Christopher Crowley

6.7K posts

Christopher Crowley banner
Christopher Crowley

Christopher Crowley

@CCrowMontance

InfoSec Ops Generalist: NSM, IR, Mobile, PenTest, Forensics. SOC-Class Author. (https://t.co/QBKm4Ub7ka). SANS Senior Instructor. Retweets unverified. #infoseclatteart

planet earth Katılım Haziran 2012
3.1K Takip Edilen6.7K Takipçiler
Sabitlenmiş Tweet
Christopher Crowley
Christopher Crowley@CCrowMontance·
The 2025 SOC Survey is now live. Please retweet and share. If you work in a SOC or something that vaguely resembles a SOC, please take it. Finally, please take the whole thing to demonstrate the value of longer surveys. You can pause and return. survey.sans.org/jfe/form/SV_8o…
Christopher Crowley tweet media
English
1
0
1
615
Jake Williams
Jake Williams@MalwareJake·
Mountain coaster time in Helen, GA.
Jake Williams tweet media
English
6
1
88
3K
Christopher Crowley
Christopher Crowley@CCrowMontance·
@HackingLZ Hell yeah. Defenses are genuinely working! There is still a universe of exploitable systems, though. Lots left to do. Some of it is easy, most of it is hard.
English
0
0
0
49
Justin Elze
Justin Elze@HackingLZ·
InfoSec had the same COVID era overhiring problem as the rest of tech especially entry level OffSec. The job getting harder isn’t gatekeeping, it means defenses are working and the work demands real R&D. Meanwhile, vuln assessments and low-level pentesting are exactly the kind of work automation and agents are designed for.
English
13
2
192
15.2K
Christopher Crowley retweetledi
SANS Institute
SANS Institute@SANSInstitute·
40% of SOCs use AI without defining where it belongs operationally. 42% run it out of the box with no customization. That’s why so many teams feel stuck. In this @TheHackersNews piece, SANS senior instructor Christopher Crowley (@CCrowMontance) explains where AI helps, where it doesn’t, and why discipline matters more than tooling: thehackernews.com/2025/12/how-to…
English
0
2
4
1K
Christopher Crowley
Christopher Crowley@CCrowMontance·
Exploitation required ... custom Deflate compressor, tailored Huffman codes ... output restricted to valid modified UTF-8 bytes (0x01-0x7F) while remaining incompressible by zlib, enabling the payload to survive a double-compression pipeline intact. slcyber.io/research-cente…
English
0
0
1
231
Christopher Crowley
Christopher Crowley@CCrowMontance·
@cyber_rekk Yes & no. Lots of cyber security jobs can be done by AI/ML. But, there is not enough human attention deployed to cyber security currently. I see a net stable count, with substantial reskilling requirement to stay in cyber. ( soc-survey.com for published details )
English
0
0
1
78
Christopher Crowley
Christopher Crowley@CCrowMontance·
@vxunderground Nobody needs to do anything. I was sitting at a vendor event at a big conference a few years ago talking with one of their employees having a great time. The marketing manager came over and told us we needed to circulate with the guests because that's what we were there for. lulz
English
0
0
0
46
vx-underground
vx-underground@vxunderground·
I guess being a stinky nerd isn't approachable to other companies that want cybersecurity stuff. I get it. But, I don't know bro, you gotta loosen up a little
English
9
0
146
12.6K
vx-underground
vx-underground@vxunderground·
There is a huge disconnect between the suits that run information security places and have money versus the nerds that are employed there Over the years I've had a few cybersecurity companies approach me and discuss potential collaboration. Each time it was super PG, watered down, boring, and generic. They were extremely concerned over my behavioral mannerisms, the ideas I recommended, etc. because they were not "brand safe". In other words, it was too nerdy schizo and not B2B sales fluff junk I get it, the suits want money, or whatever. But dawg, if you want to actually communicate and reach out to nerds and be approachable, you cannot sound like a fucking infomercial. You have to be an actual human being and actually give a fuck about shit. As an example, one time a vendor wanted to do a collaboration and sponsor a vx-underground merchandise giveaway. The idea was quickly shutdown when they realized the vx-underground 5 year anniversary swag had a pixelated woman with her breasts slightly exposed which displayed a pixelated nipple. The attached image is the image they were concerned about. They were afraid it was too pornographic.
vx-underground tweet media
English
53
34
580
37.5K
Christopher Crowley
Christopher Crowley@CCrowMontance·
@vxunderground How about agreeing to take money and do a comparative analysis? They pay for your time and to produce a paper. They can choose to publish or not. I have done several product analysis projects the vendor chose not to publish. 🤷🙊 But I got paid.
English
0
0
0
104
vx-underground
vx-underground@vxunderground·
A large VPN provider reached out to me. They were wanting to do some stuff together to reach the cybersecurity audience, or something. The primary reason I don't do ads, while I very much enjoy having money, is because I can't in good faith recommend a product to my audience which I cannot in totality stand behind. vx-underground's success is partially due to transparency, honesty, admitting mistakes, and willingness to accept fault and/or responsibility. I believe there is a shift in the VPN-sphere whereas some providers are trying to capture a more cybersecurity attentive audience. That's cool. Do your thing homie. I understand the VPN business is rough and your company is always on the grind to make money. No hate. However, I can't deceive my audience because they're the only reason I have success Thank you for the love and support despite my many (MANY) faults, mistakes, typos, repetitive corrections and updates, unnecessarily crass tone when writing, failed and/or abandoned vx-underground experiments, etc. I have no idea what the fuck I'm doing and why so many people follow this account. But we're riding this bitch, dawg Ride and die malware ✊(I'm scared and confused)
English
59
50
1.6K
93.9K
Christopher Crowley
Christopher Crowley@CCrowMontance·
AI is going to deprecate those who don't adapt. In response to this morning 's message from Bloomberg:
Christopher Crowley tweet media
English
0
1
1
258
Christopher Crowley
Christopher Crowley@CCrowMontance·
Dear @Google - just last year, Gmail seamlessly updated my Google calendar with items from email. Now, ten prompts later with Gemini, I still don't have correct calendar entries. Much worse. That's the only way to describe it. Fix it, or revert it to the working assistant.
English
0
0
0
280