Blake Regan (@crash0ver1d3) 's Twitter Profile
Blake Regan

@crash0ver1d3

Christian | #GirlDad | #BlueTeam | #DFIR | Leader | Blue Team Con Staff | My views != my employer
@ crash0ver1d3.bsky.social

ID: 1201560037296132100

linkhttps://blueteamtactics.net/ calendar_today02-12-2019 17:53:55

7,7K Tweet

743 Followers

703 Following

Moose (@litmoose) 's Twitter Profile Photo

Been using PayPal just because they've been around so long? Time to check your accounts. Don't see the option to NOT have your info sold? Likely you're listed as a business. There's no way to downgrade to a personal account, so make sure you delete your info before you close.

Been using PayPal just because they've been around so long? 
Time to check your accounts. 
Don't see the option to NOT have your info sold?
Likely you're listed as a business. There's no way to downgrade to a personal account,  so make sure you delete your info before you close.
Dray Agha (@purp1ew0lf) 's Twitter Profile Photo

Using the following simple cyberchef recipe for the encoded PwSh payloads coming from the attempted Cleo CVE-2024-50623 compromises we're detecting Huntress Copy/paste this base64 extrator for subsection: [a-zA-Z0-9+/=]{30,} Use the IPv4 regex option Blog soon come

Using the following simple cyberchef recipe for the encoded PwSh payloads coming from the attempted Cleo CVE-2024-50623 compromises we're detecting <a href="/HuntressLabs/">Huntress</a> 

Copy/paste this base64 extrator for subsection: [a-zA-Z0-9+/=]{30,}

Use the IPv4 regex option

Blog soon come
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph πŸ˜ƒ

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

Interested in all the new macOS malware of 2024!? πŸŽπŸ› I've started my annual "The Mac Malware of <Insert Year>" report. Each day, I'll be adding details of a new (for '24) malware ...including its infection vector, persistence, & capabilities. Follow: objective-see.org/blog/blog_0x7D…

Blake Regan (@crash0ver1d3) 's Twitter Profile Photo

Who can help me with Intune Scope Tags? Trying to make a custom role assigned to a scope tag to manage Intune Endpoint Security Antivirus policies and striking out with Device Management rights.

Blake Regan (@crash0ver1d3) 's Twitter Profile Photo

Who can help me with Intune Scope Tags? Trying to make a custom role assigned to a scope tag to manage Intune Endpoint Security Antivirus policies and striking out with Device Management rights. Nathan McNulty Joe Stocker ?

mRr3b00t (@uk_daniel_card) 's Twitter Profile Photo

Imagine having a firewall where you are one zero day away from total comprise πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚ Congrats you own a fortigate πŸ˜‚πŸ˜‚πŸ˜‚πŸ₯³πŸ₯³πŸ₯³πŸ₯³πŸ₯³

Dave Kennedy (@hackingdave) 's Twitter Profile Photo

Smart phish via github - email comes from github - issue is created on repo that suspicious activity was detected and to click link to revoke access. When you click the link its to give full permissions to that repo. If you didn't know it was an issue, might accidentally give

Smart phish via github - email comes from github - issue is created on repo that suspicious activity was detected and to click link to revoke access. 

When you click the link its to give full permissions to that repo. 

If you didn't know it was an issue, might accidentally give
Moose (@litmoose) 's Twitter Profile Photo

Hot take: If all you ever do is agree with your senior leadership, and they love you for it, you're not doing your job, and they're not doing their jobs. Good business and relationships are founded on open discourse, diversity of thought, and often a bit of friction.