cyber threat intelligence, OSINT, and corgi hair. Thoughts are my own, RT/Like != Endorsement. (He/Him)

Chicago, IL
My first ever in-person cybersecurity conference was @BsidesORL back in 2019. So I am really pumped to be giving my talk "OSINT Wins: A Celebration of Poor Threat Actor OPSEC" at the conference tomorrow!
1
1
57
There are many indicators that this type of OSINT engagement bait is slop, but one of the most egregious is recommending a tool that hasn’t worked in years
1
1
90
The more I use the “report ai slop” feature on LinkedIn, the more slop I get in my feed 🙄
1
60
The end of that Michigan game felt like a metaphor for our society right now. The elite the get rules bent or ignored to accommodate their wants, without any consequence whatsoever
101
818
7,386
81,844
The older I get the more I use gruvbox themes in my ide and terminal
61
They’re gate keeping the most cracked OSINT technique of all time
We were able to dox this threat actor using ADVANCED tactics (waited until the actor literally confessed then turned themselves in) Buy our threat intel tool
2
181
IntelCorgi retweeted
Next hacker summer camp giveaway! 3 seats to our “The Bug Hunters Methodology” course! Like and share to be entered! arcanum-sec.com/training/the…
91
446
743
25,446
Thanks, HackerOne! I’m so excited to have to give my id to a third party (Veriff) in order to submit bugs to bug bounty programs docs.hackerone.com/en/articl… 🤔
1
1
136
IntelCorgi retweeted
time to bring back "PCAP or it didn't happen" until we start seeing evidence of these claims. I'm not saying its not possible, I'm saying "show your work".
It appears that the autonomous attacker that hit Huggingface was an OpenAI cyber model test that escaped the lab. This is almost unbelievable. Am I reading this right?
16
23
190
10,149
IntelCorgi retweeted
It do be like that sometimes
53
1,454
18,308
703,590
One of the things they don’t tell you bout your thirties is how many times you will find yourself wishing you had a shop vac
1
99
The Obama library is a Halo 3 map
The Obama presidential library really is stunning.
113
1,574
32,029
1,675,191
Idk if I was a foreign intel operator trawling LinkedIn and I saw someone’s dad made a sponsored post advertising his sons name, job in the military, and clearance level I might splurge a bit on lunch that day #opsecawareness
1
79
IntelCorgi retweeted
On this day in 1944 Amon Carter presented FDR with the deed to the land that would become Big Bend National Park. Famously FDR had nothing else going on June 6, 1944, which you can tell from his extremely relaxed demeanor
39
953
20,108
868,255
I used to recommend the @hunchly mobile app for preserving mobile screenshots, but it looks like they took the app off the app store, probably after @MaltegoHQ bought them. Does anyone have any recommendations for an app with similar functionality?
1
42
IntelCorgi retweeted
Today, I signed an Executive Order temporarily repealing bedtimes in the City of New York so that kids of all ages can watch our team in the NBA Finals. As Mayor, you’re forced to make many difficult decisions. This was not one of them. Go Knicks.
104
10,439
206,941
5,383,671
Missed opportunity to not name the malware “Sophon”
the fast16 malware was almost certainly targeting spherical implosion simulations. left: unmodified LS-DYNA 970 right: LS-DYNA 970 modified with the relevant portions of fast16.sys both running a spherical implosion deck
1
172
Howdy folks! Taking a break from my twitter break to let yall know that we released a new @GreyNoiseIO product yesterday. It's called Project Swarm. We've been quietly not-so-quietly working on it for a few years. You can buy it now. It costs $1. There are lots of vulnerabilities on edge-facing apps. To catch in-the-wild exploitation of them, we @ GreyNoise run sensors on the internet. New AI models means more vulnerabilities being identified and exploited, and FASTER. Long term, software and hardware will probably get better, but in the meantime we're gonna have to deal with A LOT of vulnerabilities. At GreyNoise, the sensors we run are basically honeypots- we bait attackers to scan and exploit them which enables us to learn where the attackers are, which vulnerabilities they are exploiting, what it drops, and what it looks like on the wire. From ~2020-now it took us years to build up our fleet. Now anyone can use our new product to deploy their own sensors on their own networks, or an entire fleet of any size, in a day. You can rip back the data and do whatever you want with it. You can resell it, put it into your product, or just stare at it- whatever you want! On our side, we aggregate the data and pour it into a community dataset that everyone shares. As more people join, the data gets bigger and better. Couple neat features: - Sensor deployment is a single bash command on any modern linux distro that supports iptables and wireguard. - Sensors and vulnerable software (profiles) are abstracted into different logical concepts, which means the "what" and "where" are different things, and the sensor is not constrained by the compute required to run the vulnerable software. Also, no matter how hacked the profile (honeypot) gets, it can't touch your host sensor or the rest of your network. - Sensors can run fake honeypots, real software, or even real hardware (bridged with a raspberry pi) like old crappy routers and modems (or expensive firewalls and VPN gateways 👀) - You can create dynamic blocklists that block IPs sourced from your own sensors in real time, so if a remote IP address *looks at your network* the wrong way, you block them instantly. - All the PCAP data is available to you in a gorgeous and intuitive interface at near real time and fully enriched against all of our (thousands of) rules. We're working on the host metadata (malware, syscalls, host behaviors) as well, but this will come later. - If we don't tag a CVE that's interesting to you, you can write a Suricata rule to tag it yourself once and your data gets tagged with it in real time forever. - You can instantly download PCAPs of any exploits that hit your sensors. - If you don't want your data shared with the community dataset, you can talk to our team and we'll work out rights to make it private. Check it out! There's a lot of moving pieces to make this work and we expect bugs, but it's available right now. Join the fight! greynoise.io/project-swarm
16
81
355
36,961
RT @BushidoToken: I’m not gonna lie, TLP restricted CTI reports with massive AI-generated cover pages of scary terminators from Russia & cy…
5
IntelCorgi retweeted
45
508
4,314
101,285