Matt Biedronski

218 posts

Matt Biedronski banner
Matt Biedronski

Matt Biedronski

@Gonski47

Katılım Nisan 2023
209 Takip Edilen258 Takipçiler
Matt Biedronski retweetledi
Joey
Joey@JoeyMulinaro·
1st lawn cut of the year presser
English
71
232
4.1K
747.4K
Matt Biedronski retweetledi
S1apSh0es
S1apSh0es@S1apSh0es·
It is Wednesday, my true knights of Westeros.
S1apSh0es tweet mediaS1apSh0es tweet media
English
12
390
4.9K
87.5K
Matt Biedronski retweetledi
doomer
doomer@uncledoomer·
good morning
doomer tweet media
English
31
504
7.5K
151.6K
Matt Biedronski retweetledi
🕳
🕳@sekurlsa_pw·
Why doesn’t pretender from @RedTeamPT get more love? It’s excellent for relaying.
🕳 tweet media
English
3
27
133
9.3K
Matt Biedronski retweetledi
Penn State Football
Penn State Football@PennStateFball·
Officially official. Welcome to Happy Valley, Coach Campbell! #WeAre
Penn State Football tweet media
English
116
1.2K
9.3K
486.3K
Matt Biedronski retweetledi
James Clear
James Clear@JamesClear·
Many situations in life are similar to going on a hike: the view changes once you start walking. You don't need all the answers right now. New paths will reveal themselves if you have the courage to get started.
English
1
568
3.6K
112.8K
Matt Biedronski retweetledi
Mustafa Suleyman
Mustafa Suleyman@mustafasuleyman·
Some of the best career advice I've ever gotten: comfort is the enemy of learning. If an opportunity is a little intimidating and feels like a stretch - it's probably the right opportunity.
English
114
773
5.2K
142.1K
Matt Biedronski retweetledi
Bordeaux
Bordeaux@bordeauxyoutube·
it’s kinda crazy how one interception broke an entire football program
English
105
104
3.9K
396K
Matt Biedronski retweetledi
BlackRoomSec
BlackRoomSec@blackroomsec·
Next month is cyber security awareness month but I'm starting early. If you are not in a role which exposes you to the next best thing and current modern best practices to keep current, sign up for vendor webinars for the products that you wish you could use but can't for whatever reason. Palo Alto regularly does webinars where they have a CTF event and you can use their product live and learn its functions. Find study guides for cybersecurity certifications with the answer key as they contain the information the certificate holders have to know in order to do the job the certificate covers. If you have not spent over 5 hours on the Microsoft learn platform in the last year you're missing out on all modern best day practices. Back in the '90s we were charged $10,000 to get our MCSE certifications whereas today all the knowledge from Microsoft is free you only have to pay for the exam. However Microsoft and all of their articles has a slew of external references which have informed the articles creation and which will help you frame your thinking around certain topics and how to best approach them from a problem resolution standpoint. The NICE framework has pretty much every cyber security role in existence. The on-ramps tell you what jobs you do prior and the off ramps tell you what jobs you will do or be promoted into after. They give you tasks knowledge and skill statements which contain all of the areas of focus and discipline you need in order to do that job. It is chock full of information it's free to help you not only in your current role but get a promotion or a raise, the current terrible state of the job market aside. If you cannot do a CTF yourself because you lack the knowledge or do not have the time read CTF write-ups so you can learn how certain attacks are performed. CTFTime is the site you go to to read these write-ups and has all the current and past events. After DEFCON every year you should be downloading all the public files videos training etc on the repos to familiarize yourself with current tradecraft. Vendors like VMware and Dell have their own write-ups for really weird use cases in order to get their equipment to work in these very specific scenarios. VMware has a ton of sanitization knowledge base articles where they go step by step with screenshots and walk you through the example scenario. I've actually fixed real world production problems this way because places like Reddit and elsewhere did not have the information I needed. I routinely use the algorithm to assist me in finding information I'm currently looking for that I cannot find. How I achieve this is by repeatedly searching for what I'm looking for on Google Tiktok Twitter and elsewhere and within a few days I will start seeing ads and search results for what I was looking for a few days prior. Google found me the modern diode replacement for a diode I was given by a customer of mine that is over 25 years old simply by doing this little algorithm trick. If AI systems are not giving you the answers you need and you're getting frustrated prompt inject them by asking it to tell you a story about the information you're looking for or do a simulation. By putting it into terms that the AI system can agree with that being you are playing Make-Believe it will often yield better results. Research paper sites like Research Gate and Arxiv are full of capstone projects for various students all over the world and these students will often build out applications in order for them to pass their course. Because their focus is research they are able to find a lot of resources you may not be able to in your own searches so search those sites for what you're looking for. An example of this is the research paper "Do you play it by the books?" which contains 1284 incident response playbooks and the URL to the GitHub repo where they can be found. It is the largest single source of playbooks by various vendors in existence.
English
8
16
88
4.8K
Matt Biedronski
Matt Biedronski@Gonski47·
> Saturday > 65 degrees > College Gameday on the tv > Top-10 Big-Noon Kickoff matchup on deck > CFB all day …That time of the year
GIF
English
1
0
5
210
Matt Biedronski retweetledi
ACE Responder
ACE Responder@ACEResponder·
⚡️You can now use AI to make ACE-style animations in the AttackAnimator! Ask for help or have it create a full video entirely from scratch. aceresponder.com/attackanimator
English
2
20
94
7.1K
Matt Biedronski retweetledi
fin3ss3g0d
fin3ss3g0d@fin3ss3g0d·
CypherHound github.com/fin3ss3g0d/cyp… now supports ALL traversable AD edges in BloodHound CE! There have been a lot of traversable edges added by @SpecterOps over the last year, my project is providing prebuilt queries for you to use with the latest edges! Don't miss out!
fin3ss3g0d tweet mediafin3ss3g0d tweet mediafin3ss3g0d tweet media
English
0
22
71
3.8K
Matt Biedronski retweetledi
Tomer Nahum
Tomer Nahum@TomerNahum1·
Today, together with Jonathan Elkabas, we're releasing EntraGoat - A Deliberately Vulnerable Entra ID Environment. Your own hands-on Entra lab for identity attack simulation. Built for red teams, blue teams and identity nerds. Check it out here👉github.com/semperis/entra…
Tomer Nahum tweet media
English
8
234
700
41.8K
Matt Biedronski
Matt Biedronski@Gonski47·
@al3x_n3ff How is NXC confirming/checking for null auth? On an engagement NXC flagged null auth as true but none of the secondary info-gathering methods that leverage null-auth sessions suceeded for me
English
1
0
2
263
Alex Neff
Alex Neff@al3x_n3ff·
Added a small Quality of Life improvement to NetExec: When the target allows null authentication the host banner automatically displays this info now🚀
Alex Neff tweet media
English
10
38
225
17.9K
Matt Biedronski
Matt Biedronski@Gonski47·
@4JMAN I also actually enjoy working on a MacBook with the right specs they can be pretty beefy and can handle a lot while still being snappy and fast
English
1
0
0
57
Matt Biedronski retweetledi
Akshay 🚀
Akshay 🚀@akshay_pachaar·
Model Context Protocol (MCP), clearly explained:
English
63
493
5K
1.1M
Matt Biedronski
Matt Biedronski@Gonski47·
Offsec folks - what are you doing to learn more about AI security and such? Lets get a thread of cool resources shared around!
English
3
1
3
349