Haag's Avatar

Haag

@mhaggis.bsky.social

Just a person hacking away.

269 Followers  |  209 Following  |  34 Posts  |  Joined: 16.02.2023  |  1.8063

Latest posts by mhaggis.bsky.social on Bluesky

Hi

11.09.2025 13:09 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - MHaggis/ASRGEN: ASR Configurator, Essentials and Atomic Testing ASR Configurator, Essentials and Atomic Testing. Contribute to MHaggis/ASRGEN development by creating an account on GitHub.

๐Ÿšจ Still on your journey to mastering ASR rules?
Donโ€™t sleep on ASRGEN ๐Ÿ›ก๏ธ๐Ÿ’ฅ

โšก Point. Click. Generate ASR rules.
๐Ÿ” Learn + test safely with built-in atomic simulations
๐Ÿ“ฆ Export to Intune/GPO-ready formats
๐ŸŽฏ Built for defenders, by defenders

๐Ÿ‘€๐Ÿ”ฅ
๐Ÿ‘‰ asrgen.streamlit.app

๐Ÿ“š github.com/MHaggis/ASRGEN

21.08.2025 07:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
๐Ÿš€ Fresh ClickGrab โœจ | Into the Rabbit Hole ๐Ÿ‡๐ŸŒ€
๐Ÿ”ฅ We started fresh with ClickGrab ๐Ÿ–ฑ๏ธโœจ looking at some new stuffโ€ฆ but then the whole thing flipped upside down ๐ŸŒ€ and turned into a full-on rabbit hole deep dive ๐Ÿ•ณ๏ธ๐Ÿ‡ ๐Ÿ” What we explored: ๐Ÿโ€ฆ ๐Ÿš€ Fresh ClickGrab โœจ | Into the Rabbit Hole ๐Ÿ‡๐ŸŒ€

๐Ÿ†•๐Ÿ‡ Just dropped a 1-hour rabbit hole dive into API playgrounds, mocks, & random nerdy finds ๐Ÿค“

We started with ClickGrab, but then it turned into:

๐Ÿ Beeceptor

๐Ÿ› ๏ธ Mockbin

๐Ÿงฉ Zudoku

๐Ÿ” VirusTotal hunts

๐Ÿค– ChatGPT making OpenAPI bins & routes

Chaotic, nerdy, fun. Come hang out ๐Ÿ‘‰ youtu.be/j7QE-6p9Y9Q

20.08.2025 07:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Minted narwhal!

I am/was burnt sienna goose

29.04.2025 19:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ASRGEN Access ASRGEN here on https://asrgen.streamlit.app/

๐Ÿšจ New ASR rules are now GA:

โŒ Block rebooting in Safe Mode
๐Ÿ•ต๏ธโ€โ™‚๏ธ Block copied/impersonated system tools

ASRGEN had these since preview. ๐Ÿ˜Ž

Want to:

โšก Quickly create Intune-ready ASR policies
๐Ÿงช Simulate and understand rule impacts

Check โ†’ asrgen.streamlit.app

Be proactive. Be precise.

14.04.2025 20:15 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ’ฐ The hunt beginsโ€ฆ

The first drops for PowerShell-Hunter: Season 2 are coming SOON.
New tools. Smarter hunting. Sexier telemetry.
This isnโ€™t just DFIRโ€”itโ€™s an evolution.

โš”๏ธ Hunt smarter. Hunt harder.
โญ github.com/MHaggis/Powe...

