Josh Madeley

1.3K posts

Josh Madeley

Josh Madeley

@MadeleyJosh

a begrudgingly polite Canadian ex-pat living in Boston, finding evil at @Mandiant

가입일 Mayıs 2012
381 팔로잉1.3K 팔로워
Josh Madeley
Josh Madeley@MadeleyJosh·
@cyb3rops If the TA had the privileges to install software, not sure what tool they downloaded and used really matters. Seems “troll-ey” that they picked an open-source forensic tool more than anything else.
English
0
0
3
456
Nick Carr
Nick Carr@ItsReallyNick·
little faster today. 19 miles after work! get it. time for the weekend
Nick Carr tweet media
English
2
0
14
1.4K
Nick Carr
Nick Carr@ItsReallyNick·
marathon training with busy/travel weekends is rough – cramming the long runs in before or after work i genuinely don’t understand how distance runners find the time, aside from just being lots faster than me
Nick Carr tweet media
English
6
0
23
3.7K
Austin Baker
Austin Baker@BakedSec·
I had the great fortune to share a great tool called TIM at @BlackHat Arsenal - and I wanted to share it here with the InfoSec Twitterverse too! TIM (no, it doesn't stand for anything) is a fantastic alternative interface to work with ADX/KQL-accessible data.
Austin Baker tweet media
English
5
28
85
14.6K
Josh Madeley 리트윗함
Ryan Tomcik
Ryan Tomcik@heferyzan·
Thrilled to co-present on cloud threat hunting with the IR legend @MadeleyJosh on June 13th! Tune in to hear: ☁The nuances of hunting in the cloud ☁ How to turn intel into detection/TH opportunities ☁ Case studies on recent compromises Register now: bit.ly/3Vmnstd
English
1
6
20
1.2K
Josh Madeley
Josh Madeley@MadeleyJosh·
@gleeda @ImposeCost This is not to say they can’t benefit from it; just my observations in practice is that they don’t use it that way. Security vendors are exempted from my observations - someone has to build detections at scale.
English
0
0
2
40
Josh Madeley
Josh Madeley@MadeleyJosh·
@gleeda @ImposeCost There probably isn’t a good way. My intuition (and anecdotal experience) is that most blue teamers are not using the POC code to build detections; they are using it to test if the mitigation or patch worked until their is an official vuln scanner detection.
English
1
0
4
201
Jamie Levy🦉
Jamie Levy🦉@gleeda·
How would you propose sharing such things? Because I personally think that blue teamers can benefit from exposure to exploits and POCs. I think they need it in order to better understand the attacks, and a lot of them aren’t able to craft these things themselves in order to study these things. Should these be vetted research groups or … ?
English
1
0
7
1.3K
Josh Madeley
Josh Madeley@MadeleyJosh·
@_Omer_GG @Big_Bad_W0lf_ @cglyer Commercial datasets like Spur attempt to identify them. They are not “great” given the high turnover, but it’s a starting point.
English
1
0
5
221
Omer
Omer@_Omer_GG·
@Big_Bad_W0lf_ @cglyer How does one identify residential proxies with a company that has remote work or hybrid work?
English
2
0
1
199
Christopher Glyer
Christopher Glyer@cglyer·
Additional TTPs from Midnight Blizzard campaign “Due to the heavy use of proxy infrastructure with a high changeover rate, searching for traditional IOCs, such as infrastructure IP addresses, is not sufficient to detect this type of…activity” 👆👆 microsoft.com/en-us/security…
English
2
47
150
43.6K
derekcoulson
derekcoulson@derekcoulson·
@ImposeCost and 26% of its workforce is employed to "fortify its defense against cyber crime"......
English
1
0
1
196
J⩜⃝mie Williams
J⩜⃝mie Williams@jamieantisocial·
I grew up on these streets 🤷‍♂️
J⩜⃝mie Williams tweet media
English
4
0
20
5.7K
Josh Madeley
Josh Madeley@MadeleyJosh·
@PJ47596176 The baby swing is a great touch! I started getting my daughter to count reps!
English
1
0
2
60
Josh Madeley
Josh Madeley@MadeleyJosh·
@brettshavers Maybe I am missing something, but are they saying that IP address based tracking still worked when people were incognito? Was the expectation that client side changes impact server side analytics?
English
0
0
1
49
Brett Shavers 🙄
Brett Shavers 🙄@brettshavers·
I wonder if Google’s ROI justified the $5B settlement…my guess is yes.
English
2
0
1
403
Josh Madeley
Josh Madeley@MadeleyJosh·
@ImposeCost Maple syrup should only come in a glass bottle. Zero exceptions.
English
1
0
2
277
Josh Madeley
Josh Madeley@MadeleyJosh·
@ImposeCost Juxtaposed to a tweet about needing a mobile IV van paints the picture of a wild Friday night.
English
0
0
3
286
Josh Madeley 리트윗함
Doug Bienstock
Doug Bienstock@doughsec·
Today we launched a 🔎 scanning tool for orgs to search their Citrix netscalers for evidence of CVE-2023-3519 post-exploration. You can run this direct on the ADC or against a forensic image. With public POCs out there expect more exploitation! mandiant.com/resources/blog… #DFIR
English
2
32
51
8.4K