David Cottingham

179 posts

David Cottingham

David Cottingham

@c0tts

CEO & Co-Founder of Airlock Digital, practical and effective allowlisting

Australian Capital Territory Katılım Temmuz 2017
114 Takip Edilen310 Takipçiler
David Cottingham
David Cottingham@c0tts·
@Collab_Seth @AirlockDigital Anytime! I have been wanting to reply to this for months now! If I can help in any way, please don't hesitate to reach out to myself or support :)
English
0
0
2
47
Seth Kusiak
Seth Kusiak@Collab_Seth·
@c0tts @AirlockDigital Hey David, thanks for sending this — I was just reading the release notes and was like 🥳
English
1
0
1
19
David Cottingham
David Cottingham@c0tts·
Really exciting milestone to have the whole company together in Adelaide this week, cooking up the next chapter :)
David Cottingham tweet media
English
0
1
10
466
David Cottingham retweetledi
Brian in Pittsburgh
Brian in Pittsburgh@arekfurt·
Application allowlisting is the future for all security consciousness organizations that have any significant resources. It's just a matter of how and when any particular org will adopt it.
English
9
17
59
15.2K
David Cottingham retweetledi
Brian in Pittsburgh
Brian in Pittsburgh@arekfurt·
Here's the reality: We need to shift focus away from relying on detection + response to catch and stop ransomware/extortion actors and toward preventative/blocking means. There simply is no viable alternative if we're going to make substantial progress at societal level here.
Justin Elze@HackingLZ

One of the drivers behind people purchasing EDR is ransomware. If your argument is, who cares about "bypasses" or default blocking, and you say, "Well, EDR creates telemetry people can hunt on days or weeks later," ask yourself what the average dwell time is for these events.

English
3
5
20
3.1K
David Cottingham retweetledi
Koen Van Impe ☕
Koen Van Impe ☕@cudeso·
The “Allowlist Auditor” from @AirlockDigital is great to highlight the current state of allowlisting on endpoints. Includes tests for execution (exe, dll, PS1, CPL and others) in common locations, and an audit for existing allowlisting solutions. airlockdigital.com/application-wh…
Koen Van Impe ☕ tweet mediaKoen Van Impe ☕ tweet media
English
0
14
46
12.5K
David Cottingham
David Cottingham@c0tts·
@jmelville It seems so! That does make life a little easier. Still unclear as to why this occurred. Intentional? unintentional? rolled back due to impact?
English
0
0
1
36
David Cottingham
David Cottingham@c0tts·
Something is happening at Digicert. It looks like on many Windows systems the VeriSign Class 3 Public Primary Certification Authority - G5 root certificate (serial: 18dad19e267de8bb4a2158cdcc6b3b4a) has been revoked as of around 9 hours ago.
English
2
20
29
6.5K
David Cottingham
David Cottingham@c0tts·
Update: This change has been rolled back by Microsoft, with the certificate appearing as valid on systems. This can also be seen here ccadb.my.salesforce-sites.com/microsoft/Incl… (SHA1 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5) showing with the status of 'Not Before'.
David Cottingham tweet media
English
0
2
6
686
David Cottingham
David Cottingham@c0tts·
@back2all You unfortunately can't, Microsoft has set the remove flag. It's effectively perma banned. Even if you trust this yourself, the system will still block it.
English
0
0
0
13
David Cottingham retweetledi
Daniel Schell
Daniel Schell@danonit·
A Where’s Wally for the @riskybusiness sticker on the Defcon sticker wall.
Daniel Schell tweet media
English
0
1
3
522