Paul_sec (@paulsec4) 's Twitter Profile
Paul_sec

@paulsec4

Threat Hunting Lead

ID: 1100738060021649408

linkhttp://newtonpaul.com calendar_today27-02-2019 12:42:59

74 Tweet

259 Followers

187 Following

Paul_sec (@paulsec4) 's Twitter Profile Photo

Calling all Charlton Athletic fans, I have a selection of kit shirts on sale, including some stunning vintage shirts, with more to come! Check them out below! #cafc #Charlton ebay.co.uk/usr/paunewto_6…

Calling all Charlton Athletic fans, I have a selection of kit shirts on sale, including some stunning vintage shirts, with more to come! Check them out below! #cafc #Charlton 
 ebay.co.uk/usr/paunewto_6…
Paul_sec (@paulsec4) 's Twitter Profile Photo

New Blog Post!! In this one I show how and why you need to be doing threat hunting in your SOC! I also include some hunt & detection examples for Cobalt Strike and Impacket! #infosec #threathunting #cobaltstrike newtonpaul.com/a-guide-to-thr…

Jon Hencinski (@jhencinski) 's Twitter Profile Photo

And when a SOC analyst makes a wrong call, it's not on them. It's on me / the leadership team. We didn't arm you with the right context...OR The evidence in the alert wasn't good enough...OR We didn't provide enough training here. "We'll do better" Own it.

Paul_sec (@paulsec4) 's Twitter Profile Photo

New Blog Post! This is a short one, where I take a look at some sneaky phishing sites that avoid analysis by being Virtual Machine Aware. #phishing #CyberSecurity #infosec newtonpaul.com/virtual-machin…

Red Canary (@redcanary) 's Twitter Profile Photo

"Adversaries at all levels of sophistication use Cobalt Strike beacons, and this guide is an excellent resource for hunting those beacons:" - Tony Lambert

Kostas (@kostastsale) 's Twitter Profile Photo

This report on Cobalt Strike should serve as a guide to help defenders protect their networks. We have gathered all techniques & relevant detections in one writeup with some additional information to help our community. This is only a start with many more to come. #CobaltStrike

Paul_sec (@paulsec4) 's Twitter Profile Photo

Grateful for the shoutout! Hoping to push more content next year, providing threat actors chill and the day job quietens down. 😂#infosec

June (@junenotmary) 's Twitter Profile Photo

Because she's been on steroids for awhile now, her hair's not growing back as much (post haircut). 😭🥺 #CatsOfTwitter #cats

Because she's been on steroids for awhile now, her hair's not growing back as much (post haircut). 😭🥺 #CatsOfTwitter #cats
Paul_sec (@paulsec4) 's Twitter Profile Photo

Great thread showing how NOT to respond to an incident. Really highlights the need for a quick response and why having well trained analysts is so important.

June (@junenotmary) 's Twitter Profile Photo

Silver Chinchillas normally are fluffy but my baby is on steroids + chemo after having had her 2x a year haircut. So now, my cat Winter looks like she has a massive head because her fluffiness is focused on her head, and her tail. 😂

Silver Chinchillas normally are fluffy but my baby is on steroids + chemo after having had her 2x a year haircut. So now, my cat Winter looks like she has a massive head because her fluffiness is focused on her head, and her tail. 😂
Paul_sec (@paulsec4) 's Twitter Profile Photo

The goal of any top tier Threat Hunt process should be automated hunts, where pathways are taken to generate advanced threat leads and enrichment for analysts to triage. Here’s a great blog from Rob Lowery on how you can get started lowery.tech/threat-hunting…

Paul_sec (@paulsec4) 's Twitter Profile Photo

My first blog post in over two years, life has been keeping me busy. newtonpaul.com/svchost-analys… This quick post looks at triaging svchost making unusual DNS requests to infostealer C2 domains. #infosec #cyber #soc

Paul_sec (@paulsec4) 's Twitter Profile Photo

Following on from my last post on Microsoft Dev Tunnels, in this post, I take a look at similar functionality baked into VSCode. Remote Tunnels are increasingly being abused by threat actors, and allow for easy remote code execution. #CyberSecurity newtonpaul.com/vscode-remote-…