Tory☁️

4.4K posts

Tory☁️ banner
Tory☁️

Tory☁️

@KoredeSec

Cybersecurity & Cloud || @nacss_uniosun President || Security, systems, and people.

127.0.0.1 but root Katılım Mart 2020
378 Takip Edilen636 Takipçiler
Sabitlenmiş Tweet
Tory☁️
Tory☁️@KoredeSec·
🚀 My Cybersecurity Project: Built a Cloud Honeypot + Automated Response with Microsoft Sentinel 💥 Tracked real attackers, logged their data, and triggered auto-alerts all in the cloud ☁️ Here’s a full breakdown of how I did it 👇 A Thread 🧵 @ireteeh @akintunero @OnijeC
Tory☁️ tweet mediaTory☁️ tweet media
English
5
10
69
7.8K
Tory☁️ retweetledi
0xDamian
0xDamian@damnsec1·
Half an hour ago, I was setting up Vulnbank (by @commando_s) on a VPS and watched an automated attack happen. I identified and analysed the attack and mitigated it. Here's how it works: - It scans the entire internet for open port 5432 (postgres) and default creds. - Once it gets in, it fires an obfuscated bash script that has a custom curl command, kills competitor malware on the machine (lmao), does some cleanup and sandbox detection. - Then, it downloads malware from the attacker's C2 server and attempts to execute it. Not sure what the executable does yet. Anyway, port 5432 does not even have a rule in my inbound firewall settings, but the `docker-compose.yml` file in the Vulnbank repo had a particular line that bypasses the firewall entirely: `"5432:5432"` which binds it to 0.0.0.0 So I edited it to `"127.0.0.1:5432:5432"` I did that because the `127.0.0.1:` prefix binds the port to localhost only instead of all interfaces, so it's no longer reachable from the internet even though Docker bypasses the firewall. And then I rebuilt the container. Docker did its job and contained the attack tbh. So make sure you dockerise Vulnbank or any other lab, just in case. ILY.
0xDamian tweet media
English
3
5
23
936
Tory☁️ retweetledi
Freddy
Freddy@AlfredoTaGinci·
Neymar was so good, Perez is out here signing every Brazilian wonderkid he hears about cause he fears missing out on the next Neymar. I love Rooney but Sheikh Mansour ain't never worried about missing no next Wayne
English
37
1.6K
15.2K
214.6K
Tory☁️ retweetledi
aitch
aitch@hackysterio·
in all of these, just make sure you are happy. make sure you are getting paid. very important. like i always say, nobody go actually help you. nobody like you like that. you have to fight for your head. ❤
English
0
1
7
84
Tory☁️ retweetledi
Henry
Henry@realhenry_x·
Day 42/#100daysofcybersecurity I engaged in a checkpoint exam today covering all the modules I've been studying these days and I got 76%/100% @ireteeh @KoredeSec @adekunle_443 @Dstixx05
Henry tweet media
Henry@realhenry_x

Day 41/#100daysofcybersecurity Today I dived into the Ipv4 address structure, I got to know more about Ipv4. Then I proceeded to do the quiz under module 6 and got 92% I also did a revision on what I've learnt so far. @ireteeh @KoredeSec @Dstixx05 @Azutech_ @confirmedHOD

English
0
1
14
72
Tory☁️ retweetledi
Akin Olaoye
Akin Olaoye@akintollgate·
I grew up learning how certain Nigerian families were very strategic. A daughter studying law and becoming a magistrate court judge. A son joining the army and coming a young captain. A daughter studying finance with an MBA and working for a top bank. The last born studying medicine to become a heart surgeon. They are all in the pinnacle of their careers as a high court judge, Major General, Bank CFO and top heart surgeon with a large hospital. Their father was an Oil & Gas executive and their mum was a retired principal turned politician and later became a commissioner. Be intentional with your offsprings! E get why…….The devil doesn’t always have your time!
English
93
512
3.4K
169.8K
Tory☁️
Tory☁️@KoredeSec·
A serotonin drop would heal me rn🥹
English
1
0
1
53
Tory☁️ retweetledi
Henry
Henry@realhenry_x·
Day 41/#100daysofcybersecurity Today I dived into the Ipv4 address structure, I got to know more about Ipv4. Then I proceeded to do the quiz under module 6 and got 92% I also did a revision on what I've learnt so far. @ireteeh @KoredeSec @Dstixx05 @Azutech_ @confirmedHOD
Henry tweet mediaHenry tweet media
Henry@realhenry_x

