Gabriel Landau (@gabriellandau) 's Twitter Profile
Gabriel Landau

@gabriellandau

Principal WinDbg’er @ Elastic. Thoughts are my own. Blogs tiny.cc/jqeavz @[email protected] @gabriellandau.bsky.social

ID: 91486079

calendar_today21-11-2009 02:53:15

1,1K Tweet

3,3K Followers

691 Following

Orange Cyberdefense Switzerland (@orangecyberch) 's Twitter Profile Photo

🛡️ In this blog post, Clément Labro and Romain extend the work of 🤷‍♂️ and demonstrate how Server Silos can be leveraged to exploit the #KsecDD #Windows driver, and achieve #admin-to-kernel even when LSA Protection is enabled. 👉 Discover more about it: ow.ly/438L50U4mAG

🛡️ In this blog post, <a href="/itm4n/">Clément Labro</a> and <a href="/PMa1n/">Romain</a> extend the work of <a href="/floesen_/">🤷‍♂️</a> and demonstrate how Server Silos can be leveraged to exploit the #KsecDD #Windows driver, and achieve #admin-to-kernel even when LSA Protection is enabled.

👉 Discover more about it: ow.ly/438L50U4mAG
Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

We’re adding a new section to Elastic’s HackerOne Bounty Program! Today, we’re opening our SIEM and EDR rules for testing. We’re excited to have another way to thank our community for their efforts on our #detectionengineering. Get more details here: go.es.io/4hdKQCI

Samir (@sbousseaden) 's Twitter Profile Photo

in a year period we had 50% increase in Elastic Defend endpoint behavior rules (coverage as well - 1000+) 💪 for all the 3 supported platforms Windows, macOS and Linux H/T DefSecSentinel Ruben Groenewoud Mika Ayenson Shashank and all the team ofc github.com/elastic/protec…

in a year period  we had 50% increase in Elastic Defend endpoint behavior rules (coverage as well - 1000+) 💪 for all the 3 supported platforms Windows, macOS and Linux H/T <a href="/DefSecSentinel/">DefSecSentinel</a> <a href="/RFGroenewoud/">Ruben Groenewoud</a> <a href="/stryker0x/">Mika Ayenson</a> Shashank and all the team ofc

github.com/elastic/protec…
Joe Desimone (@dez_) 's Twitter Profile Photo

Multi-Platform FINALDRAFT malware targeting government orgs. Outlook drafts for C2. We published a deep dive on the malware and another on the campaign. Great research by the team! elastic.co/security-labs/… elastic.co/security-labs/…

Multi-Platform FINALDRAFT malware targeting government orgs. Outlook drafts for C2.  We published a deep dive on the malware and another on the campaign. Great research by the team! elastic.co/security-labs/…
elastic.co/security-labs/…
Joe Desimone (@dez_) 's Twitter Profile Photo

A lot of fun techniques coming out of the mdsec crew! Fortunately, this one is fairly easy to spot github.com/elastic/protec…

Samir (@sbousseaden) 's Twitter Profile Photo

with #Elastic process events enriched with call stack info we can detect processes started via Windows+Run and with more than 1 argument (pretty rare especially when coupled with lolbins/cmd/ps)

with #Elastic process events enriched with call stack info we can detect processes started via Windows+Run and with more than 1 argument (pretty rare especially when coupled with lolbins/cmd/ps)
Connor McGarr (@33y0re) 's Twitter Profile Photo

If you are passionate about Windows OS internals; detection, software, and reverse engineering; debugging; and solving interesting problems, come join us Prelude Research jobs.ashbyhq.com/preludesecurit…

Matt Hand (@matterpreter) 's Twitter Profile Photo

The team at Prelude Research is looking for Windows internals researchers, reverse engineers, and people passionate about rethinking how we combat modern adversaries. Join us! jobs.ashbyhq.com/preludesecurit…

Samir (@sbousseaden) 's Twitter Profile Photo

new #elastic defend rules out : - PPL bypass via ComDotNetExploit - Execution via Windows-Run (trending delivery method ITW) github.com/elastic/protec…

new #elastic defend rules out :
- PPL bypass via ComDotNetExploit
- Execution via Windows-Run (trending delivery method ITW)
github.com/elastic/protec…
Andrea Allievi (@aall86) 's Twitter Profile Photo

techcommunity.microsoft.com/blog/windows-i… Finally! I personally worked on Hotpatch, together with my team 3 years ago... and now is finally approaching client versions of Windows... Yuuuyuuu!

Elastic Security Labs (@elasticseclabs) 's Twitter Profile Photo

Join John U to explore the concept of Execution Modality within #detections — specifically, how modality-focused detections can complement behavior-focused ones: go.es.io/4mgb5ve #ElasticSecurityLabs #detectionengineering

Samir (@sbousseaden) 's Twitter Profile Photo

nice research & high likely this will be abused ITW, new detections out using new term rule type to alert on first time seen SubjectUserName in last 10 days creating a new dMSA account or modifying the msDS-ManagedAccountPrecededByLink attribute. github.com/elastic/detect…

nice research &amp; high likely this will be abused ITW, new detections out using new term rule type to alert on first time seen SubjectUserName in last 10 days creating a new dMSA account or modifying the msDS-ManagedAccountPrecededByLink attribute.

github.com/elastic/detect…