Christopher Witter (@mr_cwitter) 's Twitter Profile
Christopher Witter

@mr_cwitter

PhD. Threat Hunting (School of Hard Knocks). Former Falcon Overwatch and DIB CSIRT. DFIR nerd, outdoor enthusiast, Maker. My thoughts are my own.

ID: 194687800

calendar_today24-09-2010 19:11:25

1,1K Tweet

710 Followers

779 Following

Marcus Bakker (@bakk3rm) 's Twitter Profile Photo

Published v0.3 of my KQL cheat sheet - updated all queries to work again with data in the LA Demo portal (except one query due to a lack of needed example data) - updated a few KQL function links - textual improvements Get your copy here: github.com/marcusbakker/K… #KQL #Sentinel

Published v0.3 of my KQL cheat sheet
- updated all queries to work again with data in the LA Demo portal (except one query due to a lack of needed example data)
- updated a few KQL function links
- textual improvements

Get your copy here: github.com/marcusbakker/K…

#KQL #Sentinel
SANS DFIR (@sansforensics) 's Twitter Profile Photo

ICYMI: Jaron Bradley joined @sechubb to discuss tips for finding persistence mechanisms and malicious processes in enterprise #macOS devices Listen here 👉🏾 sans.org/u/1mOS #BlueprintPodcast

ICYMI: <a href="/jbradley89/">Jaron Bradley</a> joined @sechubb to discuss tips for finding persistence mechanisms and malicious processes in enterprise #macOS devices

Listen here 👉🏾 sans.org/u/1mOS
#BlueprintPodcast
Jaron Bradley (@jbradley89) 's Twitter Profile Photo

TrueTree has been updated with some major code cleanup, better readability, and a --timeline mode that will simply print processes in order of their creation time. themittenmac.com/tools/

TrueTree has been updated with some major code cleanup, better readability, and a --timeline mode that will simply print processes in order of their creation time.
themittenmac.com/tools/
Christopher Witter (@mr_cwitter) 's Twitter Profile Photo

There are few jams I’ll have to wait for them to finish. If all you know of The Prodigy is their two main stream hits you’re seriously missing out. open.spotify.com/track/2RcKI41i…

Sublime Security (@sublime_sec) 's Twitter Profile Photo

You can now use MQL to detect HTML Smuggling attacks delivered via email body links. Detect+block+hunt for these techniques, recently observed to deliver Qakbot and other malware: - URL->Encrypted zip->ISO - URL->Zip->ISO->LNK - URL->Zip->IMG->VBS - and more How it works:

You can now use MQL to detect HTML Smuggling attacks delivered via email body links.

Detect+block+hunt for these techniques, recently observed to deliver Qakbot and other malware:
- URL-&gt;Encrypted zip-&gt;ISO
- URL-&gt;Zip-&gt;ISO-&gt;LNK
- URL-&gt;Zip-&gt;IMG-&gt;VBS
- and more

How it works:
Trevor Miller (@cyb3rdefender) 's Twitter Profile Photo

My team recently converted our entire detection library to #SIGMA and created a wiki around it! We are an MSSP & platform agnostic, meaning we have a version of a rule for pretty much every SIEM & EDR platform there is, and... 🧵1/3 Img: Thomas Roccia 🤘

My team recently converted our entire detection library to #SIGMA and created a wiki around it!

We are an MSSP &amp; platform agnostic, meaning we have a version of a rule for pretty much every SIEM &amp; EDR platform there is, and...

🧵1/3

Img: <a href="/fr0gger_/">Thomas Roccia 🤘</a>
Christopher Witter (@mr_cwitter) 's Twitter Profile Photo

This is a great thread. As a hiring manager I measure time as an IR consultant or at a decent MSSP/MDR provider in dog years… it isn’t a one for one experience. You will see, analyze, and investigate so much more in your X years in those environments vs. one company.

Ryan Jordan (@bigskyry) 's Twitter Profile Photo

Trail Days Online is for those who can’t afford the time or travel to attend an in-person event to celebrate the beautiful magic of spending time outdoors pursuing their passion for wilderness. backpackinglight.com/bpl-trail-days…

Trail Days Online is for those who can’t afford the time or travel to attend an in-person event to celebrate the beautiful magic of spending time outdoors pursuing their passion for wilderness. backpackinglight.com/bpl-trail-days…
Christopher Witter (@mr_cwitter) 's Twitter Profile Photo

I took a break from here after my beloved Tweetbot was killed. The user experience using the native client and the web are exponential worse but here I am <fingers crossed> it doesn't get worse.

Josh Liburdi (@jshlbrd) 's Twitter Profile Photo

what’s missing from this discussion is that different orgs have different requirements, and there are multiple levels of maturity for security visibility. 🧵

Sublime Security (@sublime_sec) 's Twitter Profile Photo

Defenders know their environments better than anyone, but they haven't been able to truly capitalize on that knowledge in email — until today. Sublime Platform is now generally available. Deploy in minutes using Docker, for free. sublime.security/blog/introduci…

Christopher Witter (@mr_cwitter) 's Twitter Profile Photo

I’ve been a defender most of my career and there are few tools that fundamentally changed the game for me (in chronological order): Netwitness Investigator, CrowdStrike, Splunk, Elastic Search. Last year I added Sublime to that list.

Christopher Witter (@mr_cwitter) 's Twitter Profile Photo

Last month Jack invited me on to the Detection at Scale podcast. I had a great time talking about my experiences building highly effective detection and response teams and operating at scale. open.spotify.com/episode/6fI401…

vx-underground (@vxunderground) 's Twitter Profile Photo

Our friends at SentinelOne were kind enough to hook us up and help us out. We have the opportunity to gift a talented researcher a valuable prize whereas without them the best we could do is a $5 coupon to Arbys. Submit your unique and novel research to s1.ai/vx-s1

Christopher Witter (@mr_cwitter) 's Twitter Profile Photo

Last year Jaron did a private training for my whole team. If you’re currently consuming MacOS telemetry and looking for ways to use it, like investigations or detection ideas there’s nothing else like this course.