#ff0000 (@_eternalred) 's Twitter Profile
#ff0000

@_eternalred

Private Figure || DFIR || Thrunter || Naughty Program Researcher || Malware Secret Admirer 🖤

ID: 1272855571645911041

linkhttp://always-ti.red calendar_today16-06-2020 11:36:44

1,1K Tweet

68 Followers

375 Following

#ff0000 (@_eternalred) 's Twitter Profile Photo

You know how senior devs retire and other devs have to pick up their projects… imagine being an APT and the code is obfuscated 😅

NASA InSight (@nasainsight) 's Twitter Profile Photo

My power’s really low, so this may be the last image I can send. Don’t worry about me though: my time here has been both productive and serene. If I can keep talking to my mission team, I will – but I’ll be signing off here soon. Thanks for staying with me.

My power’s really low, so this may be the last image I can send. Don’t worry about me though: my time here has been both productive and serene. If I can keep talking to my mission team, I will – but I’ll be signing off here soon. Thanks for staying with me.
Riot Games (@riotgames) 's Twitter Profile Photo

Earlier this week, systems in our development environment were compromised via a social engineering attack. We don’t have all the answers right now, but we wanted to communicate early and let you know there is no indication that player data or personal information was obtained.

Hillai Ben-Sasson (@hillai) 's Twitter Profile Photo

I hacked into a @Bing CMS that allowed me to alter search results and take over millions of Office 365 accounts. How did I do it? Well, it all started with a simple click in Microsoft Azure… 👀 This is the story of #BingBang 🧵⬇️

I hacked into a @Bing CMS that allowed me to alter search results and take over millions of <a href="/Office365/">Office 365</a> accounts.
How did I do it? Well, it all started with a simple click in <a href="/Azure/">Microsoft Azure</a>… 👀
This is the story of #BingBang 🧵⬇️
Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

So, a TA offers a tool that kills all EDRs/AVs and all we got is a short video clip All we know is it uses the HxD icon & is named "terminator" Let's write a YARA rule to detect it (& other malware using the HxD icon) Report linkedin.com/feed/update/ur… YARA github.com/Neo23x0/signat…

So, a TA offers a tool that kills all EDRs/AVs and all we got is a short video clip

All we know is it uses the HxD icon &amp; is named "terminator"
Let's write a YARA rule to detect it (&amp; other malware using the HxD icon)

Report
linkedin.com/feed/update/ur…

YARA
github.com/Neo23x0/signat…
Elli Shlomo (IR) (@ellishlomo) 's Twitter Profile Photo

Gather information about email events related to malware/phishing threats and get detailed information about each recipient. EmailEvents | where Timestamp > ago(10d) | where ThreatTypes has "Malware" or ThreatTypes has "Phish" | where DeliveryAction != @"Blocked" | join

Gather information about email events related to malware/phishing threats and get detailed information about each recipient.

EmailEvents
| where Timestamp &gt; ago(10d)
| where ThreatTypes has "Malware" or ThreatTypes has "Phish"
| where DeliveryAction != @"Blocked"
| join
TryHackMe (@realtryhackme) 's Twitter Profile Photo

We're giving away FREE one-month access to our AWS Cloud Security Training to four lucky subscribers. You asked, we listened! 😉🔥 All you have to do is like and retweet👇 Winners will be chosen at random on Facebook, Twitter, LinkedIn and Instagram. Good luck!

Tib3rius (@0xtib3rius) 's Twitter Profile Photo

I lose a tiny amount of respect for a person when I hear them say "sequel" instead of SQL, and I'm not ashamed to admit it. 😛

an0n (@an0n_r0) 's Twitter Profile Photo

found Mimikatz dpapi::chrome (for decrypting chrome/msedge secrets) fails with No Alg/Key handle error now. seems to be the encrypted_key parser from the Local State file is broken. no worries, it is possible to feed it with the encrypted_key directly, here is what I mean.👇

found Mimikatz dpapi::chrome (for decrypting chrome/msedge secrets) fails with No Alg/Key handle error now. seems to be the encrypted_key parser from the Local State file is broken. no worries, it is possible to feed it with the encrypted_key directly, here is what I mean.👇