Staff Threat Detection Engineer @Chainalysis and 179CPT Cyber Operations Technician 170A @MOARNG

Filter
Exclude
Time range
-
Minimum likes
Yesterday was my last day at @elastic. It was an incredible run. I’m grateful for the opportunity I was given to help build Elastic’s #macOS endpoint agent and endpoint/SIEM detections from the ground up, work that delivered real impact for customers and made life harder for the adversaries. It was truly an honor to work alongside so many talented people, and I’m very proud of everything we built together. Wishing Elastic and everyone there nothing but the best. I’ll be looking for my next adventure soon. Stay tuned!
4
3
53
3,329
You are going to want to check out this awesome new research write-up from the team. Very interesting and somewhat creative initial access method. Includes a @macos piece as well. Shout out to @soolidsnakee, @SBousseaden and team working hard to get this out.
We have identified a novel social engineering campaign abusing Obsidian, the popular note taking app, to deliver a previously undocumented RAT #PHANTOMPULSE and it’s loader #PHANTOMPULL targeting individuals in finance and crypto. The attack never exploits a vulnerability. It abuses Obsidian's own plugin ecosystem to execute code the moment a victim opens a shared vault. Full analysis: go.es.io/4cld0dB
1
9
669
Check it out. For those of you who asked about and/or are interested in our Endpoint/SIEM detection rules that fired for this activity they are public and linked in the blog here. Huge kudos to the awesome team we have here @elastic, @dez_ @SBousseaden @RFGroenewoud @andythevariable and many others.
ElasticSecurityLabs detects the Axios npm supply chain attack across Linux, Windows & macOS. Our behavioral detections caught it without relying on static indicators. Full malware analysis dropping soon: go.es.io/488UwvJ
6
23
2,947
3 of my Elastic endpoint behavior rules detected and immediately killed the malicious payload (com.apple.act.mond): Potential Binary Masquerading via Invalid Code Signature Suspicious URL as argument to Self-Signed Binary Suspicious XPC Service Child Process
3
2
24
4,243
Replying to @wtsdev
It's on VT: 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a
1
3
259
Binary Hash: 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a Payload Analysis: gist.github.com/joe-desimone… @dez_ Gist tracking Axios intrusion: gist.github.com/joe-desimone…
1
4
21
4,015
7. WAVESHAPER DPRK attribution:
Now let's talk attribution. @DefSecSentinel quickly pointed to DPRK 🇰🇵. Remarkable similarities to WAVESHAPER / UNC1069
1
1
17
6,890
6. C2 victim host -> 142.11.206.73:8000
1
1
15
3,834
5. Cleanup osascript deletes the temp AppleScript: rm -rf /var/folders/.../T/6202033 Approx. 618ms from setup.js execution to full cleanup. The dropper, the malicious package.json, and the temp AppleScript, all gone.
1
2
17
3,990
4. Payload download + execution osascript runs a chained shell command The binary masquerades as an Apple daemon (com.apple.act.mond), hides in /Library/Caches, and gets backgrounded via zsh, reparented to PID 1 again. Double process-tree break. No visible ancestry back to npm.
1
13
4,215
3. Process tree evasion setup.js writes an AppleScript to $TMPDIR and launches it with nohup: nohup osascript /var/folders/.../T/6202033 nohup detaches osascript from node's process tree, reparented to PID 1 (launchd). The forensic link back to npm is severed. The filename "6202033" is the campaign ID. It doubles as the C2 URL path.
1
1
16
4,683
2. Defense-evasion Within 42ms of execution, setup.js destroys all evidence: • Deletes itself (setup.js) • Deletes the malicious package.json containing the postinstall hook • Renames a pre-staged package.md → package.json (clean decoy) If you inspect node_modules/plain-crypto-js/ after the fact, it looks completely normal.
1
23
5,319
1. The supply chain entry point npm install → axios@1.14.1 → resolves plain-crypto-js@4.2.1 (a package that didn't exist 24hrs earlier) → postinstall hook fires: sh -c node setup.js
1
1
22
5,416
🧵 The axios @npmjs compromise dropped a @macOS backdoor that closely mirrors North Korea's (@DPRK) recent WAVESHAPER backdoor. Let's take a quick look the full intrusion:
13
115
429
83,521
Another awesome #OBTS 🌴🏖️☀️in the books. It was an honor to speak again this year and share my research with this incredible community 🍎. Such a blast spending time with newcomers and old friends. There is truly no other conference like it. Huge shout out and thank you to both @andyrozen and @patrickwardle for all the hard work you put in ❤️.
1
8
27
3,892
Heading to my 3rd #OBTS 🌴☀️🌊today! Best conference out there. Honored to be speaking again this year alongside so many other incredible #Apple 🍎 security researchers. It’s gonna be a blast, can’t wait to see everyone! Pumped to get to share my research into using and abusing containers as payloads in “BYOB: Bring your own Blackbox - Isolated Defense Evasion on MacOS” 💪
2
6
31
4,438
❤️ Love to see it 😎
3
141
I am honored and could not be more excited to present again this year at #OBTS 🌴☀️. So many incredible talks and amazing researchers. It's gonna be awesome! Shoutout to @patrickwardle and @objective_see who work hard to put on the best conference out there. Can't wait to see everyone. 🙂 Looking forward to sharing my research around weaponizing #containers on #macOS, including Apple's new container framework, for defense evasion. 💪
📢 Just dropped: the full #OBTS v8 talk lineup! objectivebythesea.org/v8/tal… And for the first time we'll have 3 full days of presentations! 🤩 Congrats to the selected speakers and mahalo to all who submitted. With ~100 submissions, selecting the final talks was a daunting task! 😫
1
5
28
4,540
This @elasticseclabs blog elastic.co/security-labs/bit… was the result of a really fun 4 day exercise my colleague @_xDeJesus and I decided to undertake a few weeks ago. After the @SlowMist_Team initial access writeup, @Mandiant IR Findings and @Unit42_Intel payload analysis we wanted to see if we could emulate the entire @safe attack end-to-end from #macOS compromise to #AWS pivot and frontend injection pulling everything together in order to derive actionable lessons in defense. The entire emulation was done using the same payloads and tools the #DPRK did during the intrusion, slightly modified to be used in our lab environment . Some assumptions had to be made but overall it gave us a pretty accurate picture of what happened, how the attackers did it and why they made certain choices, along with how best to defend against an attack like this going forward. We couldn't fit everything we wanted in but I hope you all enjoy and get something out of it. #TraderTraitor #ByBit #Emulation #Elastic #SafeWallet #Detections #ThreatHunting
24
86
5,188
Replying to @SkrzSecurity
I would highly recommend you use our security serverless offering then. Super easy to to start using and very affordable. Allows you to run Elastic Security in an autoscaled and fully managed environment, where you don’t have to worry about or manage the underlying Elasticsearch cluster and Kibana instances. Just create a serverless security project, configure your endpoint policy, install agents and your off. 👍 elastic.co/docs/solutions/se… elastic.co/pricing/serverles… $1.50 per endpoint per month, plus data ingest
2
4
185