Evan Reese

72 posts

Evan Reese banner
Evan Reese

Evan Reese

@reesespcres

Los Angeles, CA Присоединился Nisan 2018
249 Подписки526 Подписчики
Evan Reese ретвитнул
x0rz
x0rz@x0rz·
@JackRhysider You can evade an EDR, but you can’t evade a big nerd rawdogging wireshark
English
15
61
978
29.1K
Evan Reese ретвитнул
Jared Wilson
Jared Wilson@JWilsonSecurity·
🔥New APT41 Methodologies 🔥 While DUSTTRAP was really interesting, analyzing the methodologies observed alongside SQLULDR2 and PINEGROVE were fascinating. Both families highlight very specific methodologies worth hunting for. Check the blog for details! cloud.google.com/blog/topics/th…
English
1
30
58
8.2K
Evan Reese ретвитнул
Steve YARA Synapse Miller
Steve YARA Synapse Miller@stvemillertime·
Files are just extra large packets.
English
7
7
50
6.4K
Evan Reese ретвитнул
Matthew Dunwoody
Matthew Dunwoody@matthewdunwoody·
I love to see the fantastic contributions from the @Mandiant Intelligence #AdversaryMethods Research & Discovery team! Identifying and classifying attacker methodologies at scale! 🔥🔥
Willi Ballenthin@williballenthin

capa v6 released with 26 new rules, including: shellcode techniques, mailslot interaction, service manipulation, exchange plug-ins, and AMSI & ETW patching. github.com/mandiant/capa/…

English
0
12
29
5.6K
Evan Reese ретвитнул
Jared Wilson
Jared Wilson@JWilsonSecurity·
"If the technical sleight of hand is successful, the adversary will achieve persistence by means of malicious Chromium-based browser extensions" 🌶️ dissect adversary methodologies 🔥 identify malware families 💥highlight detection opportunities mandiant.com/resources/blog…
English
2
45
92
16.6K
Evan Reese
Evan Reese@reesespcres·
@ImposeCost Good question, hindsight bias is a thing
English
0
0
3
0
Evan Reese ретвитнул
Steve Elovitz
Steve Elovitz@SElovitz·
Looking to add a manager to @Mandiant's IR team in DC. Let me know if interested, DMs are open.
English
1
26
44
0
Evan Reese ретвитнул
Jared Wilson
Jared Wilson@JWilsonSecurity·
Sometimes you just want to hunt 🔫 Three excellent technologies to investigate are... - VPN Clients - Proxy Services - Localhost Tunneling Read along to further expand the defender’s hunting and detection repertoire against these three troublemakers. mandiant.com/resources/burr…
English
4
71
200
0
Evan Reese ретвитнул
Alyssa (she/her)
Alyssa (she/her)@ramen0x3f·
🚨🚨Today I'm releasing THIRI - a Jupyter notebook for rapidly prototyping threat hunting rules: github.com/mandiant/thiri… THIRI is designed to be super intuitive and even easier to extend than past tools like my own HeySerial. Check out the README for all the deets!
English
10
211
628
0