#PurpleTeam | Ex Raytheon MSSP, SCYTHE, & GD | Taught at BlackHat & DEFCON | #100DaysofSigma | Keep exploring, keep learning, and stay curious.
events.cancer.gov/sites/defaul...
events.cancer.gov/sites/defaul...
events.cancer.gov/sites/defaul...
0 VT detections on any component of the malware loader.
Proofpoint rules detect the outbound C2 traffic.
My Yara rule detects the installer.
0 VT detections on any component of the malware loader.
Proofpoint rules detect the outbound C2 traffic.
My Yara rule detects the installer.
1. Is Gossi freaking out?
2. Is Florian freaking out?
3. Does SANS have an emergency webcast?
4. Are all your red team friends losing their minds over how crazy easy it is to give them awesome access.
1. Is Gossi freaking out?
2. Is Florian freaking out?
3. Does SANS have an emergency webcast?
4. Are all your red team friends losing their minds over how crazy easy it is to give them awesome access.
Get yours in ASAP. Last year saw nearly 2,000 registrations. This is one of the best B-Sides in the world. Oh and did I mention you can visit beautiful Florida beaches during your trip in May?
events.bsidestampa.net/BSidesTampa2...
Get yours in ASAP. Last year saw nearly 2,000 registrations. This is one of the best B-Sides in the world. Oh and did I mention you can visit beautiful Florida beaches during your trip in May?
events.bsidestampa.net/BSidesTampa2...
Working alerts in a SOC is a high stress environment and the grind never stops, so find ways to laugh and enjoy who you work with.
Working alerts in a SOC is a high stress environment and the grind never stops, so find ways to laugh and enjoy who you work with.
1. Engagements with SOC per year/quarter.
2. Intel leads tested.
3. Custom tests to verify detection logic.
4. Request for testing completed %
1. Engagements with SOC per year/quarter.
2. Intel leads tested.
3. Custom tests to verify detection logic.
4. Request for testing completed %
“gained initial access through a web shell left from a third party’s previous security assessment”
www.cisa.gov/news-events/...
“gained initial access through a web shell left from a third party’s previous security assessment”
www.cisa.gov/news-events/...
1. Does it reduce risk by uncovering previously undetected activities?
2. Does it enhance productivity?
3. If the answers to both of the above are no, then where is the potential return on investment?
1. Does it reduce risk by uncovering previously undetected activities?
2. Does it enhance productivity?
3. If the answers to both of the above are no, then where is the potential return on investment?
Keep exploring, keep learning, and stay curious.
Keep exploring, keep learning, and stay curious.
www.cisa.gov/sites/defaul...
www.cisa.gov/sites/defaul...