Brian Baskin

16.1K posts

Brian Baskin banner
Brian Baskin

Brian Baskin

@bbaskin

Threat researcher, malware analysis, RE, incident response, with some old school forensics and CTFing. Apologetic ginger. These are my personal opinions

Bawlmer, Maruhlan, US Katılım Kasım 2008
885 Takip Edilen7.1K Takipçiler
Brian Baskin retweetledi
Sublime Security
Sublime Security@sublime_sec·
🚨 Zoom impersonation attacks are on the rise, and getting more convincing. We found a fake Zoom invite that launches a JS-based “meeting” with simulated lag, then delivers a malicious update download. Not simple phishing, a high-fidelity attack built to gain trust before delivering malware. Breakdown: sublime.security/blog/advanced-…
English
0
3
3
319
Brian Baskin retweetledi
The DFIR Report
The DFIR Report@TheDFIRReport·
Threat Actors are "Bringing Their Own Forensics" In a recent ClickFix campaign, we saw threat actors likely related to Interlock Ransomware, running Volatility (vol.py) directly on victim machines. Commonly a tool for defenders, the TAs are using it to:
The DFIR Report tweet media
English
4
70
354
27.9K
Brian Baskin retweetledi
BSidesCharm
BSidesCharm@BSidesCharm·
Remember, a ticket to #BSidesCharm 2026 gets you access to our awesome Hiring Village on Sat 4/25, where you can get career help & talk with companies looking to hire! Details at bsidescharm.org/hiringvillage/
English
0
6
2
779
Brian Baskin retweetledi
RE//verse
RE//verse@REverseConf·
RE//verse 2026 talks are live on YouTube! Want to revisit a talk or catch the ones you missed? The full playlist is now available: youtube.com/playlist?list=…
RE//verse tweet media
English
4
57
321
22.2K
Brian Baskin retweetledi
Anton
Anton@Antonlovesdnb·
Day 3 of #ClaudeForBlueTeam We'll stick with the ATT&CK theme - working with the data kind of sucks on the website alone. It's static, you can't really take any notes and there's no cool graph view. Prompt Claude to make you a backlinked & tag filled Obsidian vault containing the ATT&CK data - and specifically data sources. From here, you can do some powerful stuff like look at what data sources are required for SaaS type techniques. You can also visualize detection coverage for a particular technique.
Anton tweet media
English
0
35
183
8.7K
Brian Baskin retweetledi
mthcht
mthcht@mthcht2·
LOLFSAAS Living off Free SaaS Hundreds of SaaS platforms with free tiers, documenting abuse surface, opsec risks, authent methods, C2 framework mappings, and operational limits. lolfsaas.github.io
English
7
131
604
41.6K
Brian Baskin retweetledi
Rob
Rob@Rob_Mulla·
In 2021 I mined 1.55 ETH into a crypto wallet. When I needed to access it recently my seed phrase didn't work in any standard tool. Turns out the wallet software (coinwallet) back in 2021 had a bug that gave people the WRONG SEED PHRASE! Anyone who created a wallet during that period can't access it by normal approaches. After weeks of forensics, I found the bug and recovered my ETH. Posting the full story and recovery code below! Full story: robmulla.substack.com/p/how-my-sons-… Repo: github.com/RobMulla/coins…
English
12
41
747
77.8K
Brian Baskin retweetledi
Kostas
Kostas@Kostastsale·
Funniest investigation of the week: Attacker logs in as admin → Opens the browser → Googles how to uninstall tools → Downloads a cracked Russian copy of "Revo Uninstaller" with an activation key → Installs it → Then uninstalls the tools they just used 🤦 😂 💀 The whole cycle and everything else they did is coming to you through a flash hunt in the @ThruntingLabs soon. You'll have a laugh as well 😆
Kostas tweet media
English
2
27
274
33.5K
Brian Baskin retweetledi
BSidesCharm
BSidesCharm@BSidesCharm·
Well, sometimes you hit the send button too quickly - Tuesday's post should have been announcing ROBERT M. LEE as the #BSidesCharm 2026 keynote!!
BSidesCharm tweet media
English
0
5
5
501
Brian Baskin retweetledi
BSidesCharm
BSidesCharm@BSidesCharm·
It appears that the room block has filled up in record time - we have posted potential alternatives on bsidescharm.org/venue/
BSidesCharm tweet media
English
0
2
1
244
Brian Baskin
Brian Baskin@bbaskin·
@TheUncleBob @facebook That is truly the best solution. In Facebook's quest to remain relevant, they've destroyed any reason to keep it installed.
English
0
0
0
39
Brian Baskin
Brian Baskin@bbaskin·
A whole new level of enshittification is constant notifications from @Facebook app about random junk. It cannot be disabled at all, even with help from Facebook support AI.
Brian Baskin tweet media
English
2
0
1
231
Brian Baskin retweetledi
Cory Zue
Cory Zue@czue·
PSA: I just survived the best phishing attempt I've ever seen. A "reporter" at TechCrunch with a 10-year-old account and 9k followers DMed me asking if I'd be interested in giving input to an article that sounded relevant. When I said yes, they sent me to a real cal.com link to book with the name of an actual TC reporter. After booking, I got redirected to another page saying I had to verify myself to complete the booking. The auth request looks somewhat legit, except for a small red note that it's not approved. My spidey sense had been tripped and I realized the domain was sketchy, but if I wasn't on autopilot (or if I was an OpenClaw) I might have easily given them full access to my account. Stay safe out there.
Cory Zue tweet mediaCory Zue tweet mediaCory Zue tweet media
English
68
107
2K
254.6K
Brian Baskin retweetledi
Jamie Levy🦉
Jamie Levy🦉@gleeda·
🧵 We recently had an incident that involved a MuddyWater hands-on attacker who couldn't spell "administrators" Full timeline breakdown below. 1/
Jamie Levy🦉 tweet media
English
14
74
362
54.3K
Brian Baskin retweetledi
Petr Baudis
Petr Baudis@xpasky·
> be me, buy a minipc sporting a shiny rgb stripe > can i turn it off? > found a windows binary blob that can control it, welp > download the zip and fire up pi > gpt-5.4: "reverse engineer LedControl_S3A_F3A.exe, i'd like to control the LEDs from Linux" (that's the full prompt) > 10 minutes of `objdump -d` later: "Yes — I dug into it." > i can now control my rgb stripe from linux > what.
Petr Baudis tweet mediaPetr Baudis tweet mediaPetr Baudis tweet media
English
105
319
7.3K
514.9K
Brian Baskin retweetledi
nolen
nolen@itseieio·
made a hook that adds a bouncing dvd logo to claude code whenever it's thinking
English
311
1.1K
17.2K
925.7K