Nate Guagenti (@neu5ron) 's Twitter Profile
Nate Guagenti

@neu5ron

ID: 324391039

linkhttps://github.com/neu5ron calendar_today26-06-2011 14:45:47

3,3K Tweet

2,2K Followers

1,1K Following

Sebastian Fernandez (@snfernandez) 's Twitter Profile Photo

While this has been used forever to create exploits. It's a very creative way of makng a JIT for architectures that don' allow allocating executable memory. The code can be seen in this commit: github.com/ktemkin/qemu/c… (7/7)

Johan Berggren (@jberggren) 's Twitter Profile Photo

Sigma integration in Timesketch. Today we merged a feature to show Sigma rules in the UI. You also have the ability to search your timelines based on the generated query. #DFIR

Nate Guagenti (@neu5ron) 's Twitter Profile Photo

research from 2007 that mentions RPC calls used within PetitPotam as potential attack surface "Vista Network Attack Surface Analysis". if there is one there is more.. vx-underground.org/archive/Symant…

HAMZA 🇲🇦 🇵🇸 (@cyb3rsn0rlax) 's Twitter Profile Photo

Pull request created. Here is the Jupyter notebook under the forked repo : github.com/H1L021/EVTX-AT… Examples: - Top tactics by number of events - Top 10 Tactics by EventIDs and Event Log Providers - Top 30 RelativeTargetName of EventID 5145 by ShareName - Sankey Diagrams

Pull request created.
Here is the Jupyter notebook under the forked repo : github.com/H1L021/EVTX-AT…
Examples:
- Top tactics by number of events
- Top 10 Tactics by EventIDs and Event Log Providers
- Top 30 RelativeTargetName of EventID 5145 by ShareName
- Sankey Diagrams
Roberto Rodriguez 🇵🇪 (@cyb3rward0g) 's Twitter Profile Photo

🚨 A few detection opportunities while interacting with local AD hybrid health agent registry keys & Azure AD connect health AD FS services ☁️ 📡SACLs & 🛰️Activity Logs (Directory Activity) FTW 🛡️ #AzureSentinel : github.com/search?q=repo%… 🌎 sigma : github.com/SigmaHQ/sigma/…

Roberto Rodriguez 🇵🇪 (@cyb3rward0g) 's Twitter Profile Photo

🚨 Sharing how to deploy a lab environment w/ #AzureSentinel , a few Linux 🐧 VMs and Microsoft Audit Collection Tool (AUOMS) set up 📡to identify & map sources of data to the execution context of OMI! #MSTIC #OMIGOD 😎 This has been very helpful 💥 techcommunity.microsoft.com/t5/azure-senti…

Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

In the last couple of weeks, we've been working 3CORESec 🛡 on a little project we're calling MAL-CL. It aims to collect and document real-world/common "malicious" CLI execs of different tools/utilities. Feedback and contributions are much appreciated. github.com/3CORESec/MAL-CL

Vadim Khrykov (@blackmatter23) 's Twitter Profile Photo

Considering current situation when my country is running down I see no longer future in Russia for me and my family. I open for any job offers relevant to my LinkedIn profile. Pease DM me, for detailed CV. #NoToWar #НетВойне

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

.tob mic from my team created a sigma extension for VS Code It's in an early stage but already pretty useful and we've already discussed the cool functions and snippets that he's going to add #Sigma #VSCode marketplace.visualstudio.com/items?itemName…

.<a href="/_humpalum/">tob mic</a> from my team created a <a href="/sigma_hq/">sigma</a> extension for VS Code 

It's in an early stage but already pretty useful and we've already discussed the cool functions and snippets that he's going to add

#Sigma #VSCode 

marketplace.visualstudio.com/items?itemName…
Will LaForest 🇺🇦 (@wlaforest) 's Twitter Profile Photo

Check out the #opensource #Kafka #sigma interpreter @mpeacock1964 and I built: github.com/confluentinc/c… Load sigma rules in a topic and the kstreams app will appply them against your streams of observability data in real time! #cybersecurity #cyber inspired by Nate Guagenti socprime

Yarden Shafir (@yarden_shafir) 's Twitter Profile Photo

Quick blog post on a new ETW event to monitor "valid" KASLR bypasses through system calls: windows-internals.com/an-end-to-kasl…

Quick blog post on a new ETW event to monitor "valid" KASLR bypasses through system calls: windows-internals.com/an-end-to-kasl…