Shreshta (@shreshtait) 's Twitter Profile
Shreshta

@shreshtait

We uncover badness.

ID: 2909885030

linkhttps://shreshtait.com calendar_today25-11-2014 10:20:40

125 Tweet

59 Takipçi

48 Takip Edilen

Vayavya Labs (@vayavya) 's Twitter Profile Photo

We are fully booked for a great evening of talks and mingling. Hope to see many of you there! #belgaum #belagavi #belgaumtech #ITBelgaum #techmeetup #BGMTechMeetUP #eventsponsor

We are fully booked for a great evening of talks and mingling. Hope to see many of you there! 

#belgaum #belagavi #belgaumtech #ITBelgaum #techmeetup #BGMTechMeetUP #eventsponsor
Stephan Berger (@malmoeb) 's Twitter Profile Photo

2/ This HTTP request can now be used very well for an alert. Or better, collect and monitor all your DNS logs, because a DNS request will still go out if the Advanced IP Scanner is run without an installation (portable version). An excellent opportunity for detection.

2/ This HTTP request can now be used very well for an alert. 

Or better, collect and monitor all your DNS logs, because a DNS request will still go out if the Advanced IP Scanner is run without an installation (portable version).

An excellent opportunity for detection.
@pswapneel@infosec.exchange (@pswapneel) 's Twitter Profile Photo

A good starting point would be to check the DNS logs/SIEM if any of the domain names were queried for in the network. Aside from the domain names mentioned in the blog, also check for the domain name links-circleci[.]com That one showed up in our data Shreshta

Shreshta (@shreshtait) 's Twitter Profile Photo

Our security researchers using SDINET - our threat intelligence platform, have detected and identified another phishing domain – links-circleci[.]com, which is part of the phishing campaign. Detailed report - shreshtait.com/blog/2022/09/p… #dns #phishing #GitHub #SDINET #shreshtait

ARCHIVED: Jen Easterly (@cisajen) 's Twitter Profile Photo

👉It’s official! We launched Protective DNS as part of our mission to enhance the federal government’s cyber defenses. Learn more here: go.dhs.gov/Z53

👉It’s official! We launched Protective DNS as part of our mission to enhance the federal government’s cyber defenses. Learn more here: go.dhs.gov/Z53
@pswapneel@infosec.exchange (@pswapneel) 's Twitter Profile Photo

Everything begins with a DNS query. The good stuff and the badness (there are a few exception cases). Enabling and monitoring the DNS logs is an excellent step towards network security monitoring (NSM).

@pswapneel@infosec.exchange (@pswapneel) 's Twitter Profile Photo

Seeing an influx of suspicious domain names (domain shadowing attack) which appear to impersonate gitlab/github Most are pointing at AS57724(DDOS-GUARD, RU).

Seeing an influx of suspicious domain names (domain shadowing attack) which appear to impersonate gitlab/github

Most are pointing at AS57724(DDOS-GUARD, RU).
Ben April (@bapril) 's Twitter Profile Photo

I’m watching the news this week with growing concern. If you find yourself suddenly unemployed and think you might be a good fit for Maltego’s Product and Tech team, ping me. We have some roles open (maltego.com/careers/) and others in the planning stages.

@pswapneel@infosec.exchange (@pswapneel) 's Twitter Profile Photo

Stopping C2 communications in human-operated ransomware through network protection - Microsoft Security Blog microsoft.com/en-us/security…

@pswapneel@infosec.exchange (@pswapneel) 's Twitter Profile Photo

Sometimes it's fascinating to see how some domain names constantly rotate the IP addresses and the network infrastructure they point to. Here's a quick look at one such domain over time 👇 FYI, this is not fast flux. #DNS #threatintelligence

Sometimes it's fascinating to see how some domain names constantly rotate the IP addresses and the network infrastructure they point to.

Here's a quick look at one such domain over time 👇

FYI, this is not fast flux. 

#DNS #threatintelligence
Shreshta (@shreshtait) 's Twitter Profile Photo

Well, we didn't expect impersonation of Obsidian on a website while hunting pig-butchering/romance baiting and investment scams today! obsidiantrades[.]de was registered through Porkbun and is currently pointing at 34.117.223.165 (AS396982 - Google Cloud Platform) cc: kepano

Well, we didn't expect impersonation of <a href="/obsdmd/">Obsidian</a> on a website while hunting pig-butchering/romance baiting and investment scams today!

obsidiantrades[.]de was registered through Porkbun and is currently pointing at 34.117.223.165 (AS396982 - Google Cloud Platform)

cc: <a href="/kepano/">kepano</a>
Shreshta (@shreshtait) 's Twitter Profile Photo

Our latest report uncovers how scammers are exploiting the Tesla brand in large-scale crypto & investment scams — from fake trading platforms to cloned websites. Full report 👉 shreshtait.com/blog/2025/05/c… #pigbutchering #romancebaiting #crypto #investment #scams

Shreshta (@shreshtait) 's Twitter Profile Photo

Our team is growing, and we’re looking for passionate individuals to join us across multiple roles. Learn more and apply here: shreshtait.com/careers Know someone who'd be a great fit? Feel free to share or tag them below! #Hiring #Careers #Belagavi #CyberSecurity