Russ

2.9K posts

Russ banner
Russ

Russ

@rustla

Pentester who often hangs out with the blue team. (he/him) https://t.co/1FK1qTVE4f | https://t.co/am6hJzTsmf

///hacker.coffee.hops Bergabung Aralık 2007
650 Mengikuti268 Pengikut
Tweet Disematkan
Russ
Russ@rustla·
If you missed my @BSidesPer talk on token theft, it’s now uploaded. youtu.be/br-fSjz9ySs This AI generated image didn’t quite make the cut in my slide deck but it’s too weird not to share.
YouTube video
YouTube
Russ tweet media
English
0
7
27
11.3K
Paweł Skarżyński
Paweł Skarżyński@chesteronio·
@techspence Hopefully they haven't changed the password to Spring2026! yet. It's in two days, so they should be precise ;-)
English
1
0
1
30
spencer
spencer@techspence·
Conversation I see on X: so long pentesters, AI is taking your job! Conversations I have with clients: The password Winter2025! was valid for a user. We got in through vpn (no mfa). We kerberoasted the built-in admin account and cracked the hash. The password was badass1983!. Oh and your DCs are on the internet, did you know that? The internet, as amazing as it is, is very much an echo chamber. If you’re an IT admin or IT/Security leader it’s paramount that you talk to people in the trenches, preferably somewhere other than social media.
English
17
3
90
6.1K
Russ
Russ@rustla·
@techspence 👻 eseutil /p c:\exchange.edb
Filipino
0
0
0
8
spencer
spencer@techspence·
Tell me you’ve worked in IT without telling me you’ve worked in IT. I’ll go first… Did you try turning it off and back on again?
English
2.4K
29
1.4K
144.4K
Russ
Russ@rustla·
Week 53: You better watch out You’d better not cry You’d better not pout I’m telling you why Sandy Claws is coming to town
Russ tweet mediaRuss tweet media
English
0
0
0
37
Russ
Russ@rustla·
In 2015 I did a weekly photo challenge - a pic of Mathias (middle) taking a photo and also the pic Mathias took. 10 years later he’s back with his wife (they met during the 2015 project) and their daughter, and I’m sharing his pics again. 2015 project - flickr.com/photos/rustla/…
Russ tweet media
English
48
0
0
1.1K
Russ
Russ@rustla·
My 7 year old asked me if I can ChatGPT is Santa is real 😳
GIF
English
0
0
0
51
Russ
Russ@rustla·
Week 52: Yippee ki yay mother quokka As we rapidly hurtle towards Christmas, Mathias found the Christmas light displays in Perth’s city centre. He was excited to see the lights featured a Quokka.
Russ tweet mediaRuss tweet media
English
0
0
0
43
EZ
EZ@IAMERICAbooted·
This is hilarious 😆 😆 😆 😆
Peter Girnus 🦅@gothburz

