Nef (@nef0sf) 's Twitter Profile
Nef

@nef0sf

The cloud is just someone else's computer. I am someone else's computer. I like InfoSec and DFIR stuff.

ID: 1098330414651969541

calendar_today20-02-2019 21:15:51

90 Tweet

46 Followers

262 Following

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

That escalated quickly #Lapsus #Nvidia #LeakedCertificate Mimikatz virustotal.com/gui/file/9d123… KDU virustotal.com/gui/file/0e163…

That escalated quickly #Lapsus
 #Nvidia #LeakedCertificate 

Mimikatz
virustotal.com/gui/file/9d123…

KDU
virustotal.com/gui/file/0e163…
Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

I wonder how many hours / days / weeks of analyst time was wasted on outdated IOCs, especially IPs that now have completely different owners #IOCs

I wonder how many hours / days / weeks of analyst time was wasted on outdated IOCs, especially IPs that now have completely different owners
#IOCs
✞ inversecos (@inversecos) 's Twitter Profile Photo

When they tell you their name and job and you gotta act surprised because you work in infosec so you already stalked them.. 💀

Stephan Berger (@malmoeb) 's Twitter Profile Photo

Please do the incident response team a favor, and check that the X-Forwarded-For Header is set on all your reverse proxies / load-balancers / etc. They will thank you later.

Chetan Nayak (Brute Ratel C4 Author) (@ninjaparanoid) 's Twitter Profile Photo

Since Cobaltstrike v4.9 is leaked and sooner or later it will be exploited, here is the detection for beacon's core. This detection cannot be modified with malleable profiles. EDRs like Crowdstrike/Elastic/MDATP which constantly scan the memory region for known patterns should

Thomas Roccia 🤘 (@fr0gger_) 's Twitter Profile Photo

📢 New Microsoft Threat Report: "ViewState Code Injection Attacks Using Publicly Disclosed ASP.NET Machine Keys" I wanted to understand deeper how works the attack so I created a detailed overview. Hope that helps 🤓 👉 microsoft.com/en-us/security…

📢 New Microsoft Threat Report: "ViewState Code Injection Attacks Using Publicly Disclosed ASP.NET Machine Keys"

I wanted to understand deeper how works the attack so I created a detailed overview. Hope that helps 🤓

👉 microsoft.com/en-us/security…
St0pp3r (@_st0pp3r_) 's Twitter Profile Photo

NVISO identified a campaign where #DeerStealer spread via fake Chrome updates on infected sites, using #Telegram to report infections. Together with Lontz and Nef, we took a closer look at how adversaries are abusing Telegram and shared #KQL queries for detection.