левиафан🔻

607 posts

левиафан🔻 banner
левиафан🔻

левиафан🔻

@derni99a

Katılım Ekim 2023
257 Takip Edilen11 Takipçiler
левиафан🔻 retweetledi
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
How we do tabletop exercises: - made a web app that generates a random scenario (via Claude) - pick the initial response, add a few words, then roll a d20 - the effectiveness of this step’s response is determined based on your roll (by Claude) - eg a 1 means, our logs show nothing, and the attacker pivots further etc. - you then write into a text box how you’d respond again, roll again, etc In the future, could add items and spells based on your “class”, eg security analyst vs SRE vs IT admin etc Super fun
Bits, Bytes, and Bourbon@DecryptedTech

Build your TTXs like a game of D&D (complete with dice and random event tables). I once did a TTX for food processing company and the random event table came up with infected "zombie" rats in a shipment of grain. Everyone had a great time, lots of engagement and participation from the executive team as well

English
6
3
70
6.6K
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
To bypass age restrictions, kids will look up “free vpn” to sign up in a diff country, opening them up to further risks. So make sure to ban VPNs too, and computers and math and thinking. Just kill the children.
English
61
113
1.5K
63.7K
vx-underground
vx-underground@vxunderground·
This is a tricky question and, in a bit of irony, there is a kind of like ... an unspoken ... or poorly documented philosophy of malware development. You kind of learn tricks of the trade as you write malware and witness malware campaigns operating in the wild. tl;dr idk it depends on wtf ur doing bro non-tl;dr To be direct, malware that works is not necessarily good malware. You can write a simple Windows batch script that deletes every file in an important directory and (technically) this would be "wiper" malware. This does not make it good, or sophisticated. Additionally, what defines "good" has changed over time. There tends to be trends with malware development. Malware tricks that used to work in the 90's are old news. Malware tricks from 2025 are old news (sort of). However, some malware tricks from the 90's are still applicable and can still be evasive. It's weird. You'll also see old tricks the 90's suddenly reappear and catch everyone off guard because... people simply forgot it even existed... The trick is usually only identified from industry veterans (or as the kids say, "unc" or "old heads") who are also surprised the trick has re-emerged. What's old is new. What's old is also old. What's new will eventually be old. Anyway, "good malware" also depends on the objective. State-sponsored malware (malware written by governments, or written for government or military usage) has extremely strict rules of engagement (usually, not always, but usually). State-sponsored is usually extremely narrow in scope and designed for a very small and limited audience. State-sponsored may not necessarily be super advanced and cutting edge, but because it is so narrow in scope it is difficult to identify. Conversely, financially motivated Threat Actors (malware developed for ... crime ...) is usually designed to be ass blasted in your face and sprayed across the internet. Financially motivated Threat Actors will typically (if it's "good malware") design malware to be modular. In other words, because it is being blasted all over the internet it will be detected quickly, hence their malware needs to be broken down into almost like ... plugins ... and they need to have it so their malware can quickly replace one segment of code with another (and quickly). If you've ever seen racing like NASCAR or F1, you'll notice vehicles can be torn apart in basically seconds and re-assembled, parts effortlessly replaced so it can quickly get back in the race. Likewise, modular malware needs to be able to change quickly to avoid it's inevitable detection. If you're curious, look up TrickBot, Emotet, or QakBot. They kind of defined what it means to be modular. They also kind of gave birth to what's known as "MaaS" (Malware-as-a-Service). State-sponsored Threat Actors malware is trickier because it needs to be designed for a target. For example, when the United States (allegedly) targeted the Chinese government (allegedly) as APT NightEagle (allegedly) the malware was developed to work almost exclusively for specific Chinese infrastructure and (allegedly) contained exploits which would work in ideal scenarios which (allegedly) were that of Chinese critical infrastructure. This can also be seen with what the Russian government alleges the United States and Israel (allegedly) did with Operation Triangulation whereas the malware (allegedly) only worked for specific sets of hardware (allegedly). Furthermore, this can also (allegedly) be seen with the United States (allegedly) purchasing cell phone malware from Israeli companies (allegedly) which were developed and sold to ICE (allegedly) to spy on people critical of ICE (allegedly). These companies are called NSO Group and Intellexa Alliance. Of course, the United States and Israel government vehemently deny the allegations from the Chinese and Russian government. Okay, I have to stop writing and schizo ranting for the time being. I have to go back to watching a baby and stuff.
💽bubble tea enjoyer@wawilow108

@vxunderground what is the difference between poorly written and really good malware? one does work and other doesn't? or is it more how clever implementation and distribution is?

