BACKDOORS & BREACHES - CARD OF THE DAY
Deck: Core Deck 2.2
Attack/Procedure Type: Persistence
Attack/Procedure Evil Firmware
More:
UEFI Rootkit - threatpost.com/uefi-rootkit...
Trickbot - thehackernews.com/2020/12/tric...
Get physical decks -- spearphish-general-store.myshopify.com/collections/...
08.08.2025 20:47 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
If you're attending DEFCON -- please come say hello, we'd love to see you! We're in the exhibitor area.
07.08.2025 15:06 โ ๐ 4 ๐ 0 ๐ฌ 1 ๐ 0
Soulmate or threat actor? Maybe both!
You can order your copy of the ANTISOC issue here -- spearphish-general-store.myshopify.com/products/pro...
You can read all past issues of PROMPT# here -- www.blackhillsinfosec.com/prompt-zine/
06.08.2025 19:33 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0
Offensive Tooling Cheatsheets: An Infosec Survival Guide Resource - Black Hills Information Security, Inc.
An Infosec Survival Guide Resource, released as blog posts, with fully designed, printer-friendly PDF cheatsheets.
*NEW RELEASE**
Offensive Tooling Cheatsheets: An Infosec Survival Guide Resource
10 essential offensive tool references, available as PDFs or blog posts. Download all or individual sheets. Thanks again to all our contributors!
Check it out: www.blackhillsinfosec.com/offensive-to...
06.08.2025 16:57 โ ๐ 7 ๐ 0 ๐ฌ 0 ๐ 1
Plug and Play works!!! Till it doesn't...What are your implementation nightmares?
If you want to learn more about SOAR join us and Hayden Covington on August 20th --- www.antisyphontraining.com/event/anti-c...
01.08.2025 21:45 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0
BACKDOORS & BREACHES - CARD OF THE DAY
Deck: Densecure
Attack/Procedure Type: Initial Compromise
Attack/Procedure: Wi-Fi Guest Network Escape
Tools:
Bettercap - www.bettercap.org
Metasploit - www.metasploit.com
Get physical decks: spearphish-general-store.myshopify.com/collections/...
01.08.2025 20:34 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
looking good!!!
01.08.2025 20:25 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Backdoors & Breaches - Black Hills Information Security, Inc.
This is Backdoors & Breaches, an Incident Response Card Game, from Black Hills Information Security and Active Countermeasures. Backdoors & Breaches contains 52 unique cards to help you conduct incide...
THURSDAY - BHIS Webcast
Datadog & BHIS created a new Backdoors & Breaches expansion deck.
Join a free one-hour webcast to learn about the new attack, detection, and inject cards.
Thursday, July 31st - 1:00 PM EDT
Register (Zoom): events.zoom.us/ev/AgWn-tGp5...
29.07.2025 17:34 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
30 Tips for Secure JavaScript w/ Tanya Janca
Hey folks!
WEDNESDAY - Antisyphon Training Anticast
Join a free one-hour training with Tanya Janca to learn 30 tips for writing secure JavaScript.
You'll learn what to do, what to avoid, and how to use open-source tools.
July 30th - 12:00 PM EDT
Register (Zoom): events.zoom.us/ev/AmaSwRAqJ...
29.07.2025 17:34 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Last week the ANTISOC Team joined us for a free one-hour webcast!
We learned the details of how they operate, working to improve our customers security every day, and take home tools and techniques that you can try yourself!
Watch the full webcast here -- www.youtube.com/live/JRXQRfO...
28.07.2025 18:26 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
BACKDOORS & BREACHES - CARD OF THE DAY
Deck: Core Deck 2.2
Attack/Procedure Type: Initial Compromise
Attack/Procedure: Password Spray
Tools:
SprayingToolkit - github.com/byt3bl33d3r/...
FireProx - github.com/ustayready/f...
Hydra - github.com/vanhauser-th...
25.07.2025 18:05 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
PROMPT# is Back!
This issue is by the ANTISOC team at BHIS, and it highlights the work they do!
Order -- spearphish-general-store.myshopify.com/products/pro...
If you get a 404 code that means we can't ship to your location but you can read it for free -- www.blackhillsinfosec.com/prompt-zine/...
24.07.2025 19:31 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0
We all need a humble brag every now and then!!!
