Priyanshu🦈

345 posts

Priyanshu🦈 banner
Priyanshu🦈

Priyanshu🦈

@_KumarPriyanshu

infosec hobbyist. resumed training thru THM.

Katılım Nisan 2021
126 Takip Edilen57 Takipçiler
Sabitlenmiş Tweet
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
I've made several videos on Autopsy last few months. Anyone who is total beginner at it could learn from these easily. youtube.com/playlist?list=…
English
0
0
1
0
Intigriti
Intigriti@intigriti·
OSINT Quiz! Where am I? 👀 Challenge difficulty: Hard 🔥
Intigriti tweet media
English
47
2
141
29.9K
Priyanshu🦈 retweetledi
Тsфdiиg
Тsфdiиg@tsoding·
Pentesters must rebrand themselves as Vibe Checkers.
English
45
297
2.8K
104.6K
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@wearyandroid Sad to hear that. Something similar to my situation. I got off from learning, and again leaning back to it. Keep grinding, you'll find it.
English
0
0
0
9
WearyAndroid
WearyAndroid@wearyandroid·
@_KumarPriyanshu I already had a good job, infosec doesn't pay the bills ☹️ Took a few years off from learning and decided to get back into it recently.
English
1
0
1
15
WearyAndroid
WearyAndroid@wearyandroid·
I completed the Basic Static Analysis #tryhackme Room Learn basic malware analysis techniques without running the malware. ✅Lab setup for malware analysis ✅Searching for strings and obfuscated strings ✅Fingerprinting malware using hashes and identifying similar samples using imphash and ssdeep ✅Using signature-based detection like Yara and Capa ✅Identifying artifacts from the PE header #malware #blueteam @tryhackme tryhackme.com/r/room/statica…
English
1
0
8
234
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
Sun:Moon North:South Vibe coders : ????
English
1
0
0
12
Graham Helton (too much for zblock)
VIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBE CODINGVIBEEEEEEEEEEEEE
Română
1
0
6
525
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@GrahamHelton3 Live Pentests and report writing. I loved your Practical Phishing assessments , few years back. And, sure will be waiting to get some more practical experiences from you.
English
0
0
0
6
Graham Helton (too much for zblock)
Would love feedback on this. I've been considering streaming a few hours a week doing security research, deep dives, tool writing, etc. Would this be interesting to watch? What would you like to see if so?
Graham Helton (too much for zblock) tweet media
English
45
13
626
38.5K
🇷🇴 cristi
🇷🇴 cristi@CristiVlad25·
if you're just starting out in cybersecurity, I guess @tryhackme is all you need.
English
8
1
42
3.7K
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@IceSolst This is exactly the insightful tweet, for which I follow experts like you on X.
English
0
0
1
46
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Is red team harder than blue team? Target’s 2013 breach is my fav example of resource mismanagement, alert fatigue, and the complexity of large environments. Actor activity was flagged, but ignored. Having been on both sides, both can be hard, both have heavy resourcing constraints, but blue teams have the unique challenge of cat herding at large scale. A common misconception for newer blue team leaders is ”just buy the tool”, “just use edr” etc. Procuring a shiny new tool is the easiest part. What do you do with the findings? How does it scale? When you do get many alerts with bad signal:noise ratio, now what? I think of Sartre’s quote “Hell is other people” and in blue team you have to deal with more people. Anyway you’re probably going to get phished more than anything else.
Tim@__invictus_

@techspence I'll give you even more copium if you want. It's far far easier to be a blue teamer than red. BT has a huge amount of heavy lifting done by EDR vendors. RT has to (in most cases) build their entire service from the ground up.

English
15
9
90
13.4K
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@CheddarB0b42 Yes! I guess it brings out the real-time SOC work. Been doing static analysis with autopsy, wireshark,splunk,etc. and I love doing so. I think I'm gonna try this, but its for enterprises and not for individuals, right?
English
1
0
1
247
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@payloadartist @navifinance Few months back the ministry of art& culture website was taken control of. No one's concerned of data anyway. whether its pvt or pub. Just a few lakhs of VDP, and all this loss of crores could be avoided.
English
0
0
0
47
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@soychotic By no means, I've experienced proton as honeypot. Almost no spams till now for 5yrs. Hosting own email server, atleast requires money and some technical knowledge and, still gets into the hands of spammers.
English
0
0
0
41
annie
annie@soychotic·
📢 PROTONMAIL IS A HONEYPOT 📢 Host your own email server or perish
English
144
78
2.9K
412K
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@GrahamHelton3 Almost no security addition, as if one possesses a password, he will have it for a long term and not just for some seconds for 1st input. So, its just creates the friction for users.
English
0
0
0
9
Graham Helton (too much for zblock)
Fun scenario: A bank requires MFA (shocking, I know). The auth flow looks like this: - Username/password -> submit - MFA token & Password -> submit - Logged in The question: Does providing the password again along with the MFA token provide any extra security?
English
16
2
15
5.6K
Priyanshu🦈 retweetledi
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
The best way to learn hacking is to be a thirteen year old with an underdeveloped moral compass, no notion of consequences, and a mind-numbing education system to fuel your existential boredom.
English
26
142
1.7K
58.2K
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
So, This 2025 will be actually cool. I'll reboot my IT security learnings since I left it for 2 yrs or so. Focusing on essential skills first and then on bug bounty. If available, I'll freelance in pentesting when I'm capable of doing so.
English
0
0
0
39
Kristof
Kristof@CoastalFuturist·
Obsidian users, do you store your vaults locally or in a cloud storage environment?
Kristof tweet media
English
140
0
351
28.9K
Priyanshu🦈 retweetledi
Bihar_se_hai
Bihar_se_hai@Bihar_se_hai·
The man who broke mountains for love ♥️
Bihar_se_hai tweet media
English
3
49
679
0
Priyanshu🦈
Priyanshu🦈@_KumarPriyanshu·
@jakecreps I have done this for some of my reports. All of them got rejected. Probably for being "out-of-scope", even though it could actually affect the organisation.
English
1
0
1
0
Jake Creps
Jake Creps@jakecreps·
I just submitted my first #BugBounty report using only #OSINT. I’m not sure it counts but I found an app running on a subdomain in scope that was actively being exploited by a stored XSS that resulted in a defacing with extremely graphic content. Let’s see what happens.
English
2
1
35
0