Josh Liburdi's Avatar

Josh Liburdi

@jshlbrd.bsky.social

infosec person: detection and response, threat hunting, distributed systems. would rather be eating a bagel.

87 Followers  |  18 Following  |  69 Posts  |  Joined: 07.05.2023  |  1.7476

Latest posts by jshlbrd.bsky.social on Bluesky

fyi for the new followers iโ€™m not really using this thing. find me on LinkedIn if you want to chat. bye!

22.11.2024 15:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

the environments and art direction is really good

05.06.2023 16:08 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

thought about making one but i think you have to manage a database, so i noped out

30.05.2023 21:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Ray j unbreakable glasses๐Ÿ˜‚๐Ÿ˜‚
Ray j unbreakable glasses๐Ÿ˜‚๐Ÿ˜‚

when vendors give me a new feature to test

21.05.2023 18:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

itโ€™s ORD for me

18.05.2023 01:37 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

somehow after 4 hours i still donโ€™t have a shirt / tunic? my link is running around more than half naked. ๐Ÿคฃ

17.05.2023 14:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

tbh that sounds a-ok

12.05.2023 22:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

ended up needing to drop off early but solid conf overall, would be great to be there in person sometime

12.05.2023 21:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

demo / walkthrough of the redline builder was ๐Ÿ”ฅ but then the stream cut out ๐Ÿ˜ง

12.05.2023 19:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

this talk is dropping hot IOCs, especially those github dorks

12.05.2023 19:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

deep dive on redline stealer backend, this stuff really highlights the nuances between cybercrime and nation state actors

12.05.2023 19:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

unfortunately missed most of the venom spider talk but love seeing the OSINT, that was some of the most interesting stuff from when i was at CrowdStrike

12.05.2023 19:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

missed half the lightning talks due to work work ๐Ÿ’€

12.05.2023 18:54 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
'RustBucket' malware targets macOS Learn how APT group, BlueNoroff targets macOS devices with newly discovered malware.

hereโ€™s the blogpost from Jamf on the macOS activity

12.05.2023 17:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

TA444 using AppleScript and shell commands to drop payloads on macOS

12.05.2023 17:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

TI at COIN talking about approval farming campaign that leveraged cloudflare, trojaned open source wallet apps, distributed on github and can be tracked by signer

12.05.2023 17:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Home - Cannabis ISAO The Cannabis Information Sharing & Analysis Organization (ISAO) is a member-driven non-profit association formed in April 2021 with the mission of being the cannabis industryโ€™s primary resource for information on physical, cyber, and natural threats, risks, and mitigation.

thereโ€™s a cannabis ISAO!

12.05.2023 17:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

phat panda is my rap name

12.05.2023 17:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

didnโ€™t realize this is lightning talks till just now โšก๏ธ

12.05.2023 17:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

authenticode signatures, this talk is focused on solar marker (not familiar with this one!)

12.05.2023 17:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Itโ€™s alive! Joe Wise and I have been working on answering the question: What the heck is going on in the ecrime threat landscape post macros? Spoiler: chaotic vibes

https://www.proofpoint.com/us/blog/threat-insight/crime-finds-way-evolution-and-experimentation-cybercrime-ecosystem

12.05.2023 15:32 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

LB.SB might be the successor to Breached, but seems like itโ€™s still too early to tell

12.05.2023 16:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

data on actual sale price v list price seems inconclusive, probably due to lack of visibility and lack of trustworthiness (of sellers)

12.05.2023 16:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

fin, gov, and tech were most popular content sold ๐Ÿ˜ฌ

12.05.2023 16:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

wow, prices by sector for sold data โ€” top 3 are aerospace, health, and entertainment

12.05.2023 16:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

sounds like there was a correlation in forum chatter by language to leaked data affecting specific countries, otherwise EN was predominant language

12.05.2023 15:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

some low-level data analysis on forum data, this is worth watching later ๐Ÿ‘€

12.05.2023 15:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

CrowdStrike crew talking about Breached

12.05.2023 15:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

affiliates will straight up give intel to extortion targets (or in this case, extortion negotiators)

12.05.2023 15:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

used to have heavy vetting for affiliates, but less so now. speaker describing how they had to โ€œask for the managerโ€ when dealing with an affiliate, who turned out to be scamming the RaaS leader (avaddon).

12.05.2023 15:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@jshlbrd is following 17 prominent accounts