Strassi

47 posts

Strassi banner
Strassi

Strassi

@Strassi7

Katılım Ekim 2018
41 Takip Edilen6 Takipçiler
Strassi
Strassi@Strassi7·
@Suricata_IDS Is this going to be recorded and published anywhere?
English
0
0
0
0
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
For me and many other analysts it’s always: “Blah blah, critical vulnerability, blah blah install patch now, blah blah some kid published a PoC [great] blah blah … were’s the god damn information on how to detect a compromise? Where are the indicators?” helpnetsecurity.com/2022/10/11/cve…
Florian Roth ⚡️ tweet media
English
15
58
296
0
Strassi
Strassi@Strassi7·
@cyb3rops @malmoeb @TheDFIRReport I need your help for my master thesis. I currently looking for resources on detection opportunities besides the windows event log on windows. Any Hints/Papers/Projects (something like @OSSEM_Project would be awesome).
English
0
0
0
0
Strassi
Strassi@Strassi7·
@0sm0s1z I think a future vuln scanner should enable users to measure or guide the effectiveness. The new EPSS model might be worth reading: first.org/epss/model I would like to define my risk acceptance and have EPSS to guide my patch efforts on found vulnerabilities.
English
0
0
0
0
Matthew Toussain
Matthew Toussain@0sm0s1z·
I've been working on a thing... If you had an open source general-purpose vulnerability scanner. What would you need it to do?
Matthew Toussain tweet media
English
61
34
379
0
Strassi retweetledi
vx-underground
vx-underground@vxunderground·
15 members of REvil has been arrested by the Russian authorities. REvil, once dubbed the "Crown prince of Ransomware", was responsible for the Kaseya supply chain attack, and many other high-profile breaches. Footage courtesy of the FSB.
English
32
688
1.6K
0
Strassi
Strassi@Strassi7·
@haveibeenpwned Does the breach contain passwords or does it not? Can someone clarify this situation for me?
Strassi tweet media
English
1
0
2
0
Have I Been Pwned
Have I Been Pwned@haveibeenpwned·
New breach: Epik had 180GB of data breached last week including 15M unique email addresses (both customers and scraped WHOIS), names, phone nums, physical addresses, purchases and passwords in various formats. 52% were already in @haveibeenpwned. More: arstechnica.com/information-te…
English
10
149
363
0
Strassi
Strassi@Strassi7·
@cyb3rops @certbund @CERT_at how do you size your windows client event log files? Would you agree with the (old) microsoft calculation? #maximum-log-size-kb" target="_blank" rel="nofollow noopener">docs.microsoft.com/en-GB/previous…
English
0
0
0
0
Strassi
Strassi@Strassi7·
@Chronopost my parcel is not moving. There seems to be a problem with my address. Pls reach out to me
English
0
0
0
0
Strassi
Strassi@Strassi7·
@TheDFIRReport Can you tell me, what tools are you using to create your timelines and graphs?
English
0
0
0
0
The DFIR Report
The DFIR Report@TheDFIRReport·
Sodinokibi (aka REvil) Ransomware ➡️TTR: 4 hours ➡️Initial Access: IcedID ➡️Discovery: nltest, net, wmic, AdFind, BloodHound, etc. ➡️PrivEsc: UAC-TokenMagic & Invoke-SluiBypass ➡️Defense Evasion: Safe Mode & new GPO ➡️Exfil: Rclone ➡️C2: CobaltStrike thedfirreport.com/2021/03/28/sod…
The DFIR Report tweet mediaThe DFIR Report tweet mediaThe DFIR Report tweet mediaThe DFIR Report tweet media
English
16
344
682
0
Strassi retweetledi
Paul Seekamp
Paul Seekamp@nullenc0de·
I swear, if anyone releases 1 more AD exploit/relay/bypass/LPE/whatever in the next 2 weeks my head is literally going to explode.
English
20
39
323
0
Strassi
Strassi@Strassi7·
@004ffca @cyb3rops This way it is possible to search related content of a CVE with a single click on its hashtag. Easier to use.
English
1
0
4
0
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Dear Twitter & InfoSec community, could we start tagging CVEs without the dashes, so that #CVE-2021-35211 becomes #CVE202135211 ? That would be great, Thanks
English
31
41
276
0
Strassi
Strassi@Strassi7·
@GossiTheDog LPE and lateral movement on beachhead hosts; for sure. Is a standard user able to authenticate against a domain controllers RPC Print Spooler Service?
English
0
0
1
0
Lee Holmes
Lee Holmes@Lee_Holmes·
The 4th edition of the PowerShell Cookbook is now available! This is a huge update, covering all the cool new things in PowerShell 7 and dropping what is no longer relevant. If you've been wanting to "get into that PowerShell thing", now's your chance :) amzn.to/3qpjHmH
Lee Holmes tweet media
English
20
120
392
0
Strassi
Strassi@Strassi7·
@bad_packets Is any particular CVE scanned or just the portal existence?
English
0
0
0
0