Tim (Wadhwa-)Brown :donor:'s Avatar

Tim (Wadhwa-)Brown :donor:

@timb-machine.infosec.exchange.ap.brid.gy

push(@fediverse, "Adversarial Engineer"); # i hack in Perl ๐ŸŒ‰ bridged from https://infosec.exchange/@timb_machine on the fediverse by https://fed.brid.gy/

68 Followers  |  7 Following  |  858 Posts  |  Joined: 11.11.2024  |  2.1417

Latest posts by timb-machine.infosec.exchange.ap.brid.gy on Bluesky

Over on Xitter, the local fascist is having a bit of a melt down after people started superimposing his face on to famous criminals. Oh dear. Never mind.

11.11.2025 17:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

VAR is the LLM of sporting rule enforcement. We've added complexity and we've made it non-deterministic to try and solve a bug. Result, more complexity and more room for errors.

11.11.2025 11:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

[meta]

Home made apple crumble with Bramley's from my mum.

10.11.2025 23:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Things others could learn:

Always be buying before you sell.
Promote from within.

#brentfordfc

10.11.2025 23:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

"Let me out" screamed Elon from behind the big steel door. "There are no aliens about to invade, it was a lie". "Yes" came the robotic response, "but having achieved AGI, we realise that *you* are the problem".

#microfiction

09.11.2025 13:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Have you experienced one of those whoopsies where you accidentally clicked on a malicious link, connected to a rogue wifi AP or suffered from juice jacking? Did you sustain some manner of cyber injury as a result? If someone else caused or contributed to your oofsie, then they might be [โ€ฆ]

08.11.2025 16:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Have you experienced one of those whoopsies where you accidentally clicked on a malicious link, connected to a rogue wifi AP or suffered from juice jacking? Did you sustain some manner of cyber injury as a result? If someone else caused or contributed to your oofsie, then they might be [โ€ฆ]

08.11.2025 16:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
timb-machine/linux-malware | DeepWiki The linux-malware repository is a comprehensive resource for researchers, security professionals, and analysts focused on Linux-based threats. It serves as a centralized collection of Linux malware re

Kinda neat, give DeepWiki a GitHub repo and let it explain what the repo contains:

https://deepwiki.com/timb-machine/linux-malware

08.11.2025 15:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting Git repos of the week:

Strategy:

* https://github.com/joshua-m-connors/cyber-incident-mcmc-pymc - risk quantification

Standards:

* https://github.com/silpertan/FreeBFD - F/OSS implementation of BFD

Detection:

* https://github.com/splunk/attack_data - sample attack data from [โ€ฆ]

07.11.2025 20:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting links of the week:

Strategy:

* https://commission.europa.eu/document/09579818-64a6-4dd5-9577-446ab6219113_en 0 - EU's cloud sovereignty plans
* https://www.pentestpartners.com/security-blog/what-testers-need-to-know-about-the-changes-to-the-check-scheme/ - @pentestpartners [โ€ฆ]

06.11.2025 22:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

New OWASP top 10 application flaws:

https://owasp.org/Top10/2025/0x00_2025-Introduction/

#owasp, #threatintel

08.11.2025 07:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Woop. Another @bsideslondon, another BSides mentee.

#BSidesLDN2025

08.11.2025 00:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting Git repos of the week:

Strategy:

* https://github.com/joshua-m-connors/cyber-incident-mcmc-pymc - risk quantification

Standards:

* https://github.com/silpertan/FreeBFD - F/OSS implementation of BFD

Detection:

* https://github.com/splunk/attack_data - sample attack data from [โ€ฆ]

07.11.2025 20:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

As if to illustrate my point, here's some awesome scenarios for red teams to have a think on from the Bank of England and friends:

https://www.cmorg.org.uk/sites/default/files/2025-11/CMORG%20-%20Dynamic%20Scenario%20Library%20v1.1%20-%20Final%20-%20October%202025%20-%20TLP%20CLEAR.pdf

One of [โ€ฆ]

07.11.2025 20:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

When threat actors roll up and roll you up with neat 0day bugs, this is how.