Day 40/#100daysofcybersecurity Pushed into Module 5: Network Layer Covered Network Layer Characteristics, then deep into IPv4 Packet (headers, fields, TTL, etc.), IPv6 Packet, extension headers @ireteeh @confirmedHOD @KoredeSec @Dstixx05 @Azutech_ @adekunle_443 @MRM_Cyber

English
0
3
16
249
Tory☁️ retweetledi
Cisco Nerd
Cisco Nerd@OnijeC·
I SAY NO TO RAPE ❗️❗️❗️ I SAY NO TO RAPE ❗️❗️❗️ I SAY NO TO RAPE ❗️❗️❗️ I SAY NO TO RAPE ❗️❗️❗️ I SAY NO TO RAPE ❗️❗️❗️ I SAY NO TO RAPE ❗️❗️❗️ I SAY NO TO RAPE ❗️❗️❗️
English
3
34
64
1.4K
Tory☁️ retweetledi
Ezechi Jeremiah
Ezechi Jeremiah@cyberjeremiah·
Day 70-72/100 #100DaysOfCyberSecurity 70-71 - Crazy days at work 72 - I started my study with Microsoft Entra ID them pivoted to carrying out an investigation on Detecting Data exfiltration and Lateral Movements @jay_hunts @segoslavia @_DeejustDee
Ezechi Jeremiah tweet mediaEzechi Jeremiah tweet mediaEzechi Jeremiah tweet mediaEzechi Jeremiah tweet media
Ezechi Jeremiah@cyberjeremiah

Day 69/100 #100DaysOfCyberSecurity Todayyy. I learnt more about Kerberos Authentication In AD Servers. I also has a hands on lab on how to detect Credential Harvesting Attack Patterns @jay_hunts @segoslavia @_DeejustDee

English
0
5
25
625
Tory☁️ retweetledi
Cisco Engr
Cisco Engr@ciscoengr·
If you want to start building some hands on projects just after you have gone through the basics in cyber security and Networking, I adviyyou to head on to u.cisco.com especially if you are into Network Security and clouds You will see many hands on there. @OnijeC @CiscoNetAcad
Cisco Engr@ciscoengr

I built a DNS monitoring lab using Cisco ThousandEyes to understand how domains resolve globally and what that means for security. Tested google.com across multiple regions and analyzed: Availability (100%) → DNS successfully resolved in all locations Query Time (~44ms) → how fast DNS responds (affects app speed & user experience) DNSSEC (0% validity) → no cryptographic validation of DNS responses Quick breakdown: - DNS (Domain Name System) = translates domain names → IP addresses. - DNSSEC = adds security to DNS by preventing spoofing/tampering. - Latency (query time) = delay in DNS response Why this matters (Security Angle) Without proper DNS security: - Attackers can perform DNS spoofing (redirect users to malicious servers) - DNS hijacking can silently reroute traffic - Lack of validation = higher risk of MITM attacks Outcome This project helped me move beyond basic networking into: - Network visibility - Security monitoring - Detection thinking Full project + breakdown : github.com/cybergabby/DNS… #Cybersecurity #NetworkSecurity #DNS #SecurityEngineering #Cisco #LearningInPublic @OnijeC @EhistheGreat @cyber_razz @cyber_rekk @akintunero

English
0
11
91
4.2K