steps involved in developing one of the most strict types of Device Guard code integrity policies.https://posts.specterops.io/adventures-in-extremely-strict-device-guard-policy-configuration-part-1-device-drivers-fd1a281b35a8 …Thanks. Twitter will use this to make your timeline better. Undo -
Chris Retweeted
Looking for more Linux *nix persistence mechanisms in Empire. Let me know if you use others than what's in Empire currently.
Thanks. Twitter will use this to make your timeline better. Undo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.