Korstiaan

299 posts

Korstiaan banner
Korstiaan

Korstiaan

@KorstiaanS

Founder of Invictus Incident Response @InvictusIR | DFIR enthousiast | https://t.co/qgFI02Nro1

Katılım Ekim 2010
325 Takip Edilen474 Takipçiler
Korstiaan retweetledi
Invictus Incident Response
Invictus Incident Response@InvictusIR·
📷 The SaaS Hardening Checklist: - Kill "Shadow Consent" – Disable user consent and implement an Admin Consent Workflow. No unvetted app should touch your data. - Audit Permissions – Understand Delegated vs. Application-level access to ensure the principle of least privilege. - Restrict App Access – Require explicit user assignment on first-party apps to block attackers from exploiting "trusted" tools. - Enforce Hygiene – Build application cleanup into your standard off-boarding process. Read the full breakdown: invictus-ir.com/news/the-silen… #StayInvictus #SaaS #CloudIncidentResponse #EntraID
English
1
2
8
1.6K
Korstiaan
Korstiaan@KorstiaanS·
Blog coming soon
Invictus Incident Response@InvictusIR

🚨Axios Attack Infrastructure Update🚨 New C2 pivots reveal a coordinated staging effort. The malicious payload was published by nrwise@proton[.]me a separate account from the ifstap proton address used in the maintainer hijack. Analysis shows a newly identified and highly likely C2 callnrwise[.]com on the same infrastructure used in the #Axios attack, sharing clear naming similarities with the attacker's Proton account. #npm #SupplyChainAttack

English
0
0
2
91
Korstiaan retweetledi
Invictus Incident Response
Invictus Incident Response@InvictusIR·
Happy is an understatement! This year we will be teaching both our AWS and Microsoft Cloud IR course at @BlackHatEvents in Las Vegas. Grateful for this opportunity!
Invictus Incident Response tweet mediaInvictus Incident Response tweet media
English
0
1
3
305
Korstiaan retweetledi
Invictus Incident Response
Invictus Incident Response@InvictusIR·
🧪New year, new lab, same quality! Another lab inspired on real life incident response cases. If you've worked on incidents in Entra ID you probably know the importance of 𝘌𝘯𝘵𝘦𝘳𝘱𝘳𝘪𝘴𝘦 𝘈𝘱𝘱𝘭𝘪𝘤𝘢𝘵𝘪𝘰𝘯𝘴 and 𝘈𝘱𝘱 𝘙𝘦𝘨𝘪𝘴𝘵𝘳𝘢𝘵𝘪𝘰𝘯𝘴. This lab is a deep dive on a lot of different techniques attackers abuse around apps in Entra. #stayInvictus #CloudLabs #CloudIncidentResponse
Invictus Incident Response tweet media
English
0
2
6
409
Korstiaan
Korstiaan@KorstiaanS·
@UID_ Als je ergens een vast adres hebt dan kan ik je swag updaten
Nederlands
1
0
0
34