Mets, Knicks, Bengals and THE Ohio State University have what’s left of my heart.
PNW == localhost
$ go run github.com/hdm/ctail@latest -f -m '^autodiscover\.'
github.com/hdm/ctail
$ go run github.com/hdm/ctail@latest -f -m '^autodiscover\.'
github.com/hdm/ctail
www.greynoise.io/blog/surge-p...
www.greynoise.io/blog/surge-p...
If you want to get the basic gist of it, this config file change has documentation on it: github.com/VirusTotal/y...
Just set it in your config file and use "yr check" for now.
Happy #100DaysOfYARA. ;)
If you want to get the basic gist of it, this config file change has documentation on it: github.com/VirusTotal/y...
Just set it in your config file and use "yr check" for now.
Happy #100DaysOfYARA. ;)
You know what isn't changing?
the dylibs it depends on and the entitlements it requests from the OS. Combined, they give us excellent signal
github.com/100DaysofYAR...
You know what isn't changing?
the dylibs it depends on and the entitlements it requests from the OS. Combined, they give us excellent signal
github.com/100DaysofYAR...
Any #CTI or #detectionengineering folks looking for a self-paced challenge to start the year with a laid back & fun community? Look no further!
The challenge is simple - write a YARA rule every day for 100 days
Any #CTI or #detectionengineering folks looking for a self-paced challenge to start the year with a laid back & fun community? Look no further!
The challenge is simple - write a YARA rule every day for 100 days
hackingthe.cloud/blog/2024_wr...
hackingthe.cloud/blog/2024_wr...
hackingthe.cloud/aws/exploita...
hackingthe.cloud/aws/exploita...
www.microsoft.com/en-us/securi...
www.microsoft.com/en-us/securi...
Our Credit Card Canarytokens are out of beta and on your Canarytoken servers..
- Grab one;
- Stash it somewhere "safe";
- We will notify you if it's ever used!
Read more about it at blog.thinkst.com/2024/12/its-...
Our Credit Card Canarytokens are out of beta and on your Canarytoken servers..
- Grab one;
- Stash it somewhere "safe";
- We will notify you if it's ever used!
Read more about it at blog.thinkst.com/2024/12/its-...
John Lambert, one of the seniormost Microsoft people who has his hand fighting their greatest battles.
medium.com/@johnlatwc/d...
John Lambert, one of the seniormost Microsoft people who has his hand fighting their greatest battles.
medium.com/@johnlatwc/d...
awseye.com
awseye.com
aws.amazon.com/about-aws/wh...
aws.amazon.com/about-aws/wh...
docs.google.com/presentation...
#redteam #purpleteam #redteamvillage
docs.google.com/presentation...
#redteam #purpleteam #redteamvillage
Full show: www.youtube.com/watch?v=Rxye...
Full show: www.youtube.com/watch?v=Rxye...
github.com/nzymedefense...
github.com/nzymedefense...
However this bit stands out to me - #infosec has become too dependent/reliant on EDR and has ignored network visibility and architectural controls, resulting in defeat if EDR is blind or bypassed.
However this bit stands out to me - #infosec has become too dependent/reliant on EDR and has ignored network visibility and architectural controls, resulting in defeat if EDR is blind or bypassed.