markus neis

2.9K posts

markus neis banner
markus neis

markus neis

@markus_neis

Senior Principal Threat Intelligence Researcher at Arctic Wolf Labs | Opinions are my own

Blockchain Katılım Şubat 2017
1.3K Takip Edilen2.7K Takipçiler
markus neis retweetledi
inversecos
inversecos@inversecos·
APT Emulation Labs: NOW LIVE 🎉 Solve incidents emulating APT29, APT10 and other threat groups. $45 per month access to ALL labs: 👀 150+ hours of lab content 👀 Disk forensics + ELK logs 👀 Hints, questions and point system 👀 7 days free trial Labs are created & designed by industry peers: @ZephrFish @svch0st @ippsec @DebugPrivilege @HuskyHacksMK @inversecos Each lab comes with scoping notes, Windows VM with forensic tools, network diagrams, disk forensics, ELK access and was created from our collective experience working in the field. 👇ACCESS THE LABS HERE 👇 xintra.org/labs
English
26
252
963
329.9K
markus neis retweetledi
The DFIR Report
The DFIR Report@TheDFIRReport·
🎉 Announcing DFIR Labs! 🎉 Introducing our DFIR Labs based on real intrusions from our public reports and private threat briefs! Whether you're starting out or looking to deepen your skills, our labs can help. 1/2
English
1
127
490
133K
markus neis retweetledi
Nils Kuhnert
Nils Kuhnert@0x3c7·
Recently, we published lists for both, APT groups as well as financially motivated threat groups, targeting organizations in Germany. These pages are now also available in english. #threatintelligence #APT
English
1
6
27
2.4K
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
Excited to join @mandiant (for the third time) and start a new adventure @googlecloud (for the first time), now shifting my focus to ICS/OT intel. I plan to continue learning and sharing about shenanigans in the cyber-physical realm and hopefully find lots of evil left of boom.
GIF
English
31
9
185
11.8K
markus neis retweetledi
Ivan Kwiatkowski
Ivan Kwiatkowski@JusticeRage·
#100DaysofYARA I created a web service that allows you to verify on which yara versions your rule compiles. In the past, shipping rules to customers, I wondered if there were limitations but couldn't find out easily. Now I can. yaravalidator.manalyzer.org
Ivan Kwiatkowski tweet media
English
2
32
85
14.2K
Bored Ape Solana Club
Bored Ape Solana Club@BoredApeSolClub·
Happy New Year 💜 Drop Your Wallet 💙 100 Lucky Winners 🎉
Bored Ape Solana Club tweet mediaBored Ape Solana Club tweet media
English
1.1K
349
752
56.5K
Michael R
Michael R@nahamike01·
Next time, I'll cover something a bit more advanced, maybe a Python script to emulate communication with a C2 framework to assist in identifying new hosts. Shout out to @embee_research for the tips and motivation to start sharing more.
English
4
0
15
1.5K
Michael R
Michael R@nahamike01·
Tracking a Rust-based C2 From downloading the framework to refining search queries, I'll guide you through my process of tracking adversary infrastructure. Today, we'll briefly look at "link," which supports implants targeting Windows, MacOS, and Linux. 1/10
Michael R tweet media
English
7
87
373
60.4K
markus neis retweetledi
Nils Kuhnert
Nils Kuhnert@0x3c7·
Frank @r3c0nst created a neat #Yara workshop some time ago and released the materials this weekend. If you want to learn Yara (or know someone who does) - this is a very good place to start. #threatintel #detectionengineering
Nils Kuhnert tweet media
English
1
22
76
6.9K
markus neis retweetledi
Ramin Nafisi
Ramin Nafisi@MalwareRE·
Midnight Blizzard is at it again, this time targeting vulnearable TeamCity servers, disabling AV/EDR, deploying VaparRage, Mimikatz, DSinternals, rsockstun, etc. Microsoft Threat Intelligence: x.com/MsftSecIntel/s… CISA: cisa.gov/news-events/cy… CERT-PL: gov.pl/web/baza-wiedz…
Microsoft Threat Intelligence@MsftSecIntel

Microsoft has taken steps to disrupt and mitigate a widespread campaign by the Russian nation-state threat actor Midnight Blizzard targeting TeamCity servers using the publicly available exploit for CVE-2023-42793.

English
0
19
49
7.5K
markus neis retweetledi
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
The YARA enthusiast community is friendly, skilled and growing, and you can be a part of it. Come learn and have fun, push yourself and your peers, and let's jam on some YARA rules together. github.com/100DaysofYARA/…
Greg Lesnewich@greglesnewich

About a month from now, #100DaysofYARA will kick off! Explainer on how to participate is linked below but the TL;DR is: A self-paced, concerted effort to learn YARA by writing a new rule everyday, starting January 1

English
0
7
30
5.6K
Matthew Toussain
Matthew Toussain@0sm0s1z·
@markus_neis @stedaniels @cyb3rops Agreed. I just don’t like the idea of invalidating the work of thousands of people by making it seem like ‘just a game’. It’s not. Folks get real value from these things and have dedicated their lives to it. Triggered me pretty hard. 🤷‍♂️
English
1
0
1
26
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
I don't call myself a 'Blue Teamer' and here's why. The term originates from gaming scenarios, where 'Red Team' implies an adversary. However, my true adversaries aren't fictional teams; they are genuine threats. People often think it's all about Red vs Blue, but it's not. It's more than just beating another team. The main job of the Red Team is to help the defenders get better and test their tools to spot real dangers. We shouldn't just think about this as a game. Our collective aim is to identify risks sooner, prevent harm, and foster positive outcomes. It's about the larger picture - safeguarding and nurturing what is valuable.
English
39
44
342
113.7K
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
So funny, I wrote "the term originates from gaming scenarios" and people correct me saying that it originates from ☝️"war gaming scenarios" as if that mattered. It originates from a game, a play, a training exercise, a side show .. that's the point. Wasn't that obvious?
English
2
0
32
7.5K
Matthew Toussain
Matthew Toussain@0sm0s1z·
@stedaniels @cyb3rops The difference is the idea of “play”. Which was the OP’s entire point. - It’s not real; it’s just a game. That’s a silly and counterproductive take. Blue teams do REAL work that has REAL benefits for REAL organizations. Discounting that value is a disservice to everyone.
English
1
0
0
61