gatari

98 posts

gatari banner
gatari

gatari

@gatariee

19 • opinions are my own

Singapore Katılım Haziran 2020
109 Takip Edilen411 Takipçiler
gatari
gatari@gatariee·
@MacmodSec yo, saw u at range village today! we were talking about godap 👋
English
1
0
1
87
Artur Marzano
Artur Marzano@MacmodSec·
Anyone around for Defcon Singapore? 🐦‍🔥🐲🐦‍🔥
English
2
0
1
289
gatari
gatari@gatariee·
@techspence genuine question: how often do you use user-to-user ACLs applied at such a scale though?
English
0
0
1
140
spencer
spencer@techspence·
How to brush up on your on-prem Active Directory skills (for pentesters) 1. Spin up an AD lab 2. Use bad blood to intentionally misconfigure it 3. Try to fix the misconfigs & harden the environment 4. Now attack it…
English
9
8
223
14.7K
gatari
gatari@gatariee·
@xxxbaemaxxx my school added as much friction as possible for students when they tried to do extra-curricular stuff, even if it's non-offensive related
English
1
0
0
42
Baesenseii
Baesenseii@xxxbaemaxxx·
My institution is apparently against it and there's no ifs or buts on this matter. But look what I got instead: 2 students of mine getting local recognition in presenting a conference. The school didn't support it but I told my students to do it (bypassing the institution)
English
1
0
0
87
Baesenseii
Baesenseii@xxxbaemaxxx·
To the SG cybersec community (especially the offensive security/red teaming peeps), it seems that the culture of our work gives a negative connotation, hence students aren't really encouraged to work on this.
English
1
0
0
93
Unit 42
Unit 42@Unit42_Intel·
Criminals are using Teams and impersonating help desk personnel to deliver an #AdaptixC2 beacon. Attackers utilized #QuickAssist to run an update.ps1 file that downloads and runs an AdaptixC2 beacon using tech-system[.]online for its C2 server. Details at bit.ly/3SMlocQ
Unit 42 tweet mediaUnit 42 tweet media
English
3
41
139
17.6K
gatari
gatari@gatariee·
@ChadWst @techspence what's up with stale computer objects? never thought those were really problematic
English
1
0
0
52
Chad 🪐👽 🚀
Chad 🪐👽 🚀@ChadWst·
@techspence Add DA’s the protected users group. Remediate PKI ESC vulnerabilities Clean up stale computer objects
English
2
1
23
2K
spencer
spencer@techspence·
Quick wins for hardening Active Directory that actually move the needle… 1, Run Locksmith and fix all findings 2, Make sure all admin accounts have unique strong passwords 3, Use fine-grained password policies 4, Remove 90% of the accounts in Tier 0 groups (they likely don’t really need to be there) These are just the first few that came to mind, what’s yours?
English
13
45
371
24.2K
brymko
brymko@brymko·
@gatariee @meekochii ayy yoo.. I actually didnt loose it It was lodged behind another card 🤣🤣 see if you can see it
brymko tweet media
English
1
0
1
114
meeko✨
meeko✨@meekochii·
offbyone con 2025 haul, wasnt able to get around doing the badge ctf and i lost my range village badge, hopefully could score it next year everyone from the staff and attendees was super chill and skilled, def giving other security cons a run for their money
meeko✨ tweet media
English
1
3
16
2K
meeko✨
meeko✨@meekochii·
@gatariee i went to the range village on day 1 and got the badge, guy with the QR code shirt and long hair unfortunately i lost the badge in the con😭
English
1
0
1
75
gatari
gatari@gatariee·
@meekochii i was running the range village, what are the chances we already met
English
1
0
2
63
meeko✨
meeko✨@meekochii·
@gatariee YESS i was, i came in and out of the con since there was only a few talks i was interested in wish we couldve met!
English
1
0
0
76
gatari
gatari@gatariee·
@Redteamj correction, just remembered that CPTS doesn't have that
English
0
0
0
39
gatari
gatari@gatariee·
@Redteamj it's not assumed breach unfortunately, you'll just get SSH credentials for a machine inside the environment (same as CPTS)
English
1
0
0
44
gatari
gatari@gatariee·
@thoughtfault rbcd - letting your intern pick their own team of interns to cause a fire in the pantry
English
0
0
2
92
gatari retweetledi
TrustedSec
TrustedSec@TrustedSec·
A Red Team engagement is a serious commitment for any org who wants to improve their security posture. In our new blog, @curi0usJack breaks down some goals of a Red Team engagement so that you can better measure its success. Read it now! hubs.la/Q039HVd70
English
3
61
211
21.7K
gatari
gatari@gatariee·
@codex_tf2 im the one reporting it fuck you
English
0
0
2
64
CodeX
CodeX@codex_tf2·
every few days google flags my evasion adventures talk slides for being malicious 💀 its been manual reviewed and unflagged every single time yet they still reflag it every few days anyways lol
CodeX tweet mediaCodeX tweet media
English
1
0
5
444
gatari
gatari@gatariee·
@meekochii it's cute so i bought one anyway
English
1
0
1
39
meeko✨
meeko✨@meekochii·
@gatariee this typo has haunted me for months but im just rolling with it, im just gonna say its sarcastic
English
1
0
0
28
meeko✨
meeko✨@meekochii·
we pride ourselves in the accurate technical designs of our stickers
CodeX@codex_tf2

@meekochii @andrew_n_carr wtf its an accurate cobalt strike client, it even has the obligatory legacy unpatched win 7 box 3 pivots deep 🥹

English
1
1
11
687
gatari
gatari@gatariee·
@Yeeb_ only aptlabs should have the words "red team" on it, although the lack of EDR isn't very red team either
English
0
0
1
175