Nick Attfield

36 posts

Nick Attfield

Nick Attfield

@AttfieldNick

Threat Research. Views/opinions are my own.

Katılım Ekim 2019
210 Takip Edilen109 Takipçiler
Nick Attfield retweetledi
Greg Lesnewich
Greg Lesnewich@greglesnewich·
Fun crossover blog about TA829 (RomCom) & TransferLoader with my ecrime pals it’s got everything: 🛰️ Popped routers for sending phish 📊 ACH on attribution 👾 custom protocols 👽 cool malware 🕵️ crime 🎯 espionage ❔many unanswered questions proofpoint.com/us/blog/threat…
English
3
17
65
11.7K
Nick Attfield retweetledi
Nick Attfield retweetledi
Pasquale Stirparo 🌻🇺🇦
And we are back 😎 , #SaveTheDate folks, we are counting on blowing your mind (again) with a great event filled with top-notch content at #PIVOTcon25. #CTI #ThreatIntel #Malware #Geopolitics #ThreatHunting #Cybercrime
PIVOTcon@pivot_con

#SaveTheDate 🚨🚨🚨#PIVOTcon25 is coming: 7-9 May 2025 👀👀👀 Book your calendars to sit with us on the #yellowsofa and listen to the top threat intelligence research and analytical pivots 💪 #CTI #ThreatIntel New venue ⬇️ 🇪🇸 🏖️ 1/3

English
2
14
46
4.4K
Nick Attfield
Nick Attfield@AttfieldNick·
Stoked to announce that I’ll be joining the APT crew at Proofpoint as a researcher! Time to ruin some ops 💪🏼
English
10
4
97
10.6K
Nick Attfield
Nick Attfield@AttfieldNick·
@greglesnewich Been looking forward to this for a long time! What a crew to join, getting to learn from and work with some of the best 💪🏼 Time to run it up 😮‍💨🙏🏻
English
0
0
1
48
Greg Lesnewich
Greg Lesnewich@greglesnewich·
But now the cavalry arrives on Monday and we are so so so stoked 🎉💪 We’ve got a list of adversaries who’s R&D we gotta waste, budgets we’ve gotta run up tabs on, and ops to ruin Can’t wait to get after it with this crew 😤
English
3
0
40
2.5K
Greg Lesnewich
Greg Lesnewich@greglesnewich·
Proud story thread time 😊 For a little over a year, our APT team has been reduced to 2 researchers working to track and disrupt espionage campaigns. Folks move on and we still ❤️ them. But it was hard
English
3
0
71
6.6K
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
Big companies have lots of talented people, each with their own ideas about the right things to do, best paths forward, top strategies for this or that. It must be tough to decide who to trust, which ideas to bet on, when to dump old things and where to embrace new hotness.
English
3
3
40
3.9K
Nick Attfield retweetledi
J. A. Guerrero-Saade
J. A. Guerrero-Saade@juanandres_gs·
This was the most important tough love keynote CTI has needed to hear and desperately needs to digest, otherwise “…reorgs will continue until perception of value improves” (h/t @invisig0th) #PIVOTcon24 #TheFanciestBear
J. A. Guerrero-Saade tweet media
English
1
19
72
9.8K
Nick Attfield
Nick Attfield@AttfieldNick·
Officially looking for work in the CTI space. Happy to have a chat about roles! I’ve been a power user of Synapse from @vtxproject for over a year in an enterprise setting as well.
English
2
25
34
15K
Nick Attfield retweetledi
Brian Bartholomew
Brian Bartholomew@Mao_Ware·
Officially on the job market today. Anyone looking for an old TI guy with a "smidge" of years under his belt, let me know. Happy to have a chat.
English
5
47
90
43.2K
Nick Attfield retweetledi
Jamie Collier
Jamie Collier@TheCollierJam·
The #VulkanFiles highlights the inadequacy of most Western conceptual frameworks for capturing how states approach cyber operations. A 🧵...
English
2
17
37
17.8K
Nick Attfield retweetledi
Danis Jiang
Danis Jiang@danis_jiang·
Here is my demo of the VM escape exploit on the latest version of VMware Fusion along with ESXi and Workstation. It was used to participate in GeekPwn 2022 and won the championship.
English
23
280
1.5K
0
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
[ 542,663 edits on 108,175 nodes ] Not bad, for a minute's worth of work.
English
2
3
17
0
Nick Attfield retweetledi
Danny Kemp
Danny Kemp@dannyctkemp·
BREAKING - Dutch intelligence services say they prevented a Russian spy from accessing the International Criminal Court in the Hague as an intern. The man was working under a Brazilian identity but actually belonged to the GRU - @AFP
English
239
5.5K
22.1K
0
Nick Attfield retweetledi
Kevin Kohler
Kevin Kohler@KevinKohlerFM·
Here’s an overview of what has happened on the cyber front so far in Ukraine 🧵
English
26
888
2.4K
0
Nick Attfield retweetledi
cyint_dude @cyint_dude@infosec.exchange
#threatintel 🧵: In scenarios where cyber threat activity that is relevant to your org overlaps with geo-political tensions, it is important to clearly distinguish the parts of your assessment that are uniquely yours, and those you derive from other sources (1/x)
English
1
18
54
0
Nick Attfield retweetledi
Loránd Bodó
Loránd Bodó@LorandBodo·
There are several Twitter search operators one can use, such as these two: 1. within_time:3h 2. filter:news e.g. "Merkel" within_time:3h filter:news -> will give you Tweets with "Merkel" from the last 3 hours & a link to a news article. Give it a try. #OSINT #research #news
English
3
53
182
0
Nick Attfield retweetledi
Shane Huntley
Shane Huntley@ShaneHuntley·
New TAG post on Countering Threats from Iran blog.google/threat-analysi… Aim is to provide some new details on what Ajax and the team discovered and blocked from APT35 (also known as Rocket Kitten and some other names)
English
1
42
88
0