BZH

107 posts

BZH

BZH

@bzhinfosec

Former pentester @intrinsec, now incident response @awscloud. Tweets erratically.

Vancouver, British Columbia Katılım Mart 2015
460 Takip Edilen89 Takipçiler
BZH
BZH@bzhinfosec·
@ChrisDeLeon I just want everything to be perfect on the first try. It shouldn't be that hard...
English
0
0
0
0
BZH retweetledi
Rob Fuller
Rob Fuller@mubix·
I would like everyone who follows me to do this one thing. DM someone who follows you, but you have never interacted with. Wish them a happy holidays and ask them how they are doing. Do this one thing for me. Please and Thank you 🙏.
GIF
English
10
13
77
0
BZH
BZH@bzhinfosec·
@cnotin 🧐 Opened filesystem ➡️ Searched "mimikatz" 😅 Added "EDR" to the marketing website
English
1
1
3
0
Clément Notin
Clément Notin@cnotin·
🧐 Opened EDR console ➡️ Searched "mimikatz" 😅 Added "threat hunting" to LinkedIn profile
English
18
44
418
0
BZH retweetledi
Jon Hencinski
Jon Hencinski@jhencinski·
Normalize the thinking that a #SOC is a place for innovation: A #SOC: - isn't just "lower-level" work - is where great innovation happens - is just as important as dev / eng / it - is filled with great feature ideas (not just based on the last problem they ran into)
English
9
71
247
0
BZH retweetledi
Colm MacCárthaigh
Colm MacCárthaigh@colmmacc·
We've completed the rollout of TLS1.3 across Amazon CloudFront. It's now available and on for all CloudFront customers with no action or settings needed. Enjoy! aws.amazon.com/about-aws/what…
English
8
64
305
0
BZH retweetledi
AWS Security
AWS Security@AWSSecurityInfo·
Updates to the security pillar of the AWS Well-Architected Framework: go.aws/2ZgP0UQ
English
0
19
36
0
BZH retweetledi
Arioch
Arioch@ZeArioch·
If you're looking into ETW for #DFIR purposes, you'll probably like feeding them into your Splunk SIEM. Bonus round: you don't need to destroy your license consumption! You can define granular filters on providers, event IDs and more. Enjoy!
Sylvain Peyrefitte@citronneur

Love ETW but can't afford #Splunk *and* Defender ATP at the same time? Take a look at our ETW Splunk Forwarder add-on! Set up the providers you want, add some filtering and voilà! github.com/airbus-cert/Sp… By the way, we're hiring! #DFIR #ETW #Windows

English
1
4
2
0
BZH retweetledi
Scott Piper
Scott Piper@0xdabbad00·
Almost one year ago after attending re:Inforce, I wanted there to be a cloud security conference that was independent of the cloud providers. I'm so excited that this is actually happening tomorrow as fwdcloudsec.org after so many hours by the organizers and speakers.
English
8
51
221
0
BZH retweetledi
Joe Słowik 🌻
Joe Słowik 🌻@jfslowik·
"So what do you do for money?"
Joe Słowik 🌻 tweet media
English
2
20
129
0
BZH retweetledi
PortSwigger Research
PortSwigger Research@PortSwiggerRes·
This is a brilliant vector by @RenwaX23 <a autofocus onfocus=alert(1) href=?>. Who knew that Chrome decided to apply the autofocus attribute to every element! Now on the cheat sheet #onfocus" target="_blank" rel="nofollow noopener">portswigger.net/web-security/c…
English
3
117
289
0
BZH retweetledi
j00ru//vx
j00ru//vx@j00ru·
With Windows 10 20H1 (2004) almost out the door, I've updated the system call tables on my blog and on GitHub. Delta-wise, this seems to be the biggest Windows 10 update yet: +7 syscalls in ntoskrnl and +64,-6 in win32k.sys github.com/j00ru/windows-…
English
5
135
411
0
BZH retweetledi
human cpu (no longer here)
human cpu (no longer here)@cpuGoogle·
Intel with all the melt/spec/leak mitigations, the bare-bones syscall cost went from ~70ns to about ~350ns. It's crazy. I think we lost 10 years of system call performance.
English
34
392
1.5K
0