Jeremy Brown

109 posts

Jeremy Brown

Jeremy Brown

@AlteredBytes

Coffee Lover. Nerd. Does wild stuff in network sessions. VP of Analysis @TrinityCyber

Joined Ekim 2020
647 Following325 Followers
Jeremy Brown
Jeremy Brown@AlteredBytes·
Excited to be presenting at @BlackHatEvents with a sponsored session talk - diving into hidden and impactful threats. Come see for yourself! #beyond-the-attack-hidden-threats-evolving-defense-48461" target="_blank" rel="nofollow noopener">blackhat.com/us-25/sponsore…
English
0
0
0
50
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
My first love was pcap, so I kinda hope for a resurgence of NSM/NDR, but like the -NG++ version of it
English
4
0
19
2K
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
Garden plants left alone tend to overgrow themselves, become brittle, imbalanced, blossom less, yield less. Many do not truly thrive without routine care and aggressive pruning. I think of this often about detection rules, workflows, tools, and "the way we do things."
English
3
2
21
2.4K
Jeremy Brown retweeted
GreyNoise
GreyNoise@GreyNoiseIO·
We cannot thank @TrinityCyber enough for providing valuable intel on CVE-2023-20198 last month. 🤝 With this information, we acted quickly and got a tag out! Grateful to be able to work together to keep our customers safe + secure.
English
0
6
18
3.3K
Brian Bartholomew
Brian Bartholomew@Mao_Ware·
Officially on the job market today. Anyone looking for an old TI guy with a "smidge" of years under his belt, let me know. Happy to have a chat.
English
5
47
90
43.2K
Jeremy Brown
Jeremy Brown@AlteredBytes·
PaperCut server exploits are in the wild; here’s how you detect the first stage: HTTP GET/POST + URI ending in “SetupCompleted” AND HTTP Response “200 OK” + header “Set-Cookie: JSESSIONID=“ with a valid token. Go hunt for this! #ThreatHunting
English
0
1
2
267
Greg Lesnewich
Greg Lesnewich@greglesnewich·
#100DaysofYARA LNK files often store a CLSID in the TargetID fields - the previous file we looked at (GOLDBACKDOOR) did not include this header, so I suspected looking for LNKs without that CLSID might surface some anomalies More on LNK file structure: u0041.co/blog/post/4
Greg Lesnewich tweet mediaGreg Lesnewich tweet mediaGreg Lesnewich tweet media
English
4
20
94
16.2K
Jessica Johannes
Jessica Johannes@jessjohannes·
When the fur kid gets back from the groomers and is feeling extra.
Jessica Johannes tweet media
English
1
0
3
0
Jeremy Brown
Jeremy Brown@AlteredBytes·
omg 2 year Twitter anniversary, yaaaas
English
0
0
2
0
Greg Lesnewich
Greg Lesnewich@greglesnewich·
Okay more feedback requested please if y’all want #100DaysofYARA for 2023! Since y’all wanted tutorials, let me know what kind of tutorials you’d like to see! Ideas include: - doc/x - PE - bulk PE similarity - general process/flow Other ideas are welcomed 😄
Greg Lesnewich@greglesnewich

If #100DaysofYARA were to happen again next year, what would people be most interested in? Anything else, throw it in a comment below! #dailyyara

English
6
3
29
0
Jeremy Brown
Jeremy Brown@AlteredBytes·
I’m looking for an experienced (3-5 years+) threat hunter who’s comfortable with both network traffic and static file analysis. You find it, you can actively take it out with @TrinityCyber tech. This you? Shoot me a DM
English
0
2
4
0
Jeremy Brown
Jeremy Brown@AlteredBytes·
Having grown up in a state that’s got trigger laws going into effect as we speak - I’m beyond disappointed at SCOTUS ruling. This is a brutal attack on women’s health, bodily autonomy, and a 50 year regression for America. I’ll always support the right to choose.
English
0
0
5
0