William | Cybersecurity & SOC Analyst

21K posts

William | Cybersecurity & SOC Analyst banner
William | Cybersecurity & SOC Analyst

William | Cybersecurity & SOC Analyst

@WilliamInCyber

๐—ฆ๐—ข๐—– ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐˜ | ๐—•๐—น๐˜‚๐—ฒ ๐—ง๐—ฒ๐—ฎ๐—บ | ๐—ฆ๐—œ๐—˜๐—  (๐—ฆ๐—ฝ๐—น๐˜‚๐—ป๐—ธ) โ€ข ๐——๐—™๐—œ๐—ฅ โ€ข ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป | Learning in public | https://t.co/9JrhGHlI9u

Johannesburg, South Africa Katฤฑlฤฑm Mart 2020
864 Takip Edilen736 Takipรงiler
SabitlenmiลŸ Tweet
William | Cybersecurity & SOC Analyst
๐——๐—ฎ๐˜† ๐Ÿญ๐Ÿณ/๐Ÿฏ๐Ÿฌ ๐—ฆ๐—ผ๐—ฐ๐—ถ๐—ฎ๐—น ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐—Ÿ๐—ฎ๐—ฏ The attacker didnโ€™t touch a single system. They just called an employee and asked. ๐Ÿงต
William | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet media
English
1
0
3
80
William | Cybersecurity & SOC Analyst
5/ SIEM alerts tell you something happened. Packets tell you what, where, and who. The skill isnโ€™t reading every packet. Itโ€™s knowing which filter to type next. DNS โ†’ conversations โ†’ payloads โ†’ DHCP. Each one peels back a layer. Full PCAP analysis: github.com/WiLL75G/soc-daโ€ฆ
English
0
0
0
12
William | Cybersecurity & SOC Analyst
4/ DHCP traffic is the SOC analystโ€™s shortcut: bootp (or dhcp) filter โ†’ Hostname: brads-MBP IP: 10.2.28. 88 MAC: captured Thatโ€™s the infected machine. Thatโ€™s the user to call. Thatโ€™s the host to isolate. Three filters. Full picture.
English
1
0
0
12
William | Cybersecurity & SOC Analyst
๐——๐—ฎ๐˜† ๐Ÿญ๐Ÿด/๐Ÿฏ๐Ÿฌ โ€” ๐—ช๐—ถ๐—ฟ๐—ฒ๐˜€๐—ต๐—ฎ๐—ฟ๐—ธ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—ง๐—ฟ๐—ฎ๐—ณ๐—ณ๐—ถ๐—ฐ ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€ A PCAP file. Thousands of packets. Somewhere in there: a malware infection. The SIEM said something happened. I had to find what. ๐Ÿงต
William | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet media
English
2
0
0
16
Dr Iretioluwa Akerele
Dr Iretioluwa Akerele@ireteehยท
Cybersecurity Twitter, letโ€™s help beginners ๐Ÿ‘‡๐Ÿพ Whatโ€™s the FIRST thing someone should learn in Cyber?
English
83
54
387
33K
William | Cybersecurity & SOC Analyst
4/ A user under pressure overlooks small inconsistencies. Wrong domain. Generic greeting. Mismatched Reply-To. All visible. All ignored. Because the attacker created urgency before the user could think. Thatโ€™s the whole attack.
English
1
0
1
24
William | Cybersecurity & SOC Analyst
๐——๐—ฎ๐˜† ๐Ÿญ๐Ÿณ/๐Ÿฏ๐Ÿฌ ๐—ฆ๐—ผ๐—ฐ๐—ถ๐—ฎ๐—น ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐—Ÿ๐—ฎ๐—ฏ The attacker didnโ€™t touch a single system. They just called an employee and asked. ๐Ÿงต
William | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet media
English
1
0
3
80
Cyber_Racheal
Cyber_Racheal@CyberRachealยท
Drop your handles in your in Cybersecurity. Engage with other cyber fellows.
English
140
19
206
13.9K
William | Cybersecurity & SOC Analyst
4/ Root account. No MFA. Used for routine tasks. In AWS thatโ€™s not a misconfiguration โ€” itโ€™s an open door. One compromised session = full account takeover. Every resource. Every region. Every service. โ†’ Finding documented. Remediation flagged.
English
1
0
2
43
William | Cybersecurity & SOC Analyst
๐——๐—ฎ๐˜† ๐Ÿญ๐Ÿฒ/๐Ÿฏ๐Ÿฌ โ€” ๐—”๐—ช๐—ฆ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐˜ƒ๐—ฒ๐˜€๐˜๐—ถ๐—ด๐—ฎ๐˜๐—ถ๐—ผ๐—ป 11 events. Two users. One account wide open. CloudTrail doesnโ€™t lie. ๐Ÿงต
William | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet mediaWilliam | Cybersecurity & SOC Analyst tweet media
English
1
0
5
97