Markus Speckmeier (@msitc) 's Twitter Profile
Markus Speckmeier

@msitc

msitc-shop.com/content/impres…

ID: 38522309

linkhttp://www.ms-it-consulting.biz calendar_today07-05-2009 21:32:37

479 Tweet

17 Followers

130 Following

Ismael Valenzuela (@aboutsecurity) 's Twitter Profile Photo

Minjector & Memhunter: learning code injection techniques and hunting memory resident malware like a boss (aka at scale) by my friend and McAfee colleague Marcos Oviedo - github.com/marcosd4h/memh… #DFIR #ThreatHunting

TrustedSec (@trustedsec) 's Twitter Profile Photo

Magic Unicorn 3.8.1 released. Adds new method for platform detection, obfuscation, and a fix for python2 raw_input when using AMSI bypass. GitHub.com/TrustedSec/Uni… #TrustedSec

dylan (@_batsec_) 's Twitter Profile Photo

My first blog post! Bypassing AV via in-memory PE execution. I've created a tool to go along with the post and help automate creating undetected PEs, links inside the post 😉 blog.dylan.codes/bypassing-av-v…

Markus Speckmeier (@msitc) 's Twitter Profile Photo

Unterstützung durch MSITC bei der Einrichtung von Nextcloud für KMU und Homeuser ms-it-consulting.biz/blog/2020/01/u…

michal Naka (@michalnaka) 's Twitter Profile Photo

An Italian hospital ran out of ICU valves. A local biz brought a 3D printer to the hospital, redesigned & produced the valves in a few hours. “At the time of writing, 10 patients are accompanied in breathing by a machine that uses a 3D printed valve.” 3dprintingmedia.network/covid-19-3d-pr…

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

RedMimicry Actor Emulation and Breach Simulation Tool by Alexander Rausch - a great example of how to do it right - vetting - watermarked - YARA and Sigma rules redmimicry.com

RedMimicry
Actor Emulation and Breach Simulation Tool
by <a href="/ReleasePreview/">Alexander Rausch</a>

- a great example of how to do it right
- vetting
- watermarked 
- YARA and Sigma rules

redmimicry.com
Robert Neel (@redeemedhacker) 's Twitter Profile Photo

Today: On an endpoint with the most well-known EDR. NtdsAudit.exe blocked. Renamed to pentest.exe, echo 0 >> pentest.exe, pulled back down. No more blocking or alerts. I guess they haven't seen: penconsultants.com/home/binary-fi… Bonus: reversible encryption for the win.

James Smith 🇺🇦 (@dfirmadness) 's Twitter Profile Photo

#DFIR Pros, noobs, and #infosec junkies - the final walkthrough necessary to answer all of the big questions surrounding the case of the stolen Szechuan Sauce is complete! Learn how to enrich disk image timelines with events pulled from the memory image! dfirmadness.com/case-001-super…