24.07.2025 18:45 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
The Detection Engineering Process w/ Hayden Covington #livestream
YouTube video by Black Hills Information Security
Let's revisit a past webcast!
Let's revisit:
โThe foundational elements of a scientific approach to detection engineering
โHow to approach each step with a clear purpose from the start
โStrategies for continuous improvement & advanced detection techniques
Watch -- youtube.com/live/i2vOuky...
24.07.2025 18:45 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
cybersecurity zine PROMPT# describing "The ANTISOC issue CONTINUOUS PENETRATION TESTING" featuring an axolotl anthro with a hoodie, eyeshadow, and gill piercings
there's free cybersecurity zines I like to get by @bhinfosecurity.bsky.social and the axolotl on the cover of this one... i love them.....
23.07.2025 19:24 โ ๐ 26 ๐ 8 ๐ฌ 1 ๐ 0
Implementing Continuous Penetration Testing w/ BHIS ANTISOC Team
Hey folks!
Join us for a free one-hour webcast with the Black Hills Information Security (BHIS) ANTISOC Continuous Penetration Testing team!
Our goal: help you think like the threats you're up against.
Thursday, July 24th - 1:00 PM EDT
Register (Zoom): events.zoom.us/ev/AtOpqfQYq...
22.07.2025 15:58 โ ๐ 5 ๐ 1 ๐ฌ 1 ๐ 0
Inside SOC Email Investigations with Tom DeJong
YouTube video by Black Hills Information Security
Last week Tom DeJong hosted our long awaited return to our weekly webcast series!
He'll taught how SOC Analysts investigate potentially malicious emails to keep their organizations inboxes safe.
Find all the info in the slide deck and watch the full webcast here -- youtube.com/live/ABjxK7P...
21.07.2025 17:23 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 0
Join us this Friday, July 18th, 11 AMโ4 PM ET for the SOC Detection Engineering Crash Course with Hayden Covington from BlackHills Info Security! No experience needed, just bring your curiosity! Register now: www.antisyphontraining.com/course/works...
14.07.2025 16:48 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
CARD OF THE DAY
Deck: Core Deck 2.2
Attack/Procedure Type: Pivot and Escalate
Attack/Procedure: New Service Creation/Modification
Tools:
Impacket - github.com/SecureAuthCo...
Metasploit - www.metasploit.com
Get decks: spearphish-general-store.myshopify.com/collections/...
11.07.2025 18:12 โ ๐ 0 ๐ 1 ๐ฌ 0 ๐ 0
ICYMI: No webcast this week so let's look back at one of the hottest topics of the year!
Craig & Derek joined us or a freewebcast on Using AI to Augment Pentesting Methodologies.
We learned ways to leverage AI to assist with penetration testing methodology -- www.youtube.com/live/WALqWZh...
10.07.2025 19:08 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
Join Jason Haddix for a free one-hour Antisyphon Anti-cast, "Attacking AI."
You'll learn practical techniques for assessing AI-enabled systems, including a seven-point methodology, prompt injection taxonomy, & useful tools.
Wed, July 9th - 12:00 PM EDT
Register: events.zoom.us/ev/Ap_oRmO3x...
08.07.2025 15:37 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
BACKDOORS & BREACHES - CARD OF THE DAY
Have you experienced this?
Deck: Cloud Deck
Attack/Procedure Type: Initial Compromise
Attack/Procedure: Malicious OAuth Application
Tools:
O365 Attack Toolkit - github.com/mdsecactiveb...
Learn more:
threatpost.com/oauth-phishi...
04.07.2025 15:34 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0
Why Your Org Needs a Penetration Test Program w/ Kelli & Corey
YouTube video by Black Hills Information Security
The BHIS team is enjoying a must needed break but that doesn't mean we can't give you your Thursday webcast fix!
Corey Ham & Kelli Tarala joined us for a very special free one-hour webcast on why your org needs a penetration test program!
Watch here -- youtube.com/live/OUWEdX1...
03.07.2025 20:40 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
Join Jennifer Shannon from Secure Ideas for this 2-day training course and by the end, you will be able to conduct a basic API pen test using a systematic approach & industry best practices!
Grab your spot here: www.antisyphontraining.com/course/profe...
