Jorge Orchilles's Avatar

Jorge Orchilles

@jorgeorchilles.bsky.social

SANS Principal Instructor & Author #SEC565 | #RedTeam | #PurpleTeam | #PenTest | #C2Matrix Creator | ATT&CK & Atomic Red Team Contributor | Published Author

713 Followers  |  46 Following  |  3,839 Posts  |  Joined: 12.06.2023  |  1.9421

Latest posts by jorgeorchilles.bsky.social on Bluesky

2025 Data Breach Investigations Report Key Findings The Verizon Data Breach Investigations Report (DBIR) is the authoritative source of cybersecurity breach information. This annual report provides an unparalleled, data-driven analysis of real-world cy...

Save the date and register for the official release of the 2025 Verizon Data Breach Investigations Report hashtag#DBIR aka THE REPORT on April 23: www.brighttalk.com/webcast/1509...

18.04.2025 20:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

At VulnCon this week, if you are here, say hi. Already got a ton of value from this conference: did an SBOM workshop, a couple VEX talks from folks leading that effort in Cisco and Nvidia, and of course AI. Looking forward for the next few days!

07.04.2025 18:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Formula 1 is back! If you played last year, you can rejoin without a passcode. If you would like to play, set up a team at fantasygp.com and DM me for the code to join #InfoSecF1

06.03.2025 12:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Threat intelligence is about more than just regurgitating indicators you found in someone else's reports.

If this is your idea of "threat intelligence" then AI is 100% coming for your job.

29.01.2025 19:55 β€” πŸ‘ 40    πŸ” 3    πŸ’¬ 4    πŸ“Œ 0

Why did we try to learn *nix with this distro? So hard headed, such a good decision though!

29.01.2025 17:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware Key Takeaways This intrusion began with the download and execution of a Cobalt Strike beacon that impersonated a Windows Media Configuration Utility. The threat actor used Rclone to exfiltrate data…

🌟New report out today!🌟

Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware

Analysis & reporting completed by @r3nzsec, @MyDFIR & @MittenSec.

Audio: Available on Spotify, Apple, YouTube and more!

thedfirreport.com/2025/01/27/c...

27.01.2025 12:55 β€” πŸ‘ 24    πŸ” 10    πŸ’¬ 1    πŸ“Œ 2
Preview
Process Hollowing on Windows 11 24H2 Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us…

In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...

26.01.2025 23:55 β€” πŸ‘ 58    πŸ” 38    πŸ’¬ 0    πŸ“Œ 1

Didn't know you were on here, searched by another name :P

03.01.2025 19:30 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This would be awesome! Probably after given some folks are taking training. I am still planning logistics but know a few folks may be down @securepeacock.bsky.social

03.01.2025 14:09 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Releases Β· FalconForceTeam/FalconHound FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag...

FalconHound 1.4.2 is out!

* Added Managed identity authentication for Azure based inputs (KeyVaults, MDE, Sentinel, GraphAPI)
* Added report command line option and actions
* Added HTML output option

Grab it here > github.com/FalconForceT...

30.12.2024 16:09 β€” πŸ‘ 18    πŸ” 10    πŸ’¬ 0    πŸ“Œ 0

Amazing shots! Thanks for sharing! Going to add to my bucket list along with Ferrari. We have done the BMW museum and factory in Munich and loved it

28.12.2024 16:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Congrats!!!

16.12.2024 19:36 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Wicked pumped for our community to have won the SANS Difference Makers award 2024 "Podcast of the Year"

Community, Cyber, Coffee, and Carl

16.12.2024 19:00 β€” πŸ‘ 7    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Post image

The Paranoids @ Yahoo was one of the oldest, largest, and highest reputation internal security teams in the industry.

A lot of good talent was built and trained there.

This is a shame.

13.12.2024 02:34 β€” πŸ‘ 23    πŸ” 6    πŸ’¬ 1    πŸ“Œ 0
Preview
Exclusive | UnitedHealthcare CEO Brian Thompson fatally shot outside Hilton hotel in Midtown in possible targeted attack: sources The CEO of UnitedHealth was fatally shot in the chest Wednesday morning outside the Hilton hotel in Midtown in what police say was a targeted attack.

If they find the perpetrator, I can't imagine how they manage to avoid jury nullification. It's not just patients. Change Healthcare (part of United) turned the lives of so many provider upside down and most will never be made whole.
nypost.com/2024/12/04/u...

04.12.2024 15:10 β€” πŸ‘ 16    πŸ” 2    πŸ’¬ 2    πŸ“Œ 1

Purple Team metrics can be tough and conflated with BAS testing so here’s a few, but feel free to add your own in the comments.
1. Engagements with SOC per year/quarter.
2. Intel leads tested.
3. Custom tests to verify detection logic.
4. Request for testing completed %

04.12.2024 00:46 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 1    πŸ“Œ 1
Preview
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...

Excellent write up from the folks @volexity.com www.volexity.com/blog/2024/11...

26.11.2024 19:00 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

You won't always win. That's okay.

The goal is to win as many as you can and learn as much as you can from the ones you lose.

22.11.2024 02:39 β€” πŸ‘ 31    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Hi friends! Just switched over. Please connect so I can follow you back!

22.11.2024 04:05 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

This was before lights out. I took the pic and called it. #F1 #MexicoGP

27.10.2024 20:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

https://phrack.org/issues/71/2.html#article

04.09.2024 14:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I first met @bsdaemon when I was randomly put on the BRA (Brasil) team at Hack Cup too many years ago (we went on to win and get free tickets to INFILTRATE). I had no idea who he was other than just a kind, fun dude that played soccer. Here is his profile:...

04.09.2024 14:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Abusing MS Windows printing for C2 communication Diverto is an information security company. We provide co...

C2 via Microsoft Windows print functionality? Yes please: https://diverto.hr/en/blog/2024-05-03-MS-Windows-Printing-C2/ Thanks for @c2_matrix shout out

09.05.2024 16:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Microsoft Warns: North Korean Hackers Turn to AI-Fueled C... North Korea's state-linked hackers are enhancing their op...

We need to reset expectations. LLMs are not "discovering" novel attacks or 0days. They are lowering the barrier for entry for all types of hackers. Embrace it, let it help you. Criminals already are: https://thehackernews.com/2024/04/microsoft-warns-north-korean-hackers.html

22.04.2024 17:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Spotted @BSidesTampa Learning some more Azure stuff with @SecurePeacock and a nice little demo @mrgretzky may recognize the tool

06.04.2024 15:18 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I should have stayed up for this race! My fantasy team did terrible but how about Ferrari!!!!! #InfoSecF1

24.03.2024 15:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
SANS AI Cybersecurity Forum: Insights from the Front Lin... The SANS Faculty, experts and practitioners in cybersecur...

started
https://www.sans.org/webcasts/sans-ai-cybersecurity-forum-insights-front-lines/

21.03.2024 16:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Spent the last year @Verizon running the offensive security team (more accurately called Readiness and Proactive Security) One of the innovative things I got to do was build an AI Red Team with @teschulz We will share lessons learned and how to get...

21.03.2024 16:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Anyone have an extra ticket for Wicys? I have a direct report that has booked flight and hotel but now needs a ticket. This will be her first time attending, please RT for reach.

20.03.2024 21:27 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

2nd race of the 2024 season in the books with @SecurePeacock taking P1. @paulpols and I sharing the podium with him. Paul manages to hold on to the lead but a long way to go with 22 more races this season! #InfoSecF1

11.03.2024 16:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@jorgeorchilles is following 18 prominent accounts