14.04.2025 12:02 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - MHaggis/PowerShell-Hunter: PowerShell tools to help defenders hunt smarter, hunt harder. PowerShell tools to help defenders hunt smarter, hunt harder. - MHaggis/PowerShell-Hunter

๐Ÿšจ PowerShell-Hunter Season 2 is coming ๐Ÿšจ

๐Ÿ’ฅ More atomic tools
๐Ÿงฌ Smarter, faster log analysis
๐Ÿค– Machine learning meets lateral movement
๐Ÿ˜ˆ PowerShell so slick it should be illegal

Youโ€™re not readyโ€”but you should be.
โญ Star the repo or miss the magic:

10.04.2025 17:40 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
PCA Analyzer Demo: Uncover Hidden Windows Execution History | PowerShell-Hunter Toolkit
๐Ÿ” Discover the wealth of forensic evidence hiding in your Windows PCA logs!In this demonstration, I showcase the PCA Analyzer - a powerful forensic tool fro... PCA Analyzer Demo: Uncover Hidden Windows Execution History | PowerShell-Hunter Toolkit

๐ŸŽ‰ Exciting News: PCA Analyzer is now part of the PowerShell-Hunter suite! ๐Ÿš€

Check it out on GitHub: github.com/MHaggis/PowerShell-Hunter ๐Ÿ’ป

๐Ÿ“บ

04.03.2025 08:36 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Atomics on a Tuesday || Introducing The SDDLMaker
๐ŸŒŸ ๐Ÿ”ฌ In this EXTRAORDINARY episode of Atomics on a Tuesday ๐ŸŽฏ, we venture deep into the mysterious realm of Windows Security Descriptor Definition Language ... Atomics on a Tuesday || Introducing The SDDLMaker

๐ŸŽฅ Want a deeper dive? Check out Atomics on a Friday, where we introduce SDDLMaker!
โ–ถ๏ธ https://www.youtube.com/watch?v=uSYvHUVU8xY

๐Ÿ”„ RT/Reshare if you find this useful! ๐Ÿš€

#WindowsSecurity #SDDL #Cybersecurity #Splunk #AtomicRedTeam

21.02.2025 15:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Analytics Story: Defense Evasion or Unauthorized Access Via SDDL Tampering Date: 2024-12-06 ID: 8ccdd852-3878-4871-ae37-e5af5c67baf3 Author: Nasreddine Bencherchali, Michael Haag, Splunk Product: Splunk Enterprise Security Description This analytic story focuses onโ€ฆ

๐Ÿ› ๏ธ Splunk Security Content:
๐Ÿ”— https://research.splunk.com/stories/defense_evasion_or_unauthorized_access_via_sddl_tampering/

๐Ÿง  Mind Map:
๐Ÿ”— https://github.com/MHaggis/SDDLMaker/tree/main/MindMap

๐Ÿงต (5/)

21.02.2025 15:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
SDDL Parser Welcome to , a handcrafted bespoke tool to revolutionize the way you build and analyze Windows Se...

๐Ÿ’ก Need to decode or generate SDDL? Try SDDLMaker ๐Ÿ”ง
๐Ÿ‘‰ https://thesddlmaker.streamlit.app/

๐Ÿ“œ Read the full blog:
๐Ÿ”— https://www.splunk.com/en_us/blog/security/windows-security-sddl-guide-access-control.html

๐Ÿงต (4/)

21.02.2025 15:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Top 3 Things You'll Learn:
1๏ธโƒฃ How attackers exploit SDDLโ€”event log tampering, service hardening, & more
2๏ธโƒฃ How to decode SDDL strings & analyze permissions, DACLs, and ACEs
3๏ธโƒฃ How to defend against SDDL abuse with detections & Atomic Red Team tests

๐Ÿงต (3/)

21.02.2025 15:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

In our latest blog, we break down SDDL: ๐Ÿ”น How it structures Windows security
๐Ÿ”น How attackersโ€”from LockBit to RomComโ€”manipulate it for privilege escalation & defense evasion
๐Ÿ”น How to detect & defend ๐Ÿ›ก๏ธ

๐Ÿงต (2/)

21.02.2025 15:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image Post image

๐Ÿ” Windows Security and SDDL: What You Need to Know ๐Ÿ”

Windows permissions misconfigurations are a goldmine for attackers. SDDL (Security Descriptor Definition Language) remains overlooked yet highly exploitable. ๐Ÿšจ

@nasbench.bsky.social and I break it down -->

๐Ÿงต (1/)

21.02.2025 15:55 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Tomorrow, join us for a legendary episode of Atomics on a Friday featuring Jonathan Johnson (@jsecurity101) as we dive deep into JonMonโ€”the tool redefining Windows telemetry!

