Incident Response & Purple Teaming @ CrowdStrike.
Previously DFIR @ANSSI_FR / @CERT_FR. Former @CertSG team leader.
The Salesloft attack shows how GitHub → AWS → Drift → Salesforce created an attack highway defenders never saw coming.
Jared Atkinson's analysis details the patterns we should look out for. ghst.ly/4ngDQrD
The Salesloft attack shows how GitHub → AWS → Drift → Salesforce created an attack highway defenders never saw coming.
Jared Atkinson's analysis details the patterns we should look out for. ghst.ly/4ngDQrD
Researchers from Institut Pasteur joined the 2025 Pride March alongside @institutcurie.bsky.social, Les Cordeliers Research Center, @institutcochin.bsky.social @institutimagine.bsky.social
👩🔬 Because diverse labs make better science.
#DiversityInScience
Researchers from Institut Pasteur joined the 2025 Pride March alongside @institutcurie.bsky.social, Les Cordeliers Research Center, @institutcochin.bsky.social @institutimagine.bsky.social
👩🔬 Because diverse labs make better science.
#DiversityInScience
posts.specterops.io/update-dumpi...
posts.specterops.io/update-dumpi...
Ukrainian CERT published a synthesis on 3 years of war time defensive activity that is well worth reading.
Ukrainian CERT published a synthesis on 3 years of war time defensive activity that is well worth reading.
www.404media.co/license-plat...
www.404media.co/license-plat...
You MUST read it!
PDF: reports.dtexsystems.com/DTEX-Exposin...
You MUST read it!
PDF: reports.dtexsystems.com/DTEX-Exposin...
AD sync itself is still performed by a MSOL_ account.
Thank you!
AADInternals 0.9.8
Microsoft Entra Connect Sync 2.4.131.0
pastebin.com/UU4u7YZR
AD sync itself is still performed by a MSOL_ account.
Thank you!
AADInternals 0.9.8
Microsoft Entra Connect Sync 2.4.131.0
pastebin.com/UU4u7YZR
www.synacktiv.com/publications...
www.synacktiv.com/publications...