Bradley Kemp (@bradleyjkemp) 's Twitter Profile
Bradley Kemp

@bradleyjkemp

Experienced ignorer of Safe Browsing warnings • Building phish.report

ID: 3303005878

linkhttps://bradleyjkemp.dev calendar_today29-05-2015 16:51:14

391 Tweet

397 Takipçi

230 Takip Edilen

Bradley Kemp (@bradleyjkemp) 's Twitter Profile Photo

Credential phishing, live 2fa code interception, *and* pushing malware 😱 #hugops to any security teams cleaning up after this one

Bradley Kemp (@bradleyjkemp) 's Twitter Profile Photo

I need to either debug some Outlook email rendering bugs, or stop using magic links and implement SAML. What a choice 😣

Bradley Kemp (@bradleyjkemp) 's Twitter Profile Photo

The next Future of Security Operations meetup is happening on Monday at the Monzo 🏦 offices 🗣️ I'm not speaking this time, but if you're around, come say hi! tines.com/events/firesid…

Phish Report (@phish_report) 's Twitter Profile Photo

🕵️ How to detect phishing sites impersonating your brand, using open source! 🐟 The key to successfully combating phishing is detecting it early, and thanks to CT logs you can get started detecting phishing sites in near-real-time, completely for free: phish.report/blog/phishing-…

Phish Report (@phish_report) 's Twitter Profile Photo

How can you find phishing sites with urlscan.io? Here's four ways to find phishing sites and then pivot to other examples of the same kit: phish.report/blog/urlscanio…

Phish Report (@phish_report) 's Twitter Profile Photo

❓You've found a phishing kit for sale which has been plaguing your team for weeks. Would you pay them for a copy of it? How much?

Phish Report (@phish_report) 's Twitter Profile Photo

From identifying phishing sites to detecting C2 panels, people have used IOK to do it all. IOK (Indicator Of Kit) is a detection language for web pages: write rules based on the page content, response headers and more. And it's open source: github.com/phish-report/I…

From identifying phishing sites to detecting C2 panels, people have used IOK to do it all.

IOK (Indicator Of Kit) is a detection language for web pages: write rules based on the page content, response headers and more. And it's open source: github.com/phish-report/I…
Phish Report (@phish_report) 's Twitter Profile Photo

A perfect example 👇 Here's a phishing site located on the path /account urlscan.io/result/f8c7816… And there's still the phishing kit at /account.zip urlscan.io/result/3f19297… 🎁

A perfect example 👇

Here's a phishing site located on the path /account urlscan.io/result/f8c7816…

And there's still the phishing kit at /account.zip urlscan.io/result/3f19297… 🎁
Phish Report (@phish_report) 's Twitter Profile Photo

Combatting brand impersonation is more than just reporting abuse to hosting providers. Here's the top 4 vulnerabilities we find in phishing kits that you can use to disrupt an attack 👇

Phish Report (@phish_report) 's Twitter Profile Photo

We've seen a huge increase in the use of LiteSpeed's "Bot Verification" page over the past few months 📈 Using reCAPTCHA isn't a new tactic, but using LiteSpeed makes detection significantly harder

We've seen a huge increase in the use of LiteSpeed's "Bot Verification" page over the past few months 📈

Using reCAPTCHA isn't a new tactic, but using LiteSpeed makes detection significantly harder