Tom (@anduinswim) 's Twitter Profile
Tom

@anduinswim

Threat hunting, ML and automation at @countercept / @WithSecure. Views are my own.

ID: 1547541396315316225

calendar_today14-07-2022 11:21:26

9 Tweet

40 Followers

44 Following

John Lambert (@johnlatwc) 's Twitter Profile Photo

ICYMI, if graph visualization and investigation together pique your interest, watch this talk by Tom Tom & Giulio Giulio Ginesi of WithSecure™ on Detectree. It began life as a Matteo Donini Notebook! 📺youtube.com/watch?v=EBVhGs… 🕹️labs.withsecure.com/tools/detectree 🔗github.com/countercept/de…

ICYMI, if graph visualization and investigation together pique your interest, watch this talk by Tom <a href="/AnduinSwim/">Tom</a> &amp; Giulio <a href="/Blazef104/">Giulio Ginesi</a> of <a href="/WithSecure/">WithSecure™</a> on Detectree. It began life as a <a href="/Jupyter/">Matteo Donini</a> Notebook!
📺youtube.com/watch?v=EBVhGs…
🕹️labs.withsecure.com/tools/detectree
🔗github.com/countercept/de…
Jack 💤 (@threebluezs) 's Twitter Profile Photo

So #Emotet is back once again with the traditional Email -> XLS -> XLM -> Regsvr -> Dll execution flow. IoCs are readily available checking the hashtag but as a group known to use 'hashbusting', let's complement these IoCs with some hunting #mde 🧵

Jack 💤 (@threebluezs) 's Twitter Profile Photo

Are you ever in the midst of reviewing web browser logs only to find yourself desperate to write some SQL? Me neither, so I wrote a python script to do it instead. Convert web browser history DBs into more human-readable .CSVs with BrowserDBParser github.com/CyberGoatherde…

LLM Security (@llm_sec) 's Twitter Profile Photo

* People ask LLMs to write code * LLMs recommend imports that don't actually exist * Attackers work out what these imports' names are, and create & upload them with malicious payloads * People using LLM-written code then auto-add malware themselves vulcan.io/blog/ai-halluc…