30.06.2025 17:25 โ ๐ 6 ๐ 4 ๐ฌ 0 ๐ 0
BACKDOORS & BREACHES - CARD OF THE DAY
Deck: Cloud Deck
Attack/Procedure Type: Initial Compromise
Attack/Procedure: Credentials Posted Publicly in a Code Repository
Tools:
Gitleaks - github.com/gitleaks/git...
TruffleHog - github.com/trufflesecur...
Gitrob - github.com/michenriksen...
27.06.2025 17:46 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Cybersecurity Awareness training
Keep yourself secure online by taking Amazon's cybersecurity awareness training and learn about cyber risks like phishing and social engineering.
Free and Pay-What-You-Can Training
learnsecurity.amazon.com/en/index.html
www.antisyphontraining.com/pay-what-you...
Find more helpful educational content and the full article by Ashley by checking out the Infosec Survival Guide: GREEN BOOK - www.blackhillsinfosec.com/prompt-zine/...
25.06.2025 19:37 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0
Father, hacker, Ninja, fitness freak, socialist, ยณยณโฐยน, โงtst, Wepwawet, afrocyberist, bka
VHSky
Horrorsky
HorrorFam
HorrorNoire
z0ds3c
Blacksky
Black Phillip
HackerSky
Taken
https://z0ds3c.substack.com/
https://infosec.exchange/@zodmagus
Author "Wireless Security Architecture" and "Low Tech Hacking" | Speaker | CISO CTO @ViszenSecurity.com | Packet Protector ๐๏ธ| @CISOLaunch.com | Security Architecture, Network, WiFi, IoT, Zero Trust | Faculty @IANS_security | www.SecurityUncorked.com
Content Director at Packet Pushers; tech journalist; co-host of the Network Break, Heavy Networking, and Packet Protector podcasts; author of the supernatural novel "The Haunting of Edward Drake"
๐ Trusted Threat Detection & Incident Response solutions. Experience the difference with our unmatched capabilities. #SIEM #APISecurity #LogManagement #InfoSec
security architect / co-founder @digitaldefenseinstitute.com / co-founder Recon InfoSec
โฅโฅโฅ == @eric.zip, nerdery, rainbows, sweatpants
she/her | mama of 3 | ๐ค๐๐ฟ๐๐
unicorns.lol
https://short-stack.net
whitneychampion.com/portfolio
IT generalist with an infosec slant. Testing out the new hotness over here.
Hacker, CTF, CCDC, BJJ Brown Belt, python, rust, malware
https://www.offensivecontext.com
https://puck.tools
https://www.malicious.fit
NPR Cybersecurity Correspondent (currently) reporting on the transformation of the federal government including by DOGE.
Send me a tip: Text JennaMcLaughlin.54 on Signal from personal (nonwork) devices.
Avid Indoorsman, Blue team, W605, and Octothorpe enthusiast.
DFIR Analyst
Blog: https://dfirdiva.com/
Free & Affordable Training (DFIR, OSINT, Cybersecurity): https://training.dfirdiva.com/
Community Events: https://events.dfirdiva.com/
Curated List of Discounts: https://training.dfirdiva.com/current-discounts
Information security practitioner and lifelong student. Away from the keyboard, you'll find me on the golf course or reading.
Entrepreneur | Security unprofessional and speaker | Former Navy stuff doer | Advocate for #fostercare | Probably yelling at bots in Russian
Independent security contractor.
#1 photography account about hacking.
Previously:
@bishopfox Red Team
@risk3sixty Pentesting Practice Lead
Product Owner | Business Analyst | Certified SAFeยฎ Practitioner | Reference SA/SME | Cybersecurity Expertise
Replying/Following/Reposting โ Endorsement.
โค๏ธ๐ค๐ ๐ ๐๏ธ ๐ฝ๐งก โฎ๏ธ ๐งฉ
๐ซXXX ๐ซMAGA ๐ซCrypto ๐ซDM ๐ซSolicitation๐ Professional Profile ๐
๐ป Blue Team Training @ Blue Cape Security
I enjoy security, technology, learning, books, & the great outdoors.
Trying to be human & kind.
Opinions = mine. He/Him/Hรคn
https://github.com/JimSycurity
https://www.adminsdholder.com
End-to-end Cybersecurity consulting team leading the industry, supporting organizations, and giving back. #HackThePlanet
https://trustedsec.com/
Red Teamer @BHinfoSecurity. Implant Dev is my passion.