BaffledJimmy

414 posts

BaffledJimmy

BaffledJimmy

@BaffledJimmy

Katılım Kasım 2017
230 Takip Edilen463 Takipçiler
BaffledJimmy
BaffledJimmy@BaffledJimmy·
@SEKTOR7net Thanks for the shoutout dude 👍🏻👍🏻 it's MacDonald but all good 😝)
English
0
0
4
139
Shawn
Shawn@anthemtotheego·
@chvancooten @MarcOverIP @capt_red_beardz Nice! Our talk focused on team R&D. From tracking of operational/tooling gaps, prioritization, standards, automation, focused team efforts, etc. Basically how you do the most important part of red teaming… work as a team.
English
1
0
2
139
Shawn
Shawn@anthemtotheego·
Seeing these posts on R&D and its place in red teaming really makes me wish @capt_red_beardz and my talk on this very subject got accepted. There’s a ton to unpack here and a lot of lessons learned. I can’t overstate the importance of R&D as the industry moves forward.
English
2
8
39
4.3K
BaffledJimmy retweetledi
Josh
Josh@passthehashbrwn·
A bunch of nerds: Your code needs to be memory safe to move the industry forward Every CVE in 2024: if you add a funny character to this URL parameter you can execute commands as root
English
10
225
2.1K
124.7K
assume_breach
assume_breach@assume_breach·
With this season of Hell's Kitchen being over, I thought I would do a follow up to my post based on some of the feedback I got. I won't do another one. Next Level Chef starts this week. link.medium.com/o6xG0vaBOGb
English
7
28
138
50.4K
Dominic Chell 👻
Dominic Chell 👻@domchell·
I mean, the majority of TTPs we see in threat intel reports would not be successful against any average maturity org. The reason we hear about them is because they got detected. I don't believe they are representative of the TTPs used by any Expert adversary (where Expert is defined by STIX). Putting aside the cred stuffing type stuff (which again I think most average maturity clients have got handled), I challenge anyone to try replaying the TTPs in the CISA reports against CrowdStrike, SentinelOne, MDE or any of the other major EDRs and see how far they get.
English
5
13
72
22.8K
Justin Elze
Justin Elze@HackingLZ·
Watching people's responses to offensive testing getting more challenging year over year when that is the entire point is entertaining. The idea of git clone pwn fading and the realization there are ongoing investments in R&D or acquiring paid tooling isn’t easy. It was always about raising the bar.
English
7
12
92
19.3K
BaffledJimmy
BaffledJimmy@BaffledJimmy·
@HackingLZ Most red team people have no clue on how to build enterprise cyber resiliency at scale. They believe bypassing EDR is the be all and end all. It's an enabling action. Most clients treat RT as point in time activities rather than 'how _could_ this play out'.
English
0
0
1
403
Justin Elze
Justin Elze@HackingLZ·
What infosec opinion(please no OST😂) has you like this?
Justin Elze tweet media
English
79
11
120
500.5K
BaffledJimmy retweetledi
wallfacer
wallfacer@simplylurking2·
I'm going to release a realistic red teaming course where we just read Confluence, wikis, shares, and git repos all day and write reports for several hours at the end.
English
3
6
51
3.3K
BaffledJimmy retweetledi
James D
James D@FranticTyping·
Scaling detection and response operations at Coinbase part 2 & 3: 🔍 Driving context into detection logic with machine and user profiles 🔧 Codifying automatic remediation for high-risk detections 📫 Automating alert triage with employees via Slackbot coinbase.com/blog/scaling-d…
English
1
31
79
8.9K
BaffledJimmy retweetledi
Sanjiv Kawa
Sanjiv Kawa@sanjivkawa·
I’ve just publicly released SQLRecon v3.3. This release includes many features that were used privately by the @xforcered Adversary Services team on real-world red team operations. Please share, enjoy, and use responsibility. Hmu if you have any questions! github.com/xforcered/SQLR…
English
1
80
231
26.1K
Tim
Tim@__invictus_·
@HackingLZ I'll only use this if they make it so one eye is looking at the camera whilst the other is looking away
English
1
0
4
353
Adam Chester 🏴‍☠️
@chompie1337 Fuck I’ve got all of my fingers done and back of my hands being done this year… guess it’s these kinds of companies we wouldn’t wanna work at anyway :/
English
2
0
12
2.1K