
D Laplante
697 posts

D Laplante
@laplanted24
CyberSecurity / Specialist Infrastructure - Networking - Storage - VmWare - Servers Virtualization



@cyb3rops Did some similar work with reverse engineering binaries with LLMs and realized the same thing — bad things embedded in nice names just cause it to ignore the finding. So wrap your ransomware code in “Ransomware Simulation” strings and you’re off to the races.













PingCastle now highlights when no policy is in place to prevent scripting files (such as .js) from being executed via double-click. A simple but effective mitigation is to configure these files to open in Notepad instead. This disrupts many common first-stage infection chains. Red Canary has published a short blog post that walks through setting this up with a small Group Policy Object: redcanary.com/blog/threat-in…



Alright threat hunters of the world, I’ve taken away your telemetry from your fancy security tools, so no firewall data, no Defender/AV data, nothing from your EDR. What non security specific logs are you using to find an adversary in your environment and why?






Solar in China generated ~1/3 as much as *all* U.S. generation last month. And it’s doubling every 2 years.