English
13
23
366
25.4K
spencer
spencer@techspence·
If you're an IT Admin and you follow this list, and you put in the work to fix the findings, your environment will be more secure.
spencer tweet media
English
10
64
455
21.2K
Zack Korman
Zack Korman@ZackKorman·
People responding to my post from yesterday “dude IT knows everything you’re using AI for they can see everything” brother most don’t even know what skills and MCP servers you’re using.
English
44
7
240
46.9K
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Do people read their own notes, at what cadence? Or is the process of writing in itself a method to internalize the info, so you wouldn’t need to read it?
English
37
3
81
7K
левиафан🔻 retweetledi
spencer
spencer@techspence·
One of the characteristics of a strong security program is that no one thing can bring you down. A user clicking a link cannot bring you down. An end-user device compromise cannot bring you down. A compromised edge device cannot bring you down. Layered defense/defense in depth is kind of a tacky saying but there's real meaning behind it.
English
5
6
52
9.3K
левиафан🔻 retweetledi
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
The only useful cert is a TLS cert
English
25
14
231
11.6K
ali
ali@endingwithali·
new vulnerability just dropped its me im vulnerable
English
13
70
507
54.1K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
One of the ways I have been learning a ton lately is just simply watching Claude and Codex work on a problem together and reading through their 'thought' processes, rationales, and results. its incredible how much you can learn just by doing this.
English
9
8
171
7.9K
vx-underground
vx-underground@vxunderground·
Hi vx-underground is 7 years old, as of 2 days ago. I forgot my own website birthday. Some of you who found vx-underground as early to mid teenagers are now adults. Some of you who found vx-underground while attending university are now in the work force. Some people who follow this account have unfortunately passed away. Some followers have been arrested. Some followers have already been released from prison. Some of you (including myself) have had children. A lot has changed over the past 7 years. The only thing that hasn't really changed is the website: free malware source code, samples, and papers, forever. Thank you for letting me serve the community. It has been a pleasure. I look forward to serving all of you for another ... unknown duration of time, probably a long time, I don't know. I'm not sure how long I'll do this, but I'm already 7 years deep.
English
74
129
2.5K
60.5K
левиафан🔻 retweetledi
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Gave a version of this workshop at HOPE, NorthSec, HackSpaceCon, and improve it each time. So you’ll get to see the best version of it yet!
ContinuumCon@_ContinuumCon_

🚨 Workshop Spotlight #3 👉 "Practical Security Engineering" by @IceSolst 📝 Description You're the first security hire at a company (they have nothing in place), and you are tasked with: "Make our product more secure." Where do you start? We'll cover setting up SAST, DAST, SCA, secrets scanning, and enrichment with LLMs. All via GitHub Actions. Hands-on labs include SAST with Semgrep (plus wiring it into PR comments), DAST with Nuclei/ZAP, and Claude via GitHub Actions for enrichment. Beginner-friendly. If you've ever inherited a "you're security now, good luck" mandate, or you're about to... then this is the on-ramp. 🎟️ Only at ContinuumCon 2026 on June 12-14 Work through it live, or revisit the lab on your own time. Own it forever. The workshop doesn't end when the conference does. Got your ticket yet? 👉 continuumcon.com Hosted by @_JohnHammond, @JustHackingHQ, @AnthonyBendas, and @Level_Effect !

English
4
9
79
8.7K
Het Mehta
Het Mehta@hetmehtaa·
what made you enter cybersecurity?
English
20
0
17
32.2K
711
711@hranikasz·
@AaronBastani Born to close Hormuz, forced to park the bus.
English
59
836
5.2K
170.9K
International Cyber Digest
International Cyber Digest@IntCyberDigest·
The internet is outraged at Spotify's designer for creating an app icon that's totally off. They're calling for Spotify to fire the designer. What do you think? 👀
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
79
7
229
32.9K
Het Mehta
Het Mehta@hetmehtaa·
If you had a choice back then, would you still choose to get into cybersecurity?
English
27
0
23
6.1K
Zack Korman
Zack Korman@ZackKorman·
@skeptrune I’m convinced that fewer people would do this if they weren’t called skills. Who doesn’t want more skills?! Add a markdown file and now your AI is more skillful!
English
5
0
71
6.3K
LordSudo
LordSudo@L0rd5ud0·
@m19o__ Any resources you would recommend?
English
1
0
0
29