Tyler's Avatar

Tyler

@secshoggoth.bsky.social

Incident Response, Forensics, Malware Analysis, Reverse Engineering, Cyber Security, RPG, Geek, Nerd, #DFIR Opinions are my own and not those of my employer.

565 Followers  |  66 Following  |  16 Posts  |  Joined: 13.11.2024  |  1.6436

Latest posts by secshoggoth.bsky.social on Bluesky

Preview
Microsoft Quick Assist is Under Attack: What You Need to Know Microsoft Quick Assist is a great tool for streamlining IT support. Unfortunately, itโ€™s also becoming a popular target for hackers trying to break into you...

Did you know there are ๐ญ๐ฐ๐จ ๐ฏ๐ž๐ซ๐ฌ๐ข๐จ๐ง๐ฌ ๐จ๐Ÿ ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐๐ฎ๐ข๐œ๐ค ๐€๐ฌ๐ฌ๐ข๐ฌ๐ญ, one of which doesn't log anything?

On ๐—”๐˜‚๐—ด ๐Ÿญ๐Ÿฏ ๐—ฎ๐˜ ๐Ÿญ๐Ÿฎ ๐—ฃ๐—  ๐—˜๐—ฆ๐—ง, I am presenting on MSQA, how we're seeing it used in attacks. More importantly, how to perform investigations into MSQA.

๐…๐ซ๐ž๐ž ๐ญ๐จ ๐š๐ญ๐ญ๐ž๐ง๐ - register here:
ow.ly/TvlR50WxW5A

08.08.2025 13:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Extra Life | Change Kids' Health, Change the Future I'm raising funds with #EXTRALIFE for kids treated at my Children's Miracle Network Hospitals! I need your help to reach my fundraising goal. Please donate today to change kids' health.

A friend of mine - @openheartgames.bsky.social - is running a D&D game all day for Extra Life. Drop by their stream and donate to a good cause!

www.extra-life.org/index.cfm?fu...

#dnd #rpg #charity #extralife

26.04.2025 16:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
BSidesROC 2025 -  Microsoft Quick Assist -  Tyler Hudak
YouTube video by BSidesROC BSidesROC 2025 - Microsoft Quick Assist - Tyler Hudak

This past weekend I had the opportunity and speak at B-Sides Rochester (NY).

My talk was on forensically analyzing Microsoft Quick Assist and the issues associated with attempting to do so. If anyone is interested:

- Slides: github.com/secshoggoth/...
- Video: www.youtube.com/watch?v=l9Kq...

26.03.2025 12:39 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Microsoft Quick Assist Remote Monitoring Learn how attackers exploit Microsoft Quick Assist, a default Windows tool, in scams and social engineering attacks. Discover detection tips, analysis methods, and strategies to protect your business ...

I've had to analyze several MS Quick Assist compromises and found challenges during each one. Threat Hunting for malicious activity thru QA is not easy either.

So I wrote a blog post on what to look for: inversion6.com/resources/bl...

#dfir #forensics #incidentresponse #threathunting

29.01.2025 13:51 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Inversion6 Launches Comprehensive Incident Response Service Global cybersecurity firm launches expanded service to help companies respond and recover from cyber threats.

Today marks the official launch of the Inversion6 Incident Response (IR) team, and I couldn't be more excited! Ready to tackle challenges, protect, and respond like never before. Letโ€™s go!

#IncidentResponse #CyberSecurity #DFIR

inversion6.com/resources/ne...

21.01.2025 14:48 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

My fallback plan is being a cranberry farmer or running a tiki bar in the Caribbean.

10.01.2025 17:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Now there is so much to learn and understand. Granted, there is also more training, free content, technology, and education. But in a way that may make it more overwhelming.

To anyone jumping into the depths of this ocean now, you have my sympathies but I also share your excitement. (2/2)

10.01.2025 14:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I do not envy those coming into Information Security now.

When I started, there were no formal programs, no degrees, and little training. It was the wild west and we were making a lot of it up as we went. In a way, it was easier. (1/2)

10.01.2025 14:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Feels like an appropriate response to me.

10.01.2025 14:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

What is everyone's favorite place for a starting sysmon config template?

10.12.2024 18:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...

@volexity.comโ€™s latest blog post describes in detail how a Russian APT used a new attack technique, the โ€œNearest Neighbor Attackโ€, to leverage Wi-Fi networks in close proximity to the intended target while the attacker was halfway around the world.ย 
ย 
Read more here: www.volexity.com/blog/2024/11...

22.11.2024 14:58 โ€” ๐Ÿ‘ 81    ๐Ÿ” 41    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 13
Preview
Sextortion | Federal Bureau of Investigation Sextortion is a crime that involves adults coercing kids and teens into sending explicit images online. The FBI has several resources to help caregivers and young people better understand what sextort...

Here are some more resources. If anyone knows of any more, please comment them.

www.fbi.gov/how-we-can-h...
ojjdp.ojp.gov/publications...
www.thorn.org/blog/identif...

13.11.2024 15:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Save or ๐—ฑ๐—ผ๐—ฐ๐˜‚๐—บ๐—ฒ๐—ป๐˜ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—บ๐—ฒ๐˜€๐˜€๐—ฎ๐—ด๐—ฒ๐˜€ (screenshots, etc.) to help law enforcement if they are brought in.

๐—š๐—ฒ๐˜ ๐—ต๐—ฒ๐—น๐—ฝ from someone you trust. Contact law enforcement. They can help stop this.

I know this may be embarrassing, but they have the resources to help you out.

13.11.2024 15:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐—•๐—น๐—ผ๐—ฐ๐—ธ ๐—ฎ๐—ป๐—ฑ ๐—ฟ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€.

They will try to message you on every platform they can find using different accounts.

Blocking and reporting them means its more likely their accounts will be taken down.

13.11.2024 15:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Don't send them anything and ๐—ฑ๐—ผ๐—ป'๐˜ ๐—ฝ๐—ฎ๐˜† ๐˜๐—ต๐—ฒ๐—บ ๐—ฎ๐—ป๐˜† ๐—บ๐—ผ๐—ป๐—ฒ๐˜†.

If you pay them, it won't go away. They will just ask for more.

If you did pay them money, try to ๐—ฟ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ฒ ๐˜๐—ต๐—ฒ ๐˜๐—ฟ๐—ฎ๐—ป๐˜€๐—ฎ๐—ฐ๐˜๐—ถ๐—ผ๐—ป. You may have to call your bank, but the faster you do it the more likely the reversal can happen.

13.11.2024 15:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Yesterday I received a call from a friend who was a victim of sextortion. This is all too common but fortunately there are things you can do if you fall victim to this.

Remember ๐˜†๐—ผ๐˜‚ ๐—ฎ๐—ฟ๐—ฒ ๐—ป๐—ผ๐˜ ๐—ฎ๐˜ ๐—ณ๐—ฎ๐˜‚๐—น๐˜. The person doing this is truly one of the worst types of criminals. You are a victim.
๐Ÿงต

13.11.2024 15:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

What's one more social media site to check out?

13.11.2024 13:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@secshoggoth is following 20 prominent accounts