Full StackOverflow Developer

The Land of Pleasant Living
Joined August 2017
I hate C, but I'm addicted...
3
7
I did not find my room
10
It's about time to blow the dust off of the ol' blog and write a new post soon...👀
2
22
Invest in the things that actually matter: - the needs of your family, dependents, and yourself - experiences with those who are most important such as family and friends - the betterment of yourself in whatever drives you and makes you truly happy
Replying to @SwiftOnSecurity
Nice car? Trust me barely anybody even looks. It's four wheels, maybe you have a cool color. Nice watch? They assume it's fake. If you want these things and value them, you have to accept it will mostly just be you who cares. And that should be fine, because it's not for Them.
Show this thread
1
12
Start with Python to learn programming they say. That's good, but don't ever stop programming in Python. It is an amazing language for most disciplines in cyber. I still use it all the time.
7
2
1
26
💯 Those DCs aren't going anywhere...and they will still be there when orgs move away from the cloud and back to on-prem 🤣
Active Directory is being obsoleted and replaced by Azure AD in the same sense that IPv4 is obsoleted and replaced by IPv6
3
26
bohops retweeted
@frodosobon 's blog is quite good and very underrated Check it out 👇 waawaa.github.io/
2
4
13
A fun alternative way to find child process execution of a certain process via BAM. You can use the "HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\<SID>\<Binary>" RegistrySet event to track child process created by a process. #dfir #detection
1
44
2
107
I’m excited to kick the morning off by announcing the release of 🍎 Living Off the Orchard: macOS Binaries (LOOBins)! loobins.io You can find more details about the LOOBins project in my “Introducing LOOBins” Medium post here: infosecb.medium.com/introduc…
6
196
11
519
Show this thread
Replying to @bohops
And for those with Sentinel/Defender for Endpoint, here's a great example of how we can leverage this project in our queries :)
Oh hell yeah, this is cool! DeviceNetworkEvents | where RemoteIPType == "Public" | where InitiatingProcessVersionInfoOriginalFileName in (( externaldata ( Name:string ) [ "lolbas-project.github.io/api…" ] with (format=csv, ignoreFirstRecord=true) | distinct Name )) #MDE
Show this thread
1
4
15
I've seen a lot of chatter about Living-Off-The-Land (LOL/LOTL) attacks and techniques on the socials this week. For background info, use cases, and offensive/defensive references, the LOLBAS project has you covered: lolbas-project.github.io/
1
16
1
65
Dynamic PInvoke without DefinePInvokeMethod ...👀
4
4
37
Really cool .NET loader for dynamic invocation and an excellent Yara rule. Great work @dr4k0nia!
I'm joining the dark side, today I'm publishing a malware loader called NixImports. It uses API-Hashing and dynamic invoking to evade static analysis. Check out my blog post for more details: dr4k0nia.github.io/posts/Nix…
Show this thread
2
3
13
🔥Updated WDACConfig module. @M_haggis & @nas_bench you can now automatically create a base policy denying all #LOLDrivers and deploy it too if you want. More info on GitHub: github.com/HotCakeX/Harden-W… Download from PowerShell gallery (self-updates): powershellgallery.com/packag… #WDAC
1
11
45
1,519
bohops retweeted
Slides from our Active Directory & DNS (ADIDNS) talk at BSidesCharm 2023 are up. AD & DNS: A Match Made in Heck I believe video will be released soon(ish).
Did you happen to miss @dotdotdotHorse & @JimSycurity @BSidesCharm? Well good news, you can view their abstract and download slides for their talk "AD & DNS: A Match Made In Heck" right now on the Trimarc content page. No registration required. Enjoy! hub.trimarcsecurity.com/post…
1
14
1
45
Show this thread
IcedID Macro Ends in Nokoyawa Ransomware ➡️Initial Access: IcedID XLS Macro ➡️Credentials: LSASS, Creds in Files ➡️Persistence: Scheduled Task ➡️Lateral: RDP, SMB, WMI, WinRM, Psexec ➡️C2: IcedID, Cobalt Strike, VNC ➡️Impact: Nokoyawa Ransomware thedfirreport.com/2023/05/22… 1/X
2
142
8
269
Show this thread