Day 1. The attacker entered. We did not notice. Day 2. The attacker moved laterally. We were in a meeting about Q2 roadmap. Day 30. Monthly security review. "No anomalies detected." The anomaly was in 47 systems. We reviewed 3. Day 90. Quarterly board update. "Our security posture is strong." The attacker agreed. Strong enough to support their operations. Day 180. Half a year. The attacker has settled in. They've customized their workspace. We've customized our dashboards. Neither reflects reality. Day 365. Happy anniversary. The attacker brought friends. Sandworm. GRU. Names we'll learn later. Much later. Day 547. The edge devices were misconfigured. We didn't know. The attackers did. That's the thing about edge devices. Someone's always on the edge. Usually not us. Day 730. Two years. The SIEM is working. The SIEM has 847,000 alerts. We've triaged 12. None of them were this. Day 847. Someone mentioned "zero trust." In a webinar. We attended the webinar. The attacker attended our network. Different priorities. Day 1,000. Milestone. We celebrated. Ship-it drinks. Product launch. The attacker celebrated too. Credential harvest. Different metrics. Same infrastructure. Day 1,095. Three years. The vulnerability was not a vulnerability. It was a configuration. Our configuration. Customer configuration. The customer is always right. The customer is also always misconfigured. Day 1,277. Security awareness training. "Don't click suspicious links." Everyone completed it. The attacker didn't need links. They had the front door. And the side door. And a ladder to the window. We left the ladder. Day 1,460. Four years. Someone in the SOC saw something. "Probably nothing." It was not nothing. It was everything. They went to lunch. The attacker stayed. Day 1,500. Audit passed. ISO 27001. SOC 2 Type II. The auditor was impressed. The documentation was thorough. The attackers were more thorough. But they weren't in scope. Day 1,643. The threat intel feed updated. "Sandworm targeting Western critical infrastructure." We read the report. We shared the report. We were the report. We didn't know yet. Day 1,700. New CISO joined. Former FBI Cyber Division. He seemed sharp. The attackers seemed sharper. For now. Day 1,750. Something wasn't clicking. For the CISO. Everything was clicking. For the attackers. Mouse clicks. Keyboard clicks. Credential clicks. Day 1,800. The new CISO asked questions. Uncomfortable questions. "Why is this device talking to Belarus?" Good question. We checked. Oh. Oh no. Day 1,825. Five years. Detection: complete. Finally. Containment: pending. Eradication: pending. Recovery: pending. Sanity: not pending. Gone. Day 1,826. The war room was activated. We have a war room now. The attacker had a war room for 1,825 days. We have one for 1. Different timelines. Day 1,827. The press release was drafted. "We take security seriously." We took it seriously. Eventually. "Sophisticated nation-state actor." They used misconfigured edge devices. The sophistication was our denial. Day 1,828. Legal joined the call. Legal read the timeline. Legal left the call. Legal is "working on messaging." The messaging is: we were home. For five years. With guests. Uninvited guests. Russian guests. Day 1,829. The recommendations were written. - Network edge device audit - Credential replay detection - Access monitoring - IOC review We wrote these down. For 2026. The attackers started in 2021. We're aspirational. Day 1,830. The CISO gave an interview. "Patch all you like, but if you leave devices misconfigured, it's like putting expensive locks on the front door and leaving an upstairs window open with a ladder on hand." Poetic. Accurate. We were the ladder. We were always the ladder. Day 1,831. New alert. North Korean operatives. Applying for jobs. 1,800 blocked since April. Different attackers. Same platform. Same year. Different vibes. They're using laptop farms. In America. To look American. While living in Pyongyang. Remote work. Very remote. Day 1,832. The incident is closed. The incidents are not closed. Plural now. Russians in the network. North Koreans in the job portal. We are popular. The wrong kind of popular. Day 1,833. Lessons learned meeting scheduled. For next quarter. Attendance: mandatory. Implementation: optional. Learning: theoretical. Day 1,834. The postmortem was written. 200 pages. Root cause: "misconfiguration." Root root cause: "human error." Root root root cause: "we didn't look." For five years. We didn't look. Day 1,835. I updated my resume. Not on LinkedIn. The North Koreans are on LinkedIn. Hijacking dormant accounts. For credibility. I respect the grind. I do not respect the implications. Day 1,836. Coffee: critical. Outlook: bleak. The 2026 recommendations are published. "Don't let 2026 be an open window for attackers." 2021 was the open window. 2022 was the open window. 2023 was the open window. 2024 was the open window. 2025 was the open window. 2026 is the recommendation. Day 1,837. The incident is over. The trauma is not. We've completed the postmortem. The patient died in 2021. We pronounced it in 2025. The paperwork is complete. Mean time to detect: 1,825 days. Mean time to care: 1,826 days. Mean time to forget: TBD. The edge devices are being audited. The attackers are being attributed. The executives are being promoted. The analysts are being caffeinated. Containment: achieved. Eradication: achieved. Recovery: in progress. Faith in detection capabilities: unrecoverable. The ladder has been removed. The window has been closed. The door remains open. It's always open. For collaboration. And apparently, nation-states. Status: Resolved. The resolution is: we know now. What we didn't know then. For 1,825 days. The breach is over. The next breach is loading. Goodnight.

