JMP RSP

464 posts

JMP RSP banner
JMP RSP

JMP RSP

@0xffhh

offensive security addict. @falconforceteam co-founder. speed maniac.

เข้าร่วม Mart 2010
329 กำลังติดตาม389 ผู้ติดตาม
JMP RSP
JMP RSP@0xffhh·
@jsecurity101 @_xpn_ Exactly this! The ROI on c2 detections is super low. You need a lot of data, a lot of time and detection effort, and still are guaranteed to miss a lot of things. Detecting bad behavior has a waaay bigger ROI.
English
0
0
2
83
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
Detection has to move off of brittle C2 detections. Detect behaviors. I’m sorry but Merlin, Havoc, etc isn’t special. C2s are just containers to execute actions. Service creation is service creation. Process injection is process injection. The list goes on.
Nasreddine Bencherchali@nas_bench

I'm here to remind you that the most underrated and slept on C2 is actually Merlin. Been there for a long time and still have a very low detection rate across the board. You all be underestimating the power of low detections with go based stuff.

English
6
30
174
39.7K
Melvin langvik
Melvin langvik@Flangvik·
Might have to ask that AI to generate me some GODLIKE arguments if I’m ever to convince my misses i am keeping it 😂😂#PLAID trackday Norway in the near future @HackingLZ ?
Melvin langvik tweet media
English
2
0
8
0
JMP RSP
JMP RSP@0xffhh·
Having an implant running undetected on an edr protected machine is all cool, but detecting TAs is just ~20% about detecting their implant. Detecting the stuff they do with their implant is what matters way more. Local priv esc, cred dumping, lateral movement, etc. Just saying 🤷‍♂️
English
1
3
20
0
JMP RSP
JMP RSP@0xffhh·
@N7WEra @Jean_Maes_1994 #expats" target="_blank" rel="nofollow noopener">expatica.com/pt/finance/tax… 🤷‍♂️ Tl;dr very low tax rates for expats.
English
0
0
0
0
Jean
Jean@Jean_Maes_1994·
Well it's official filled in the paperwork to change tax residency from Belgium *BOO* to Portugal *ayyyyy* in 2023. Cya Belgium, you will not be missed xoxo
English
3
1
26
0
JMP RSP
JMP RSP@0xffhh·
@GayzeMay I’m still waiting for @KLM to respond. Same ‘no response’ on social media…
English
0
0
0
0
JMP RSP
JMP RSP@0xffhh·
Hey @KLM, i’m waiting for 6 months already for a claim to be handled. Don’t you think it’s about time to fix this? Already called you a few times and you keep saying ‘it’s busy’. So taking the shaming route now…
JMP RSP tweet media
English
0
0
4
0
Kwyjibo
Kwyjibo@KwyjiboUK·
Cyber friends, I need your help to locate a missing person. They sent this photo at 5:30 this morning, maybe in the mid Kent area. There's awesome folks in the hacking community that can pinpoint stuff like this.@UK_Daniel_Card @LisaForteUK @AppSecBloke any ideas who can help?
Kwyjibo tweet media
English
7
5
12
0
JMP RSP
JMP RSP@0xffhh·
@pati_gallardo Build a random go project as lib and statically link into your project? 🤷‍♂️😋
English
0
0
0
0
Yarden Shafir
Yarden Shafir@yarden_shafir·
Getting into this field I thought I'd be doing cool hacker shit but instead I'm sitting here reading about the differences between different types of binary trees
English
4
1
38
0
JMP RSP
JMP RSP@0xffhh·
Does anyone have a working .NET core gadget for a deserializing vulnerability with json.net? The documented .NET framework gadgets don’t work in core. #SharingIsCaring
English
0
0
0
0
JMP RSP
JMP RSP@0xffhh·
@ChenCravat / Raymond Chen is a genius! Every time i encounter something weird in windows, he has documented it 10+ years ago 🤷‍♂️😎
English
0
0
0
0
JMP RSP รีทวีตแล้ว
FalconForce Official
FalconForce Official@falconforceteam·
It’s #FalconFriday and summer is here! Take a refreshing dive into our newest blog, where we will shed some light on how Certipy and Rebeus work with UnPAC-the-hash and shadowing creds, and how to detect these techniques with our free #Kusto detections. medium.com/falconforce/fa…
FalconForce Official tweet media
English
1
10
19
0
JMP RSP
JMP RSP@0xffhh·
@n0x08 It’s more nuanced! Dependens on country/airport. Amsterdam allows you to leave everything in your bag. While many other eu airports require you to take stuff out. US is famous for shoes off, but was flying from SAN recently, and was allowed to leave liquids in the bag go figure🤷‍♂️
English
0
0
0
0
JMP RSP
JMP RSP@0xffhh·
@alisaesage Just wanted to say thanks for offering 10 spots for free for those who’re not fortunate enough to have an employer pay for it.
English
0
0
0
0
Alisa Esage Шевченко
Alisa Esage Шевченко@alisaesage·
Okay all, you win. I reserved 10 seats in the 4-day online class at the price 1500 Euro, only for those who are eager to make the most of it. How to ask: write a comment here explaining why you think you're the right person to get it. Keep DM opened so I could send you the link
English
18
4
41
0
JMP RSP
JMP RSP@0xffhh·
Does anyone know what the status is of API Monitor? Is in dead? Will it ever get an update or be open sourced? I have so many usecases and/or feature requests…🤯 Cc: @rohitab
English
0
1
3
0