lots of cyber. All the cybers. Cyber cyber. Cyber.

London, England
Rohan retweeted
@Decode141 and I will be sharing ideas for engaging in cyber deception in Active Directory at BlackHat USA next Thursday between 11:25 and 12:35 PST in the Business Hall - Arsenal Station 5. If you are around, please visit us in-person or virtually using a free on-demand business pass. For more information, please visit blackhat.com/us-24/arsenal/s…
1
1
153
1) We are finally propagating MotW to Virtual Disk containers! For example, when you download and mount an ISO from the Internet, applications that query the zone of files inside of that ISO will receive the zone of the ISO itself. 3/7
2
24
75
Microsoft fixed my Kerberos PAC verification bypass issue this month in HTTP.sys which me and Nick presented at Blackhat. Sadly no more details for 30 days, but it might be easy to work out how to do it :) msrc.microsoft.com/update-gu…
10
51
Google completed its acquisition of Mandiant today. We’re excited to get started on our shared mission to create a comprehensive and best-in-class cyber security solution for customers and partners. Read more here: mandiant.com/company/press-r…
7
205
551
my biggest financial mistake was being in 8th grade in 2009 when I should’ve been buying foreclosed real estate
377
18,750
160,975
Rohan retweeted
44CON 2022 Talk announce : @sadreck "Codecepticon – Building an obfuscator to bypass Modern EDR and AV" here's a hint "no, this one isn’t a python script that runs “replace” a bunch of times." 44con.com/get-ticket #44CON
3
9
Rohan retweeted
Excited to announce that I will be leading an on-demand session at #BlackhatUSA that’ll cover core #GraphQL concepts and how to exploit the most common #security issues. Join the session virtually from Aug 10. blackhat.com/us-22/ #BHUSA
2
7
Rohan retweeted
Starting our list of Saturday AM workshops, we have @Decode141 and @am0nsec teaching "Windows Defence Evasion and Fortification Primitives" DC Forum link: forum.defcon.org/node/241784 EventBrite link: eventbrite.com/e/rohan-durve…
1
3
3
Excited to announce "Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling" is coming to @defcon! Can't wait to share it! Check out the abstract here #DEFCON30 portswigger.net/research/tal…
3
41
218
Rohan retweeted
Finally finished my code for parsing Virtual Address Descriptors (VADs) tree in order to extract all the different information and PTEs
1
17
107
Rohan retweeted
Thrilled to share my new blog post: Put an io_uring on it: Exploiting the Linux kernel. Follow me while I learn a new kernel subsystem + its attack surface, find an 0day, build an exploit, + come up with some new tricks. I go deep and demystify the process graplsecurity.com/post/iou-r…
41
591
2,217
Google Project Zero’s updated disclosure policy means that 0days will be disclosed exclusively through Mandiant Red Teams. /s
2
We are excited to announce that we've signed an agreement to join the @GoogleCloud family — bringing together some of the best minds in security! Read more here: mandiant.com/company/press-r…
20
324
860
Is SMB traffic blocked by Windows Firewall Domain Profile on Server 2016 Datacenter edition? Especially for the Azure image.
Spicy AF 🌶🔥🌶🔥 googleprojectzero.blogspot.c…
3
8
53
Replying to @tifkin_
@tifkin_ and I are giving our talk "ReCertifying Active Directory Certificate Services" today at 3:20PM in Room BC at #BlackHatEurope . If you're interested in securing your AD CS deployment, come check it out!
11
28
Rohan retweeted
Replying to @elonmusk
GGWP. My new Python program shorts Tesla stock everytime you tweet keywords.
1
I almost feel sorry for attackers with this... almost 😈 Amazing work from the @ThinkstCanary team! If you are not using Canarytokens in your live environment, you are missing out on easy early indicators of compromise.
Canarytokens force attackers to doubt anything they find on ur servers. Today, thanks to @dev0x01 - we ask: What happens when an attacker finds a Kubeconfig file on ur server? A: They use it, and u get a reliable alert! Our new (free) Kubeconfig token: blog.thinkst.com/2021/11/a-k…
1
3
Rohan retweeted
I’ve been doing a lot of offensive security source code auditing of enterprise apps over the last six months and every time I show my friends critical pre-auth PoCs they usually respond with “wow i can’t believe no else found that” - the magic is uncovering this attack surface
12
30
346