M45C07

522 posts

M45C07

M45C07

@m45c07

HANDLE

Katılım Eylül 2018
390 Takip Edilen56 Takipçiler
Mehmet Ergene
Mehmet Ergene@Cyb3rMonk·
This is gonna be huge. If I calculate correctly, you will be able to detect almost any Windows and Entra ID related attack with less than 20 detections. You can probably expand them to Linux/MacOS/Azure/AWS/GCP as long as you have the right telemetry as I'll teach higher-order behavioral detection logic that are universal. And they are quite hard to bypass 😎
Mehmet Ergene tweet media
English
3
6
117
7.9K
0x12 Dark Development
0x12 Dark Development@Salsa12__·
Working on a new project to represent the function call chain in a reversing exercise Do you think it could be useful to someone other than me?
0x12 Dark Development tweet media
English
1
1
18
732
Anton
Anton@Antonlovesdnb·
#ClaudeForBlueTeam - Day 11! I just cut my SIEM lab noise down by over 80 percent. Claude can drill into your SIEMs nosiest events, trace what's generating them and tell you exactly what to tune and how many events/second you can save. Want to replicate this in your environment? Grab the skill below.
Anton tweet media
English
5
27
139
13.2K
Mehmet Ergene
Mehmet Ergene@Cyb3rMonk·
Some exiciting news tomorrow 🥳
English
3
0
15
1.8K
M45C07
M45C07@m45c07·
@Cyb3rMonk I think there is also HTB module on Sliver that's pretty good
English
1
0
2
434
M45C07 retweetledi
v1n
v1n@0xv1nx0·
Dropping new LOLBin/LOLBAS inspired project today called LOLGlobs, to document some cool ways of commandline evasion using wildcards and some other obfuscation techniques that go beyond B64 encoding: 0xv1n.github.io/LOLGlobs/
English
6
99
387
23.2K
0x12 Dark Development
0x12 Dark Development@Salsa12__·
From a cybersecurity perspective, what technique does this dummy code look like to you?
0x12 Dark Development tweet media
English
7
1
47
4.6K
M45C07 retweetledi
Pavel Yosifovich
Pavel Yosifovich@zodiacon·
Access masks are easy to ignore until you hit Access Denied and waste time guessing. I wrote up a short walkthrough on what access masks are, where they live, and how to inspect them in Process Explorer, the security UI, and a debugger. trainsec.net/library/window…
English
0
34
132
6.3K
M45C07
M45C07@m45c07·
Within DeviceEvents (XDR/MDE however you want to call it) you can find this thing, that's like the most confusing event I have ever seen. I wonder if anyone is utilizing this in any way????? #cybersecurity #EDR #MDE
M45C07 tweet media
English
0
0
0
43
Mehmet Ergene
Mehmet Ergene@Cyb3rMonk·
It's been just 2 weeks since I launched my new course, and people are loving it. 🙏 I’ve lowered the bar for entry into threat hunting. #ThreatHunting
Mehmet Ergene tweet media
English
2
1
17
1K
M45C07
M45C07@m45c07·
I have been doing some AMSI bypasses lately, imagine how surprised I was finding out this: Windows 11 Pro, no MDE, Defender AV -> bypass was successful. Windows 11 Pro, MDE, Defender AV -> the same bypass was instantly detected. Huh #windows #MDE #Defender #cybersecurity #amsi
English
0
0
0
54
M45C07
M45C07@m45c07·
@Salsa12__ I have been playing with this technique lately, some EDRs trigger for it quite often
English
0
0
0
15
0x12 Dark Development
0x12 Dark Development@Salsa12__·
Do u remember the VirtualAlloc implementation using Module Stomping? It was an interesting technique... Soon we will play with it
0x12 Dark Development tweet media0x12 Dark Development tweet media
English
1
0
3
79
M45C07
M45C07@m45c07·
@AlteredSecurity I loved CRTP, so CRTE would be a next level and nice improvement;)
English
0
0
0
12
Altered Security
Altered Security@AlteredSecurity·
Final Black Friday Giveaway! Win FREE access to: • 1 CRTP seat • 1 CRTE seat How to participate: 1. Like 2. Comment which course you’re interested in and why 3. Repost If you've already availed the Black Friday offer, you're still eligible. Winners will be announced on Dec 15, 2025. Few days left to grab your Black Friday deals: • Up to 25% OFF Labs & Bootcamps • No coupon code needed • Use anytime within 6 months For More details: alteredsecurity.com/online-labs
Altered Security tweet media
English
445
345
599
37.4K
vx-underground
vx-underground@vxunderground·
Big giveaway. - (x3) Certified Red Team Expert (CRTE) - (x3) Certified by Altered Security Red Team Professional for Azure (CARTP) - (x10) Malware Analysis for Hedgehogs Bundle CTRE and CARTP sponsored by @nikhil_mitt Malware Analysis sponsored by @struppigel Leave a comment below on what you'd like. Winners chosen in 24 hours.
vx-underground tweet media
English
1.7K
126
1.5K
111.3K
0x12 Dark Development
0x12 Dark Development@Salsa12__·
The Learning C++ for Malware Development course has finished recording! So if all works out, you will have the courses available before the end of year or just at the early start of 2026 Do you want it before 2026?
English
1
0
3
55
M45C07 retweetledi
No Starch Press
No Starch Press@nostarch·
Our Black Friday sale starts now! Get 42% off everything with code BLACKFRIDAY25. Time to stock up on your winter reading! Runs through 12/2. nostarch.com
No Starch Press tweet media
English
4
48
176
26.2K
White Knight Labs
White Knight Labs@WKL_cyber·
The countdown is on, only one week until the biggest cybersecurity training sale of the year. Prepare your wish list. (Includes new course release: OADOC and OGOTC) whiteknightlabs.com/training/ Use code: WKLBLACKFRIDAY50 at checkout, November 28–December 12.
GIF
English
1
2
6
465