Sebastian Walla

161 posts

Sebastian Walla

Sebastian Walla

@SebastianWalla

Did a Cybersecurity Bachelor and Master in Computer Science with a focus on Security. Deputy Manager - Cloud Threat Intelligence Opinion/Thoughts are my own.

Deutschland เข้าร่วม Temmuz 2011
618 กำลังติดตาม208 ผู้ติดตาม
Sebastian Walla รีทวีตแล้ว
Dirk-jan
Dirk-jan@_dirkjan·
The next public edition of my "Offensive Entra ID" course will take place from June 8th to 11th in The Hague! Tickets are now available via events.outsidersecurity.nl/entra-26-07/. Last time the tickets sold out in a few weeks, so don't wait too long if you want to secure a spot.
English
0
24
78
9.5K
Phil Venables
Phil Venables@philvenables·
I'm on the conference committee/review board for [un]prompted, a new AI security practitioner conference, happening on the 3rd-4th of March, in SF. Event focused on what actually works in AI security, from tools. strategy, to offense and defense. Submit a talk and/or sign up. unpromptedcon.org
English
1
3
27
5.9K
Sebastian Walla
Sebastian Walla@SebastianWalla·
One thing I mentioned on the podcast that I will be speaking more about at @fwdcloudsec NA are trusted relationship compromises in the cloud: #when-your-partner-betrays-you" target="_blank" rel="nofollow noopener">fwdcloudsec.org/conference/nor… So come see my talk if you are interested and I heard there are still a few tickets available.
Sebastian Walla@SebastianWalla

Had a great time speaking about cloud-conscious threat actors with Cristian Rodriguez and Adam Meyers on the adversary universe podcast.

English
0
1
7
273
Sebastian Walla รีทวีตแล้ว
RE//verse
RE//verse@REverseConf·
Don’t miss Cindy Xiao’s talk on Reconstructing Rust Types from RE//verse 2025 if you’re dealing with Rust in your day to day. It’s one worth adding to your watchlist: youtu.be/SGLX7g2a-gw?fe…
YouTube video
YouTube
RE//verse tweet media
English
1
30
85
5.6K
Sebastian Walla รีทวีตแล้ว
Scott Piper
Scott Piper@0xdabbad00·
The CFP for fwd:cloudsec closes this Friday (11:59 pm Mountain Daylight Time)! This is a conference for practitioners, which means that if you work in cloud security, you have something to say that we're interested in! fwdcloudsec.org/conference/nor…
English
0
11
17
1.8K
Sebastian Walla
Sebastian Walla@SebastianWalla·
Had a great time presenting an overview of the most prevalent techniques of cloud-conscious cases at @fwdcloudsec's very first EU edition. The organizers did a great job! It felt just like the US version and was excellent to catch up and meet new people
Sebastian Walla tweet media
English
2
0
13
340
fwd:cloudsec
fwd:cloudsec@fwdcloudsec·
Ticket sales for fwd:cloudsec Europe will open up in a few days! Tickets are (very) limited, mark your calendars for next Monday at 9:00 and 19:00 CEST, we’ll release the tickets in two batches.
English
1
10
16
3.7K
Sebastian Walla
Sebastian Walla@SebastianWalla·
@AmitaiCo @christophetd @jason_trost I think that is because a majority of the container focused threat intelligence in open source is based on honeypot data, which exposes the Docker API for initial access.
English
1
0
1
93
Amitai Cohen
Amitai Cohen@AmitaiCo·
@christophetd Good point - now that I think about it, all the in-the-wild examples I'm familiar with have an exposed API server as their initial access point... btw as @jason_trost mentioned the Cloud SQL issue, there was a similar issue in Alibaba (cloudvulndb.org/brokensesame).
English
1
0
3
106
Christophe Tafani-Dereeper
Christophe Tafani-Dereeper@christophetd·
Are container escape vulnerabilities actually a thing in the wild? I've only be able to find weak evidence of exploitation of the CVE-2019-5736 vulnerability in runC, but that's all.
English
11
5
30
9.8K
Sebastian Walla
Sebastian Walla@SebastianWalla·
@christophetd Tl;Dr We very rarely observe exploitation. This might be a visibility problem as fewer people are monitoring their hosts and containers using runtime protection as well as the short live of containers, which could mean the container is gone before incident response arrives.
English
0
0
1
89
Sebastian Walla รีทวีตแล้ว
fwd:cloudsec
fwd:cloudsec@fwdcloudsec·
We’re excited to announce the European version of the conference: fwd:cloudsec Europe! It will take place on the 17th of September 2024 in Brussels, Belgium. CFP and registration will open in Spring, stay tuned!
fwd:cloudsec tweet media
English
4
25
95
22.7K
Sebastian Walla รีทวีตแล้ว
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
I'm thrilled to announce that we're bringing the @fwdcloudsec experience to Europe. We can only achieve this with the help of our community. I hope to see some of you there! Thanks to everyone who has made this possible.
fwd:cloudsec@fwdcloudsec

We’re excited to announce the European version of the conference: fwd:cloudsec Europe! It will take place on the 17th of September 2024 in Brussels, Belgium. CFP and registration will open in Spring, stay tuned!

English
0
4
23
1.3K
Sebastian Walla
Sebastian Walla@SebastianWalla·
I only had to modify the number of base32 decoded characters to truncate after 16 chars (following the 4 char prefix) i.e. b32decode(aws_id[4:20])
English
0
0
1
172
Sebastian Walla
Sebastian Walla@SebastianWalla·
Thanks to the recent @trufflesec interview with @TalBeerySec I came across his post to derive AWS account ids from AWS key ids: @TalBeerySec/a-short-note-on-aws-key-id-f88cc4317489" target="_blank" rel="nofollow noopener">medium.com/@TalBeerySec/a… Not sure if every reader knew this but his algorithm also works for other AWS IDs. I tested AGPA,AIDA,AIPA,AKIA,ANPA,AROA,ASIA
English
3
7
16
2.9K
Sebastian Walla
Sebastian Walla@SebastianWalla·
Are you not interested in analyzing/documenting cloud-conscious threat actor activities but would rather help catch them via honeypots and search/reproduce vulnerabilities at cloud service providers? (6/7)
English
1
0
0
59
Sebastian Walla
Sebastian Walla@SebastianWalla·
feel free to reach out to me via direct message. Note that I’m not the hiring manager. We had to specify a region for our hiring portal which is why it states USA-/Canada-Remote. While this would be ideal to increase our window of coverage, (4/7)
English
1
0
0
45
Sebastian Walla
Sebastian Walla@SebastianWalla·
Together we would be the first to analyze cloud activity logs to discover and document new techniques such as persistence via identity federation (cisa.gov/news-events/cy…). If you have any questions, (3/7)
English
1
0
0
49