Wes Lambert

2.5K posts

Wes Lambert

Wes Lambert

@therealwlambert

Lead Engineer, NSM @Target Github: https://t.co/tmQk6TbWMr https://t.co/5KDnHsdBlV Mastodon: @[email protected]

Augusta, GA Katılım Ocak 2016
285 Takip Edilen1.9K Takipçiler
Wes Lambert retweetledi
Sublime Security
Sublime Security@sublime_sec·
Malware campaigns are targeting real estate agents. Attackers build rapport, then send a malicious Zoom link that grants full remote access. Indicators of compromise and detection guidance here: sublime.security/blog/scammers-…
English
0
4
4
478
Wes Lambert retweetledi
Matthew Green 🌻
Matthew Green 🌻@mgreen27·
🎯 Added this Velociraptor artifact on the exchange to assist scoping IOCs related to the recent publicly disclosed Notepad++ supply chain attack. - Find impacted notepad++ versions - Find suspicious files in public reports - Find public reported network urls in running processes - Find Warbird clipc.dll shellcode loader strings 🔗 docs.velociraptor.app/exchange/artif…
Matthew Green 🌻 tweet mediaMatthew Green 🌻 tweet media
Wes Lambert@therealwlambert

Simple scoping for abused/exposed #Notepad++ via #Velociraptor notebook. For installed apps storing registry values, not portable (more likely to be leveraged given update mechansim, AFAIK). In-depth: rapid7.com/blog/post/tr-c…. I'm sure @mgreen27 has an uber artifact cooking 🔥

English
1
19
76
10.9K
Wes Lambert retweetledi
Matthew Green 🌻
Matthew Green 🌻@mgreen27·
#100DaysOfYara 🔎 Messed around with detecting the cool Warbird technique outlined by Rapid7 in their recent Chrysalis blog Velociraptor gives us the unique ability to target the VAD with live analysis: 1. Targeting sections mapped to clipc.dll 2. With PAGE_EXECUTE_READ protection 3. DEADBEEF or CAFEFE in the first bytes 🔗github.com/mgreen27/100da…
Matthew Green 🌻 tweet mediaMatthew Green 🌻 tweet mediaMatthew Green 🌻 tweet media
English
0
5
31
1.7K
Wes Lambert retweetledi
tuckner
tuckner@tuckner·
lmao for real?
tuckner tweet media
English
5
3
47
11.3K
Wes Lambert retweetledi
Sublime Security
Sublime Security@sublime_sec·
We’re hiring at Sublime Security 🚀 We’re building security that actually stops email-based attacks, and we’re growing our team with people who want to ship meaningful work at real scale. Open roles include: 🔧 Engineering Manager, Product 🛠 Corporate IT Engineer (US East Coast + UK) 📈 Sales Engineering Manager (West Coast) ✉️careers@sublimesecurity.com
English
0
2
10
735
Wes Lambert retweetledi
tuckner
tuckner@tuckner·
The extension was approved, now what? Are you going back tomorrow to see if it changed? You know they auto update instantly right? Rolling out to Secure Annex - code change alerts. This takes comparison of the code from the previous version along with additional context to understand how the code in an extension is changing over time.
tuckner tweet media
English
0
4
9
2K
Wes Lambert
Wes Lambert@therealwlambert·
The DHCP server...
Wes Lambert tweet media
Čeština
0
0
1
80
Wes Lambert retweetledi
tuckner
tuckner@tuckner·
Ransomware has appeared in the VS Marketplace and makes me worry. Clearly created through AI, it makes many mistakes like including decryption tools in extension. If this makes it into the marketplace through, what impact would anything more sophisticated cause? secureannex.com/blog/ransomvibe
English
3
30
114
62K
Wes Lambert retweetledi
tuckner
tuckner@tuckner·
The SleepyDuck code extension malware is an advanced remote access trojan allowing for remote command execution on any endpoint that installs it. Take down the C2 server? It uses an Ethereum contract to update its settings to a new endpoint. secureannex.com/blog/sleepyduc…
English
4
15
51
14.1K
The Haag™
The Haag™@M_haggis·
I know I hype Lua.. but today I was told about Tcl. Yep, see you soon.
English
5
0
13
2.6K
Wes Lambert retweetledi
Rapid7
Rapid7@rapid7·
Rapid7 recently observed threat actors misusing @velocidex. ⚠️ No vulnerability exists in the tool itself—the risk is in how attackers abuse it. To help org's detect misuse, Velociraptor deliberately creates easy to detect IOCs. Learn what to look for 👉 r-7.co/4g2JomU
English
0
7
12
2K
Josh Kamdjou
Josh Kamdjou@jkamdjou·
i have had about 10 cups of coffee today
English
2
0
6
363
Wes Lambert
Wes Lambert@therealwlambert·
@securitybrew So sorry to hear. Wishing you and your family peace and comfort.
English
0
0
2
38
Kate Brew
Kate Brew@securitybrew·
My mom died today. My fondest memory of her was car trips where she would define a word and ask me to use it in a sentence. She was an avid reader and so sharp mentally until the end.
English
39
0
70
2.6K
Wes Lambert retweetledi
Security Onion
Security Onion@securityonion·
Security Onion 2.4.160 now available including Playbooks, Guided Analysis, MCP Server, and more! Have you ever had an alert and were unsure of what to do next? In this release, when you expand an alert you'll see a new tab called Guided Analysis. This leverages Playbooks to show you plays associated with the alert. These plays include questions which help guide your investigation. Each question has an associated query and the results of that query will be automatically displayed to help you answer the question. This makes you faster and more efficient than ever before!
Security Onion tweet media
English
1
24
76
38K
Wes Lambert retweetledi
Sublime Security
Sublime Security@sublime_sec·
At Sublime, we don’t just build powerful detection tools 📷 — we empower the community to use them. Over the years, our users have created, tested, and contributed some incredible custom rules to our Core Feed. Today, we’re spotlighting a few standouts from the Sublime Community that help stop real threats in the wild and were added to our Core Feed. sublime.security/blog/community…
Sublime Security tweet media
English
0
4
14
740