I'm super excited to be speaking at @cyberwarcon.bsky.social
this year! The lineup looks amazing, as always. including a keynote with Dimitri Alperovitch. ๐คฏ
Check out the full agenda here!
cyberwarcon.com/agenda-25
09.10.2025 14:21 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Join @austinlarsen.me and me next Tuesday for a deep-dive into PRC-nexus threat actor capabilities! Learn about advanced social engineering tactics, novel malware delivery, and strategies to defend your organization.
www.brighttalk.com/webcast/7451...
09.09.2025 22:49 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats | Google Cloud Blog
A social engineering campaign leveraging signed malware, evasive tactics, and captive portal hijacking.
New GTIG blog just dropped! ๐ฅธ๐จ๐ณ๐๐ผ โDeception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats"! We're analyzing an operation that has it all; AitM, social engineering, signed malware, and more! Get the full breakdown here:
cloud.google.com/blog/topics/...
25.08.2025 16:13 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 1
Whatโs in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog
A Russia-sponsored threat actor is impersonating the U.S. Department of State, and using phishing to gain access to email accounts.
So @gabagool.ing (who will henceforth be referred to as "gabbot") and I wrote some stuff on some ASP phishing campaigns: cloud.google.com/blog/topics/...
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
18.06.2025 17:04 โ ๐ 10 ๐ 7 ๐ฌ 0 ๐ 2
๐จ Heads up! ๐จ APT41 is using Google Calendar ๐๏ธ as their latest C2 trick. GTIG just pulled back the curtain ๐ญ on the TOUGHPROGRESS malware campaign and how we shut it down ๐ช. Dive into the details here: ๐https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics
28.05.2025 14:11 โ ๐ 8 ๐ 4 ๐ฌ 1 ๐ 3
CYBERWARCON is a one-day conference in Arlington, VA focused on the specter of destruction, disruption, and malicious influence on our society through cyber capabilities.
cyberwarcon.com
Mandiant Intelligence at Google. CYBERWARCON and SLEUTHCON founder. Johns Hopkins professor. Army vet.
he/him ๐ณ๏ธโ๐ | cyber dude | and it only seems so strange right now
๐จโ๐ป coder + hacker + engineer.
๐น Hunting Adversaries.
๐ฆ
#Philly sports
๐ฎ Video games.
Views/Opinions are my own.
Freedom for all. ๐บ๐ธ๐ณ๏ธโ๐๐ณ๏ธโโง๏ธ๐บ๐ฆ
Posts/Skeets disappear.
Re-post โ endorsement.
fka @gabbyroncone on twitter. mission tech lead for RU & Eastern European APT ops @Google. views expressed here are mine, not my employerโs. she/her.
threat intelligence @google
writing & sharing on adversary tradecraft, malware, threat detection, ics/ot + cyber physical intel, and of course all things #yara
Principal Threat Analyst - Google Threat Intelligence Group
Working at Google TAG. Retired FreeBSD committer. May or may not be a robot.
Seeker & curious mind | Questioning everything | Fascinated by universe & astrophysics | Constantly seeking answers | Searching for the purpose of life | Embracing confusion as a catalyst for growth | Join me on this journey of discovery & exploration!
DFIR and Timesketch for work, hiking and sailing as a hobby, thoughts are my own, not much more to say...
Protecting the Googs ๐ฆ๐บ
Cloud Security Response @ Google ๐ต๏ธโโ๏ธ
Husband & dog / cat dad ๐๐โ๐ฆบ๐โโฌ๐
Gamer & Music nerd ๐ต๐ฎ
using this as a music / thought journal, always happy to chat about DFIR or SecOps stuff, dm me.
Security engineer.
Amateur photographer.
Floridian Vermonter Frenchman.
Signal: @jvehent.37
@0xMatt on Twitter
Rescue, DFIR, Cello and Birds
Digital Forensics and Incident Response
@Google :: I write open source tools :: Creator of OpenRelik and Timesketch
https://openrelik.org/
https://timesketch.org/
#DFIR โข Posts are my own โข he/him
Senior Security Engineer in Detection Engineering, aficionado of terrible science fiction novels, puppet of the algorithm. ๐จ๐ฆ living and working in Silicon Valley.
Blue Jays, Canucks, Jaguars.
Avatar generated by Midjourney.