English
2
0
9
1.5K
Russ
Russ@rustla·
@infosec_fox Mine did this just today 🤣
English
0
0
0
14
INFOSEC F0X 🔥
INFOSEC F0X 🔥@infosec_fox·
Is it a good time to send out phishing email test to everyone saying the company is giving out end of year appreciation gifts?
English
10
4
12
1.5K
Russ
Russ@rustla·
Week 51: Basically a Train Alex, Mathias, and Luna found the public transport in Perth to be a little outdated.
Russ tweet mediaRuss tweet media
English
0
0
0
73
Russ
Russ@rustla·
Week 50: 🐠 Omeo and Juliet 🤿 Mathias headed out to Coogee Beach and found the Omeo shipwreck. He was surprised to see so many fish while snorkelling so close to the shore.
Russ tweet mediaRuss tweet media
English
0
0
0
51
Russ
Russ@rustla·
Week 49: 🧚 I do believe in fairies 🧚‍♀️ Luna borrowed Mathias’ camera when she discovered the entrance to Pixie Hollow. I wonder if Tinker Bell is home.
Russ tweet mediaRuss tweet media
English
0
0
0
31
Russ
Russ@rustla·
Week 48: 💅 Purple Everywhere ✨ Luna, Mathias, and Alex revisited one of their favourite spots in Spring and were excited to see the Jacaranda trees have painted everything purple.
Russ tweet mediaRuss tweet media
English
0
0
0
37
Russ
Russ@rustla·
Week 47: Living Rocks Mathias headed out to Lake Clifton to check out the thrombolites. Around 2,000 years old and the largest thrombolite reef this side of equator.
Russ tweet mediaRuss tweet media
English
0
0
0
14
Russ
Russ@rustla·
Week 46: Window to the City Alex, Luna, and Mathias enjoyed a stroll through Kings Park and found a vantage point looking out across the city.
Russ tweet mediaRuss tweet media
English
0
0
0
38
Russ
Russ@rustla·
@vxunderground @starrdlux Use your local buy nothing pages to re-home things you don’t need. Same with any local parents group / friend circles that have similar aged kids. Likewise anyone expecting a baby offer them the stuff
English
0
0
1
20
vx-underground
vx-underground@vxunderground·
@starrdlux I feel like a hoarder right now. Sooo many things coming into the house. I need to just dump half the stuff out honestly or idk organize or something idk
English
3
1
19
2.3K
vx-underground
vx-underground@vxunderground·
Parents, I need your opinion Ever since my son was born my house has been a disaster. It's not filled with trash, there isn't bugs, or anything like that. But, we have INSANE clutter and disorganization. We have mountains of boxes from Amazon we have to recycle, we go through TONS of trash bags now from dirty diapers and stuff. We are always behind on laundry. On top of all of this, we made the mistake of buying him tons of stuff my baby boy has already outgrown. We have mountains of clothing that already don't fit him. My wife and I have also been moving stuff around a lot. We have a bassinet in my office, his "bedroom" (nursery), which means other furniture is literally just pushed anywhere we can fit it. It's dizzying how much is changing and so fast. Did any of you have this problem? Was your house also a mess? My son is 8 months old and everything is happening so quickly I don't even know what's going on anymore. My sleep has been ATROCIOUS since he's been born which makes doing anything else difficult as well. We're first time parents, we planned for the baby, read the books, took the classes, prepared financially, did everything how you're "supposed" to do it and it's still been a whirling wind of chaos
English
274
13
546
58.9K
Russ
Russ@rustla·
@LaCryptoSenora @vxunderground Yup. Super tired at first, now they’re 9yo and 7yo, keeping up with us doing 20k steps a day in Tokyo and trying new food on holiday. Happened so fast, they’re now basically friends who you hang out with a lot. First few years are fun to see the world new through their eyes.
English
0
0
2
42
Bacon Expat
Bacon Expat@BaconExpat·
@vxunderground The first year is the hardest, then you blink, and its over and they are in school, you blink again, and they are asking for the car keys and they never want to snuggle with you again. Enjoy it while it lasts, its over in an instant.
English
1
0
23
462
vx-underground
vx-underground@vxunderground·
I've been bamboozled My son is 7 months old. The first 3 months were an inescapable hell. At the 7 month marker things have gotten easier, but a new set of challenges continually appear I have no reason to say any of this. I'm a first time Dad and I am learning the ropes. I haven't gotten an actual full night's rest since my son was born. I'm really, really, really tired. I love my son, but it's hard and I just wanted to complain into the void of the internet.
English
244
11
1.7K
97.8K
Russ
Russ@rustla·
@techspence Congrats! Helpdesk origin story represent 💪
GIF
English
1
0
1
22
spencer
spencer@techspence·
I’ve been accepted into the Microsoft MVP Program, in Security - Identity & Access!!! This is such a super awesome honor, to be among so many folks that I admire. Me and Active Directory go back more than a decade. Started in Help Desk, not even knowing what a forest was, reset passwords and creating new user account. Fast forward to today… I now identify and abuse the same misconfigs I once made myself as a sysadmin. It’s really a full circle thing for me where I’m able to help IT teams week in and week out through internal pentesting. Help them correct and avoid the mistakes I made. The content I make and the stuff I share and try to be apart of is to serve one mission, to empower, educate, and arm IT/cybersecurity people. I appreciate the recognition and nomination by Jake Hildreth. Who is not just a friend and MVP himself, but also a tremendous asset to the community as well and a heck of a good dude. There’s too many others to name them all, who’ve been a guide and inspiration for the work I do. But special thank you to @securit360 and my boss @kamakauzy for allowing me to do work I’m passionate about and share that with all of you. I’m very much looking forward to continuing to spread the good word about Active Directory security. Thank you to the IT/cybersecurity/infosec community!!! 🙏💙
spencer tweet media
English
56
4
347
20.1K
Russ
Russ@rustla·
Week 45: Metallica After seeing Never Never Land at DisneySea, Mathias found himself taking James’ hand off to Never Never Land at Perth Stadium
Russ tweet mediaRuss tweet media
English
0
0
0
94
Matt Zorich
Matt Zorich@reprise_99·
There is truly nothing more terrifying this Halloween
Matt Zorich tweet media
English
37
443
4.4K
125.9K