Korstiaan (@korstiaans) 's Twitter Profile
Korstiaan

@korstiaans

Founder of Invictus Incident Response @InvictusIR | DFIR enthousiast | invictus-ir.com

ID: 208091547

calendar_today26-10-2010 16:25:41

266 Tweet

455 Followers

325 Following

Invictus Incident Response (@invictusir) 's Twitter Profile Photo

After the launch of Cloud Labs last month, we're excited to share with you the new ๐๐ซ๐ž๐ฆ๐ข๐ฎ๐ฆ lab for this month. We are committed to brining you a (at least one) new lab every month! Sign-up now: cloudlabs.invictus-ir.com

After the launch of Cloud Labs last month, we're excited to share with you the new ๐๐ซ๐ž๐ฆ๐ข๐ฎ๐ฆ lab for this month. We are committed to brining you a (at least one) new lab every month!

Sign-up now:
cloudlabs.invictus-ir.com
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

๐Ÿ”™ Weโ€™re back with a new blog, this time diving into a recent incident response case study. Check it out ๐Ÿ‘‡ invictus-ir.com/news/anatomy-oโ€ฆ #stayInvictus #CloudIncidentResponse #BEC

๐Ÿ”™  Weโ€™re back with a new blog, this time diving into a recent incident response case study.

Check it out ๐Ÿ‘‡
invictus-ir.com/news/anatomy-oโ€ฆ

#stayInvictus #CloudIncidentResponse #BEC
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Get in there! Black Hat is offering a ยฃ300 discount, enter the code ๐‡๐€๐‚๐Š๐“๐‡๐„๐๐‘๐ˆ๐‚๐„ at registration! Register: blackhat.com/eu-25/trainingโ€ฆ #stayInvictus #CloudIncidentResponse #DFIR

Get in there! 

<a href="/BlackHatEvents/">Black Hat</a> is offering a ยฃ300 discount, enter the code ๐‡๐€๐‚๐Š๐“๐‡๐„๐๐‘๐ˆ๐‚๐„ at registration!

Register: blackhat.com/eu-25/trainingโ€ฆ

#stayInvictus #CloudIncidentResponse #DFIR
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Back with a bang ๐Ÿงจ A new post in our Cloud Threat Actor series, today is Part V on ๐’๐ข๐ฅ๐ค ๐“๐ฒ๐ฉ๐ก๐จ๐จ๐ง a.ka. HAFNIUM ๐Ÿผ So far we've covered: - TraderTraitor - Sea Turtle - Laundry Bear - JavaGhost Blog: invictus-ir.com/news/profilingโ€ฆ #StayInvictus

Back with a bang ๐Ÿงจ 

A new post in our Cloud Threat Actor series, today is Part V on ๐’๐ข๐ฅ๐ค ๐“๐ฒ๐ฉ๐ก๐จ๐จ๐ง a.ka. HAFNIUM ๐Ÿผ   

So far we've covered: 
- TraderTraitor 
- Sea Turtle 
- Laundry Bear 
- JavaGhost

Blog: invictus-ir.com/news/profilingโ€ฆ

#StayInvictus
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Someone tried to hack us, read what happened next... invictus-ir.com/news/the-storyโ€ฆ #stayInvictus #CloudIncidentResponse #DFIR #BEC

Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Cloud Labs update for November, we've been cooking in the lab! In our new scenario you can play with EKS, ECR, pipelines and more fun stuff in the cloud. Sign up now and profit of the #BlackFriday deal! cloudlabs.invictus-ir.com #stayInvictus #CloudLabs #CloudIncidentResponse

Cloud Labs update for November, we've been cooking in the lab!

In our new scenario you can play with EKS, ECR, pipelines and more fun stuff in the cloud. 

Sign up now and profit of the #BlackFriday deal!
cloudlabs.invictus-ir.com
#stayInvictus #CloudLabs #CloudIncidentResponse
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

๐ŸงชNew year, new lab, same quality! Another lab inspired on real life incident response cases. If you've worked on incidents in Entra ID you probably know the importance of ๐˜Œ๐˜ฏ๐˜ต๐˜ฆ๐˜ณ๐˜ฑ๐˜ณ๐˜ช๐˜ด๐˜ฆ ๐˜ˆ๐˜ฑ๐˜ฑ๐˜ญ๐˜ช๐˜ค๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด and ๐˜ˆ๐˜ฑ๐˜ฑ ๐˜™๐˜ฆ๐˜จ๐˜ช๐˜ด๐˜ต๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด. This lab is a deep

๐ŸงชNew year, new lab, same quality!

