Ryan Andorfer

825 posts

Ryan Andorfer banner
Ryan Andorfer

Ryan Andorfer

@Randorfer

Tanium - VP, Cloud Engineering

Katılım Ağustos 2009
182 Takip Edilen230 Takipçiler
Ryan Andorfer
Ryan Andorfer@Randorfer·
@Delta booked first class with infant and grandparents. Arrived to check in this morning and the grandparents are downgraded to delta comfort without notification and after getting a confirmation. Help!
English
0
0
0
26
Ryan Andorfer retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
My Signature Creation Mind Map Input: Sample > the things that I check to create YARA signatures, Sigma rules or IOCs > or pivot to related samples in order to improve the signatures / rules
Florian Roth ⚡️ tweet media
English
10
345
1K
0
Ryan Andorfer
Ryan Andorfer@Randorfer·
@davehull Do what only you can do. Drop the ball and let others pick it up, they will appreciate the opportunity. Figure out what actually motivates you in life, make sure your work goals align to that. Talk to Egon for a refreshing perspective.
English
0
0
0
0
Ryan Andorfer
Ryan Andorfer@Randorfer·
2/2 Yesterday we were told that they would be looking at ways to mitigate the problem more. Today, it looks like the bypass they had in place has been dammed up. Is this just temporary I hope?
Ryan Andorfer tweet mediaRyan Andorfer tweet mediaRyan Andorfer tweet media
English
0
0
0
0
Ryan Andorfer
Ryan Andorfer@Randorfer·
1/2 @MayorShepHarris thank you for personally coming out yesterday to help ensure everything that should be done is being done to protect the homes of Bassett Creek during the bridge construction. @LindaIHiggins do you know what is going on with the project?
Ryan Andorfer tweet media
English
1
0
0
0
Ryan Andorfer retweetledi
Jessica Payne
Jessica Payne@jepayneMSFT·
At least once a week we encounter a case of lateral movement using off the shelf tools like psexec, command line utilities, or eternal blue. You can stop all of them from moving laterally by blocking SMB and RPC between endpoints using the Windows Firewall channel9.msdn.com/Events/Ignite/…
English
11
148
402
0
Ryan Andorfer retweetledi
Jessica Payne
Jessica Payne@jepayneMSFT·
Windows Event ID 4624 displays a numerical value for the type of login that was attempted. These numbers are important from a forensic standpoint but also for understanding credential exposure and mitigating risks. Descriptions in replies.
English
20
553
1.5K
0
Ryan Andorfer retweetledi
Jessica Payne
Jessica Payne@jepayneMSFT·
Have a practice IR. This may look different than you’re expecting. Can you: 1) deploy software or a script to ALL endpoints without errors? 2) identify all your endpoints? 3) know what your patch or configuration deployment status is for a basic item like KB2871997 or a GPO?
English
4
28
116
0
Ryan Andorfer
Ryan Andorfer@Randorfer·
@poshboth @sstranger Function Get-ArrayListOutput { Param() $null = $( $arraylist = new-object -TypeName System.Collections.ArrayList $arrayList.Add('First') $arrayList.Add('Second) ) return $arrayList } Get-ArrayListOutput return control from functions
English
0
0
0
0
Ryan Andorfer retweetledi
John Lambert
John Lambert@JohnLaTwC·
In Pike Place Market, you may have come across the Market Penmaker. He made pens and mechanical pencils from woods around the world. I have given them as gifts to friends and acquaintances. He died last month, but I thought his work so beautiful I wanted to share it.
John Lambert tweet media
English
1
8
58
0
Ryan Andorfer retweetledi
Nick Carr
Nick Carr@ItsReallyNick·
Fun fact: the WMI EventFilter registered by this #DailyScriptlet for persistence leverages TargetInstance.SystemUptime to specify a launch time range (in seconds). For malware, the range is often chosen to allow the system to fully boot then launch once. Method in Vault 7 leak. twitter.com/ItsReallyNick/…
Nick Carr@ItsReallyNick

How about a #DailyScriptlet with spicy VBS obfuscation using split, eval, and chr arithmetic Launches: 1⃣ Metasploit-style shellcode 2⃣ Registry persistent remote mshta 3⃣ WMI persistent #squiblydoo [pictured] cc: @cglyer "reg9.sct" uploaded this week: virustotal.com/#/file/5960880…

English
2
74
158
0
Ryan Andorfer retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Poor pentesters, getting up every day to discover & report that software is broken & security concepts are flawed. It takes some time to realise that it'll always stay that way. Become a defender! We kick ass, fight back real adversaries & ruin the day of criminal scumbags.
GIF
English
15
92
262
0
Ryan Andorfer retweetledi
bohops
bohops@bohops·
[Blog] Abusing DCOM For Yet Another Lateral Movement Technique ....unsophisticated, but may have some utility wp.me/p7MIao-6H
English
2
94
172
0