Brian Carroll (@n3tsurge) 's Twitter Profile
Brian Carroll

@n3tsurge

CTO/Security Engineer/Defender | Creator of @reflexsoar | Blue & Red Team | #GPEN #GWAPT #GDAT #GCDA #GSEC | Thoughts are my own.

ID: 3415070049

linkhttp://netsurge.sh calendar_today11-08-2015 12:23:56

380 Tweet

154 Takipçi

289 Takip Edilen

Hiren Sadhwani (@hir3n_s) 's Twitter Profile Photo

Very excited to share the news with you all that I'll be speaking at SANS #BlueTeamSummit next month on "Hunting OneNote Malware - A Practical Guide for Blue Teams" Register now for the event: sans.org/u/1paV SANS Cyber Defense 🧢 SANS Institute #ThreatHunting #DFIR #BlueTeam

Very excited to share the news with you all that I'll be speaking at SANS #BlueTeamSummit next month on "Hunting OneNote Malware - A Practical Guide for Blue Teams"

Register now for the event: 
sans.org/u/1paV

<a href="/SANSDefense/">SANS Cyber Defense 🧢</a> <a href="/SANSInstitute/">SANS Institute</a> 
#ThreatHunting #DFIR #BlueTeam
Stef Rand (@techiestef) 's Twitter Profile Photo

On June 12 I’ll virtually present a new talk at one of my fave events of the year, the SANS Cyber Defense 🧢 Blue Team Summit, on a topic near & dear to my heart: splitting hairs about where malware delivery vehicles stop & their payloads start! Register here! sans.org/cyber-security…

On June 12 I’ll virtually present a new talk at one of my fave events of the year, the <a href="/SANSDefense/">SANS Cyber Defense 🧢</a> Blue Team Summit, on a topic near &amp; dear to my heart: splitting hairs about where malware delivery vehicles stop &amp; their payloads start!

Register here! sans.org/cyber-security…
H & A Security Solutions | Securitymapper (@securitymapper) 's Twitter Profile Photo

Hey #blueteam, I'm looking to add to the team. We have an Elastic/OpenSearch Engineer position open. The position is all about making an active, usable SIEM that has proper parsing, normalization, visualizations, alert, and MITRE coverage. indeed.com/job/elasticope…

Fletus (@fletusposton) 's Twitter Profile Photo

SANS Blue Team Summit is a month away! Please register today! It is virtual and free. I am looking forward to Stef Rand talk and you should be too! sans.org/cyber-security…

SANS Blue Team Summit is a month away! Please register today! It is virtual and free. I am looking forward to <a href="/techieStef/">Stef Rand</a> talk and you should be too! sans.org/cyber-security…
SANS Cyber Defense 🧢 (@sansdefense) 's Twitter Profile Photo

The SANS #BlueTeamSummit brings together #InfoSec professionals on the front line of defending an organization's critical assets and systems against attacks and threats from adversaries. Join us Live Online for FREE June 12-13! ➡️ Register here: sans.org/u/1paL

The SANS #BlueTeamSummit brings together #InfoSec professionals on the front line of defending an organization's critical assets and systems against attacks and threats from adversaries.

Join us Live Online for FREE June 12-13!

➡️ Register here: sans.org/u/1paL
Fletus (@fletusposton) 's Twitter Profile Photo

Looking forward to hearing more nuggets from Carson Zimmerman on "How to Save Your SOC from Stagnation" come join us at the SANS #BlueTeamSummit in June! sans.org/cyber-security…

Looking forward to hearing more nuggets from Carson Zimmerman on "How to Save Your SOC from Stagnation" come join us at the SANS #BlueTeamSummit in June! sans.org/cyber-security…
Fletus (@fletusposton) 's Twitter Profile Photo

Is your SOC facing burnout and high turn? Come join us at the SANS #BlueTeamSummit in June to learn more about how to reduce! sans.org/cyber-security…

Is your SOC facing burnout and high turn? Come join us at the SANS #BlueTeamSummit in June to learn more about how to reduce!  sans.org/cyber-security…
SANS Cyber Defense 🧢 (@sansdefense) 's Twitter Profile Photo

Blue Teamers Assemble! 🛡 Join us Live Online for the #BlueTeamSummit June 12-13 Hear from #BlueTeam experts on topics like Zero Trust Architecture, hunting OneNote malware, reducing burnout in the SOC, & improving rules effectiveness. Register for 🆓: buff.ly/3Mc68DC

Blue Teamers Assemble! 🛡 

Join us Live Online for the #BlueTeamSummit June 12-13

Hear from #BlueTeam experts on topics like Zero Trust Architecture, hunting OneNote malware, reducing burnout in the SOC, &amp; improving rules effectiveness.

Register for 🆓: buff.ly/3Mc68DC
Brian Carroll (@n3tsurge) 's Twitter Profile Photo

Remember kids, just because your admin says the alert they tripped was "legitimate admin activity" doesn't mean it was done with good operational security practices. Remember to look at alarms for poor OpSec.

H & A Security Solutions | Securitymapper (@securitymapper) 's Twitter Profile Photo

📣 Seeking Elastic Engineer! Join our growing company at H&A Security Solutions LLC. Help us find the perfect candidate skilled in Elastic/OpenSearch. US citizens only. Referral bonus: $500 Amazon gift card if hired! Learn more: indeed.com/job/elasticope…

Brian Carroll (@n3tsurge) 's Twitter Profile Photo

Drastic changes in alert volume should be their own alert. Valleys in the chart could be indicating broken alert engines or no underlying data. Peaks could be signs of wide spread changes to your environment, mass activity.

Brian Carroll (@n3tsurge) 's Twitter Profile Photo

To add to this, here is an example of a chart we use to highlight alert changes between two periods. You have to ask yourself, what happened during that high spike? Was a new rule deployed, did some network wide config change, did my exclusions break?

To add to this, here is an example of a chart we use to highlight alert changes between two periods.  You have to ask yourself, what happened during that high spike?  Was a new  rule deployed, did some network wide config change, did my exclusions break?
Brian Carroll (@n3tsurge) 's Twitter Profile Photo

The previous owner of my home attempted to start finishing the basement himself...let's just say mistakes were made...how does one space studs so wrong!?

The previous owner of my home attempted to start finishing the basement himself...let's just say mistakes were made...how does one space studs so wrong!?
Volexity (@volexity) 's Twitter Profile Photo

.Microsoft has published an advisory related to CVE-2023-36884, an actively exploited #RCE vulnerability in Microsoft Office. Volexity's #threatintel team identified this #0day, related infrastructure & malware and is credited in the report: msrc.microsoft.com/update-guide/v… #dfir [1/2]

Brian Carroll (@n3tsurge) 's Twitter Profile Photo

Everyone forgets about the "political capital" you build among other IT teams. It can mean waiting 1 hour for something or 6 months. The help you give to others will pay you back at some point when you need it most.