Another lab inspired on real life incident response cases. If you've worked on incidents in Entra ID you probably know the importance of ๐˜Œ๐˜ฏ๐˜ต๐˜ฆ๐˜ณ๐˜ฑ๐˜ณ๐˜ช๐˜ด๐˜ฆ ๐˜ˆ๐˜ฑ๐˜ฑ๐˜ญ๐˜ช๐˜ค๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด and ๐˜ˆ๐˜ฑ๐˜ฑ ๐˜™๐˜ฆ๐˜จ๐˜ช๐˜ด๐˜ต๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด. This lab is a deep
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Happy is an understatement! This year we will be teaching both our AWS and Microsoft Cloud IR course at Black Hat in Las Vegas. Grateful for this opportunity!

Happy is an understatement! This year we will be teaching both our AWS and Microsoft Cloud IR course at <a href="/BlackHatEvents/">Black Hat</a> in Las Vegas. 

Grateful for this opportunity!
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Our latest research on OAuth apps is now live. In this blog we take a look at some case studies where Entra ID apps were abused. We have also included actionable advice on how to prevent these issues in your environment: invictus-ir.com/news/entra-oauโ€ฆ #stayInvictus

Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Have you ever wondered, what modern cloud compromises look like? This is your chance to investigate one, our newest lab is ready for you! Sign-up now to investigate our latest lab๐Ÿ‘‡ cloudlabs.invictus-ir.com #stayInvictus #CloudLabs #CloudIncidentResponse

Have you ever wondered, what modern cloud compromises look like? 

This is your chance to investigate one, our newest lab is ready for you!

Sign-up now to investigate our latest lab๐Ÿ‘‡ 

cloudlabs.invictus-ir.com

#stayInvictus #CloudLabs #CloudIncidentResponse
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Our latest research is live on a recent #AiTM case we worked on together with BIO-ISAC This blog dives into the underlying infrastructure of modern phishing campaigns and includes Indicators of Compromise of this recent campaign. invictus-ir.com/news/the-invisโ€ฆ #stayInvictus

Korstiaan (@korstiaans) 's Twitter Profile Photo

Very excited about this new release. It's been a goal for a long time to have live cloud labs that include Google Cloud and Google Workspace. Which AFAIK no one is doing, give it a go and tell me what you think!

Invictus Incident Response (@invictusir) 's Twitter Profile Photo

We just published an emergency blog on the #Axios compromise. A must read for incident responders and everyone who's been overwhelmed with supply chain package compromises. invictus-ir.com/news/the-poisoโ€ฆ #stayInvictus #CloudIncidentResponse #NPM

We just published an emergency blog on the #Axios compromise. A must read for incident responders and everyone who's been overwhelmed with supply chain package compromises. 
invictus-ir.com/news/the-poisoโ€ฆ

#stayInvictus #CloudIncidentResponse #NPM
Invictus Incident Response (@invictusir) 's Twitter Profile Photo

๐Ÿ“ท The SaaS Hardening Checklist: - Kill "Shadow Consent" โ€“ Disable user consent and implement an Admin Consent Workflow. No unvetted app should touch your data. - Audit Permissions โ€“ Understand Delegated vs. Application-level access to ensure the principle of least privilege.

Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Incident Response in the Neocloud โ›…๏ธ Check out the next part on Lambda Cloud invictus-ir.com/news/incident-โ€ฆ #stayInvictus #CloudIncidentResponse #NeoCloud #LambdaCloud

Invictus Incident Response (@invictusir) 's Twitter Profile Photo

Defeating the Atlas Lion Threat ๐Ÿฆ Most threat actors want your data. Atlas Lion (Storm-0539) wants your balance sheet specifically, your gift card portals. We have been tracking the evolution of this Moroccan-based group. They aren't just sending simple phishing links; they

Defeating the Atlas Lion Threat ๐Ÿฆ

Most threat actors want your data. Atlas Lion (Storm-0539) wants your balance sheet specifically, your gift card portals.

We have been tracking the evolution of this Moroccan-based group. They aren't just sending simple phishing links; they