Niklas Särökaari

465 posts

Niklas Särökaari banner
Niklas Särökaari

Niklas Särökaari

@ukk1sec

Detection engineering and threat hunting

Helsinki Katılım Ağustos 2013
86 Takip Edilen427 Takipçiler
Niklas Särökaari retweetledi
mpgn
mpgn@mpgn_x64·
The redteam when they do social engineering over the phone and the client download and execute the file "invoice.pdf.exe"
English
8
182
1.1K
106.9K
Niklas Särökaari retweetledi
Jon Hencinski
Jon Hencinski@jhencinski·
A good detection includes: - Clear aim (e.g, remote process exec on DC) - Unlocks end-to-end workflow (not just alert) - Automation to improve decision quality - Response (hint: not always contain host) - Volume/work time calcs - Able to answer, “where does efficacy need to be?”
English
5
50
198
0
Niklas Särökaari retweetledi
briankrebs
briankrebs@briankrebs·
A lot of security pros have remarked that this breach vs #Uber looks, quacks and walks like activity from the LAPSUS$ data theft/ransom group that got busted up earlier this year. But the truth is LAPSUS$ gave others a playbook for getting into F500 companies that reliably works.
English
3
6
74
0
Niklas Särökaari
Niklas Särökaari@ukk1sec·
Unfortunately this stuff still works and RTs usually goes the extra mile 😅
English
0
0
1
0
Taneli Kaivola
Taneli Kaivola@dist·
Excellent technical talk about business email compromise case in Microsoft environment by @ukk1sec at @HelSecurity meetup. Available on Youtube later I think!
English
2
0
15
0
Joosua Santasalo
Joosua Santasalo@SantasaloJoosua·
Some great stuff here by @reprise_99 - I've felt semi proficient in KQL, but just found out I can forgo joins in certain queries completely by just reading Matt's stuff - What else have I missed, need to check more :) Be sure to tag this repo! github.com/reprise99/Sent…
English
2
4
23
0
Niklas Särökaari retweetledi
Sean Metcalf
Sean Metcalf@PyroTek3·
Scott on the @TrimarcSecurity team wrote this much needed & excellent article on how best to protect an Active Directory environment & it's more than just AD. Article covers protecting workstations/servers including GPO configuration. This is a must read hub.trimarcsecurity.com/post/implement…
Trimarc@TrimarcSecurity

New article from @ScottWBlake on protecting privileged credentials in an Active Directory environment. Recommendations: * Limit # of priv accounts * Remove DA local admin rights * Control systems DAs & EAs can access * Ensure local admin pw changes often trimarc.co/tw-ProtectingP…

English
2
49
123
0
Iiro Uusitalo ✳️
Iiro Uusitalo ✳️@iiuusit·
Eilen katkesi Team ROTin voittoputki LähiTapiola hackdayssa. Onnea - @ukk1sec ja muut! 🙏 Järjettömän hyvä fiilis jäi kyllä Hackdaystä kiitos järjestäjille ja tuomareille. Tommi Läntisen yllätys kyllä kruunasi kaiken.
Suomi
2
2
37
0
Niklas Särökaari retweetledi
Runa Sandvik
Runa Sandvik@runasand·
In the series of “books I wish I’d read sooner” is @networkattack’s Network Attacks and Exploitation: A Framework. I really appreciate the solid examples and the focus on humanity throughout. amazon.com/Network-Attack…
English
2
12
70
0