Christopher Peacock's Avatar

Christopher Peacock

@securepeacock.bsky.social

I find weird things on networks. #PurpleTeam | Ex Raytheon MSSP, SCYTHE, & GD | Taught at BlackHat & DEFCON | #100DaysofSigma | Keep exploring, keep learning, and stay curious.

1,175 Followers  |  127 Following  |  33 Posts  |  Joined: 17.08.2023  |  1.8207

Latest posts by securepeacock.bsky.social on Bluesky

Update: looks like the link on the page is a drive by compromise.

29.06.2025 20:46 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
events.cancer.gov - urlscan.io urlscan.io - Website scanner for suspicious and malicious URLs

urlscan.io/result/0197b...

29.06.2025 20:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Cancer(.)gov, which is registered to the NIH, is hosting a page that lets you illegally stream the new F1 Movie 🧐

events.cancer.gov/sites/defaul...

29.06.2025 20:24 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 1    πŸ“Œ 1
Post image

New Octowave Loader sample is leading to Amatera Stealer deployment over the past week.

0 VT detections on any component of the malware loader.
Proofpoint rules detect the outbound C2 traffic.
My Yara rule detects the installer.

24.06.2025 03:11 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 2    πŸ“Œ 0

This seems like a project to watch πŸ‘€

04.04.2025 23:52 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

How to properly evaluate a CVE score:
1. Is Gossi freaking out?
2. Is Florian freaking out?
3. Does SANS have an emergency webcast?
4. Are all your red team friends losing their minds over how crazy easy it is to give them awesome access.

26.03.2025 01:08 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

Well the other thing is, I’m pretty sure they were getting bounce back emails for like 3-6 years and didn’t noticed the email was no more…

12.03.2025 00:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Every marketing email I’ve ran into in this research project has some tokenized unsubscribe link, but they don’t even offer that.

11.03.2025 23:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I can’t make this up. I bought an expired MSSP domain, and set up mail forwarding for all emails. I’ve tried to unsubscribe from getting an ISAC’s TLP Amber emails but they wont stating I must, β€œemail from an email associated with the ISAC account receiving these emails.” πŸ€¦β€β™‚οΈ

11.03.2025 23:05 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I checked out the #ZeroDay series on Netflix and I think this depiction of events would take too many coordinated attacks. The Russian targeting of Ukraine with Blackenergy and Industroyer is more realistic to what happens. The scenes I saw more resemble an EMP attack.

23.02.2025 01:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Chinese team finds coronavirus that could infect humans via same route as Covid Research was led by Shi Zhengli, a virologist known as the β€˜batwoman’, who is best known for her work on coronaviruses at a lab in Wuhan.

Stock up toilet paper now! πŸ˜‚

www.scmp.com/news/china/s...

22.02.2025 21:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Probably because most small and medium sized app businesses are just that πŸ€·β€β™‚οΈ

Most start ups have a base and then duck tape on as fast as they can to make sales happen. By then, it’d eat up too much revenue to rebuild the code right.

15.02.2025 00:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

This is why I think TTP count is a terrible metric. You either detect the procedure adversaries use or you don’t, this count of 4 for whoami /all is meaningless in most cases.

14.02.2025 03:45 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Before rushing to secure GenAI, make sure your DevSecOps and AppSec foundations are solid. GenAI is just another piece of the application stack. Security fundamentals are crucial. To help understand it, GenAI vulnerabilities are a lot like SQL vulnerabilities.

10.02.2025 18:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Interesting talk today by @wietzebeukema.nl. Make sure you follow him and check out his GitHub too.

06.02.2025 17:49 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Comparison of entries on ArgFuscator

Excellent comparison chart:

argfuscator.net/entries/comp...

06.02.2025 17:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
ArgFuscator Generate obfuscated command-line arguments for common system-native executables now with ArgFuscator.

argfuscator.net

06.02.2025 17:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
https://github.com/wietze/Invoke-ArgFuscator

Today at WWHF Wietze is dropping Invoke-ArgFuscator πŸ‘€

t.co/b4Agg3nveJ

06.02.2025 17:30 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
BSides Tampa 2025 TAMPA BAY'S PREMIER IT SECURITY CONFERENCE. BY THE COMMUNITY. FOR THE COMMUNITY. 40+ Speakers | 7 Tracks | 1000+ Participants

🚨 Last day to submit a CFP ‼️
Get yours in ASAP. Last year saw nearly 2,000 registrations. This is one of the best B-Sides in the world. Oh and did I mention you can visit beautiful Florida beaches during your trip in May?

events.bsidestampa.net/BSidesTampa2...

31.01.2025 16:22 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

Who’s going to WWHF Denver?

30.01.2025 14:59 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Heard this on a podcast and it really resonated with me.

30.01.2025 01:29 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
bart simpson is looking at a cake that says at least you tried ALT: bart simpson is looking at a cake that says at least you tried

Contrary to popular belief, piping IOCs to your SIEM does not mean you’re making CTI actionable.

29.01.2025 21:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I’m head to Breck Friday and skiing Saturday-Sunday.

03.01.2025 15:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

One of the best career tips I can share is to care about the people you work with. Not everyone will be receptive, but those who are can become invaluable connections in your career journeyβ€”and in life.

02.01.2025 01:16 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

One piece of advice to give new SOC analysts is to have humor.

Working alerts in a SOC is a high stress environment and the grind never stops, so find ways to laugh and enjoy who you work with.

17.12.2024 22:05 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Just a friendly reminder that you can hunt in datasets that are outside your organization.

17.12.2024 17:13 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Purple Team metrics can be tough and conflated with BAS testing so here’s a few, but feel free to add your own in the comments.
1. Engagements with SOC per year/quarter.
2. Intel leads tested.
3. Custom tests to verify detection logic.
4. Request for testing completed %

04.12.2024 00:46 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 1    πŸ“Œ 1

One of the quickest GenAI use cases you can do in your SOAR is to auto enrich command lines associated with an alert by adding an explanation of what the command is doing. This boost productivity and situational awareness of the analysts.

03.12.2024 22:49 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

As a Bucs fan, I disagree lol

03.12.2024 01:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization | CISA

This is approaching gross negligence, leaving a public facing back door open 🀯 :
β€œgained initial access through a web shell left from a third party’s previous security assessment”

www.cisa.gov/news-events/...

22.11.2024 19:32 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@securepeacock is following 20 prominent accounts