Shannon McHale (@_shannon_mchale) 's Twitter Profile
Shannon McHale

@_shannon_mchale

Red Team @ Mandiant/Google 👩🏻‍💻 Focused on hacking and protecting clouds. Presenter at DefCon, ShmooCon, WiCyS, and WiConnects. Ex-@RITSECclub President

ID: 1011355803234766848

linkhttps://github.com/Littlehack3r/awesome-gcp-pentesting/blob/main/README.md calendar_today25-06-2018 21:09:48

506 Tweet

1,1K Followers

692 Following

Cloud Village (@cloudvillage_dc) 's Twitter Profile Photo

Our #CFP for DEF CON ends in 2 days! Hurry up and get them papers in! Form - forms.gle/7594FC8oWBCf1p… Visit cloud-village.org for more details. #hackersummercamp #defcon #dc31

Our #CFP for <a href="/defcon/">DEF CON</a> ends in 2 days!
Hurry up and get them papers in!

Form - forms.gle/7594FC8oWBCf1p…

Visit cloud-village.org for more details.

#hackersummercamp #defcon #dc31
kat traxler 🎗️ (@nightmarejs) 's Twitter Profile Photo

Wanted to give folks a TLDR on this one because 1. Its one of the bigger GCP vulns to come out in a while (h/t Orca Security ) 2. I know most aren't that familiar with GCP and would benefit from a TLDR; 1/8

Justin Ibarra (@br0k3ns0und) 's Twitter Profile Photo

w00t! Come check us out at the DEF CON Cloud Village, where Terrance DeJesus and I will be sharing a demo tool talk about emulating attacks on #GoogleWorkspace #defcon31 #DetectionEngineering

w00t! Come check us out at the <a href="/defcon/">DEF CON</a> <a href="/cloudvillage_dc/">Cloud Village</a>, where <a href="/_xDeJesus/">Terrance DeJesus</a> and I will be sharing a demo tool talk about emulating attacks on #GoogleWorkspace

#defcon31 #DetectionEngineering
Clint Gibler (@clintgibler) 's Twitter Profile Photo

🪣 BucketLoot An automated bucket scanner for secrets * 30+ unique regexes built-in * Search custom keywords * Perform asset extraction * Compatible with AWS, Google Cloud Storage & DigitalOcean Spaces By Umair #bugbountytips #CloudSecurity github.com/redhuntlabs/Bu…

🪣 BucketLoot

An automated bucket scanner for secrets

* 30+ unique regexes built-in
* Search custom keywords
* Perform asset extraction
* Compatible with AWS, Google Cloud Storage &amp; DigitalOcean Spaces

By <a href="/0x9747/">Umair</a>

#bugbountytips #CloudSecurity

github.com/redhuntlabs/Bu…
Shannon McHale (@_shannon_mchale) 's Twitter Profile Photo

Had so much fun recording Cloud Security Podcast we talked about learning to hack GCP and some of the common attack paths Ofc always repin RITSEC Club and stay tune to the end for a mandatory shoutout to my mom and the #CeliacsInCyber (which I just made up) youtube.com/watch?v=SqfDFI…

Shannon McHale (@_shannon_mchale) 's Twitter Profile Photo

Best training ever!!!! Thank you Dirk-jan and Sanne for teaching me all your Azure AD hacking brilliance. My brain feels 10x bigger 🧠 10/10 really recommend this to others

Best training ever!!!! Thank you <a href="/_dirkjan/">Dirk-jan</a> and <a href="/sannemaasakkers/">Sanne</a> for teaching me all your Azure AD hacking brilliance. My brain feels 10x bigger 🧠

10/10 really recommend this to others
Karl (@kfosaaen) 's Twitter Profile Photo

For those that missed our DEF CON Cloud Village talk - "What the Function: A Deep Dive into Azure Function App Security" Here is a quick thread of the code/slides/blog that we released over the weekend. 🧵(1/4)

Cloud Village (@cloudvillage_dc) 's Twitter Profile Photo

Howdy Folks, It took us a while but we finally got there! :) In case you missed the YouTube notification, our first day's recording for DEF CON 31 is out. Hope you enjoy the interesting research shared by our amazing speakers! Day1 Playlist - youtube.com/playlist?list=… #DEFCON31

Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile Photo

Fun with Google Cloud's default service accounts (and how to leverage them for offensive purposes) securitylabs.datadoghq.com/articles/googl…

BlackAlps (@blackalpsconf) 's Twitter Profile Photo

🎥 RECORDED TALK #BlackAlps24 🎥 ⚡⚡⚡ GCP CL-WHY: The Hacker's and the Hero's Guide to the CLI ⚡⚡⚡ by Shannon McHale (Shannon McHale), Senior Red Team Consultant at Google youtu.be/nr4G1ekjrqY #conference #cybersecurity #switzerland

SpecterOps (@specterops) 's Twitter Profile Photo

Take a journey in Administrative Unit Attack Paths! Check out Katie Knowles's #SOCON2025 talk, which starts w/ scoped role assignments for privilege escalation against users & groups and finishes w/ protecting accounts using Restricted Management AUs. 👀: ghst.ly/4ksxiEx

Google Cloud Security (@googlecloudsec) 's Twitter Profile Photo

Most companies find out about weaknesses too late. Mandiant (part of Google Cloud) Red Teamers use offensive security to spot and fix vulnerabilities before attackers can exploit them. See how they help organizations stay ahead and learn more: bit.ly/4o3OnGp