Sam ☁️🪵

2.4K posts

Sam ☁️🪵 banner
Sam ☁️🪵

Sam ☁️🪵

@Sam0x90

SOC/Intel | @SANSInstitute | @PacktAuthors https://t.co/itz9Mly1hK Love #PurpleTeaming #DE #CTI #DFIR

EMEA Katılım Ocak 2010
780 Takip Edilen1.1K Takipçiler
Sabitlenmiş Tweet
Sam ☁️🪵
Sam ☁️🪵@Sam0x90·
💜Adversary Simulation and Purple friends💜 I'm happy to share this simulation plan which regroups a TOP 35 @MITREattack TTPs from 22-23. Based on open source intel, it's meant to ease the onboarding of more into Purple! Have a look at the readme #CTI #TTP github.com/Sam0x90/CTI/tr…
Sam ☁️🪵 tweet media
English
10
103
383
74.9K
Sam ☁️🪵
Sam ☁️🪵@Sam0x90·
@RussianPanda9xx We got the wedding planned and all with sponsorship from eLS but you walked away 🤣💔
English
0
0
0
56
Sam ☁️🪵 retweetledi
Georgy Kucherin
Georgy Kucherin@kucher1n·
It turned out there are many more payloads used in the Notepad++ attack! To stay undetected, its masterminds were COMPLETELY changing execution chains about every month. Here are more IPs used in the attack: 45.76.155[.]202 45.32.144[.]255 Read below for many other IoCs! [1/8]
Georgy Kucherin tweet media
English
19
236
1.2K
106K
Sam ☁️🪵 retweetledi
MoBustami
MoBustami@MoBustami·
Happy New Year everyone. I wrote something sec0wn.blogspot.com/2026/01/from-n… Do I get an honorary #OSEP for analyzing their payloads? Lol. Maybe Gemini should though. H/T to GeminiPro for the assist
English
1
1
4
139
Sam ☁️🪵
Sam ☁️🪵@Sam0x90·
@chrissanders88 I like it because it shows immediately if someone works with logs everyday, you can't fake an answer. Usually good answers turn around 4688/sysmon 1, 4624, sysmon 3, I heard 1102 too.
English
0
0
3
523
Chris Sanders 🔎 🧠
Chris Sanders 🔎 🧠@chrissanders88·
@Sam0x90 That's a fascinating question. What was your answer, or the best answer you've heard to this one?
English
1
0
0
956
Chris Sanders 🔎 🧠
Chris Sanders 🔎 🧠@chrissanders88·
What's the best interview question you've been asked (or used) for a SOC Analyst/Forensic/Hunting/Threat Intel role?
English
15
13
105
18.8K
Sam ☁️🪵
Sam ☁️🪵@Sam0x90·
@banthisguy9349 Just go for it. If you think, it's not "novel", it's not trendy or someone did it already years ago, etc don't listen to those thoughts, just go for it and enjoy sharing!
English
0
0
0
53
Fox_threatintel
Fox_threatintel@banthisguy9349·
I might create my first blog. What topics should I cover? Also if their are any leads, feel free to dm
English
8
1
17
3.4K
Sam ☁️🪵
Sam ☁️🪵@Sam0x90·
GG @_dirkjan ! I wish to see more of this in the future: "After some testing and filtering with some fellow researchers that work on the blue side we came up with the following detection query" 👏
Dirk-jan@_dirkjan

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…

English
0
0
2
342
Sam ☁️🪵
Sam ☁️🪵@Sam0x90·
@AndreGironda @MITREattack I'm waiting for a better hardware so for now I'm limited to smaller models mistral:7b and nous-hermes2:10.7b. You need a good system prompt, some tweaking like Top K, Temperature, etc. The structure/chunking of the KB can vary the results too. It's not too bad to be honest.
Sam ☁️🪵 tweet media
English
0
1
2
143
Andre Gironda
Andre Gironda@AndreGironda·
@Sam0x90 @MITREattack What models have you tried and how did they fare? Would you consider trying a Mistral model such as Nemo, or a very very large model such as DeepSeek R1 671b?
English
1
0
1
72