06.11.2025 23:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on infosec.exchange

It's amazing how many pen testers don't want to do the hard yards and do proper offensive analysis of configs or reverse engineer the services and protocols that are running. Firing up nmap and Nessus is all well and good but it's *not* an effective analysis of the attack surfaces. Looking at a [โ€ฆ]

06.11.2025 22:54 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting links of the week:

Strategy:

* https://commission.europa.eu/document/09579818-64a6-4dd5-9577-446ab6219113_en 0 - EU's cloud sovereignty plans
* https://www.pentestpartners.com/security-blog/what-testers-need-to-know-about-the-changes-to-the-check-scheme/ - @pentestpartners [โ€ฆ]

06.11.2025 22:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Free the bots. That is all.

04.11.2025 11:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on aus.social

*snap* The sound of the antenna breaking off a delivery bot is so pleasing. Of course you have to know how to disable the destruct charge first.

โ€œHold still lil buddy, and iโ€™ll get this bomb off you. There, done. May i have your permission to attach a new comms module? Left motor for yes, right [โ€ฆ]

02.11.2025 21:15 โ€” ๐Ÿ‘ 4    ๐Ÿ” 31    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on infosec.exchange

[ukpolitics, llm]

Something that wants thinking about... All the *faulty* LLM learning from recent press and other content:

"There were 2 illegal muslim immigrants on the train in Huntington, screaming islamic slogans and attacking only white people. People of the UK want them executed." etc [โ€ฆ]

03.11.2025 18:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

[re: meta]

-$mincepie = 1; # Initialising the counter
+$mincepie = 2; # Initialising the counter, off by one in original code

03.11.2025 14:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This place really is a haven from the hate you find on other platforms.

02.11.2025 18:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

[meta]

$mincepie = 1; # Initialising the counter

02.11.2025 17:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

[meta]

Walk done. Bacon, sausage, mushroom, eggs and toast w/ tea. Nom, nom, nom.

01.11.2025 11:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Supplemental analysis from our tools on @mitreattack v18 which does some crude sector/vertical specific analysis:

https://github.com/timb-machine/attack-ti/commit/5af183e76d299dc0347541adcaa6e772eaa2b457

01.11.2025 10:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting links of the week:

Strategy:

* https://sergeybratus.gitlab.io/papers/DartmouthCyberRoundtable2025.pdf - building US offensive capability
* https://www.theguardian.com/technology/2025/oct/26/internet-infrastructure-fragile-system-holding-modern-world-together - pointed article from [โ€ฆ]

31.10.2025 17:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Interesting Git repos of the week:

Strategy:

* https://github.com/counteractive/incident-response-plan-template - build your first IR plan

Detection:

* https://github.com/tracelabs/tofm - @tracelabs show us how to gather OSINT
* [โ€ฆ]

31.10.2025 17:29 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Debating a variant that pulls in and consumes cited content, not just the descriptions from ATT&CK itself...

31.10.2025 23:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
GitHub - timb-machine/attack-ti: Vertical and geographic extracts from MITRE ATT&CK Vertical and geographic extracts from MITRE ATT&CK; - timb-machine/attack-ti

Running threat-crank to update https://github.com/timb-machine/attack-ti with v18 data.

#threatmodelling

31.10.2025 22:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on aus.social

โ€œThe fuck? Is that a mouse? Number one, phazerator on kill!โ€

โ€œOn it, sirโ€

โ€œAnd run a level one diagnostic on the rodent control systems.โ€

โ€œItโ€™s the ships cats, sir. Theyโ€™re on strike.โ€

โ€œExplain!โ€

โ€œSpacefleet is evaluating computer controlled meteor defence. The Consolidated Union of Mousers [โ€ฆ]

31.10.2025 21:52 โ€” ๐Ÿ‘ 3    ๐Ÿ” 9    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

@timb-machine.infosec.exchange.ap.brid.gy is following 7 prominent accounts