24.01.2025 03:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐ŸŽ„ Twas the night before JonMon, and all through the net,
๐Ÿ” Defenders were stirring, their systems to vet.
๐Ÿ› ๏ธ The telemetry was hung in EventViewer with care,
โœจ In hopes that Jonny Johnson soon would be there.

๐Ÿ“… Friday, January 24th
โฐ 11 AM MST | 1 PM EST
๐Ÿ“บ

YouTube: youtube.com/watch?v=CqEhtgโ€ฆ

24.01.2025 03:02 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
a girl in a pink sweater is raising her arms in the air while a group of people are standing around her . ALT: a girl in a pink sweater is raising her arms in the air while a group of people are standing around her .
13.12.2024 01:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I got you!

13.12.2024 01:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Good Tidings - Holiday Sweet Coffee With a delicious blast of candied fruit, Good Tidings warms up crisp mornings and brightens any breakfast! Sweet and syrupy with notes of orange ribbon candy, lilac, Amaretto, and Grand Marnier. Pair ...

Down to the end of my last Christmas blend, what do you recommend this holiday season? I typically get Red Rooster or Atomic.

www.redroostercoffee.com/products/goo...

atomicroastery.com/products/mer...

07.12.2024 14:11 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Happy Monday

02.12.2024 18:04 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master ยท MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.


๐Ÿ”ฅ Tools for Testing:

โžก๏ธ Apache Builder: https://buff.ly/4fOt8F9
โžก๏ธ IIS Builder: https://buff.ly/4fLGySm

Empower your security team to hunt, detect, and patch gaps before attackers exploit them. ๐Ÿ›ก๏ธ

Test, learn, and refine! #CyberSecurity #ThreatHunting #WebShellDetection

27.11.2024 18:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master ยท MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.

๐Ÿ’ป How to Use:

1๏ธโƒฃ Deploy your favorite tools (Sysmon, EDR, XDR, etc.)
2๏ธโƒฃ Grab a webshell of choice, upload it, and start testing!
3๏ธโƒฃObserve logs, alerts, and behaviors to identify gaps in your coverage.

27.11.2024 18:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master ยท MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.

๐Ÿ” Detection Opportunities:
Use these servers to validate analytic coverage for:

๐Ÿ—‚๏ธ File modifications (webshell uploads)
โš™๏ธ Process executions (commands from shells)
๐ŸŽฏ Suspicious behaviors triggered by shells

27.11.2024 18:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image Post image

๐Ÿ’ก Webshell Testing for Defenders ๐Ÿ’ก

Having automated tools to spin up web servers isnโ€™t just convenientโ€”itโ€™s a game-changer for defenders. Here's why:

27.11.2024 18:13 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Cracking Braodo Stealer: Analyzing Python Malware and Its Obfuscated Loader | Splunk The Splunk Threat Research Team break down Braodo Stealer's loader mechanisms, obfuscation strategies, and payload behavior.

๐Ÿšจ Unlocking the Secrets of Braodo Stealer! ๐Ÿšจ

Dive into our latest blog where the Splunk Threat Research Team dissects the elusive Python malware and its sneaky obfuscated loader! ๐Ÿ๐Ÿ”โœจ

๐Ÿ”“ Cracking the code of Braodo Stealer's obfuscation

27.11.2024 14:46 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
notes/utilities/ApachePHPBuild at master ยท MHaggis/notes Full of public notes and Utilities. Contribute to MHaggis/notes development by creating an account on GitHub.

"Things that get built on a Monday... ๐Ÿค”

"'Haag do you have a easy way to build a Apache|NGINX|IIS server to easy simulate webshells?'
Hold my coffee... โ˜•

โ€ข 5-min Apache+PHP setup ๐Ÿš€
โ€ข Drop-in webshell support ๐ŸŽฏ

See you Tuesday! ๐Ÿ˜Ž

25.11.2024 20:00 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Atomics on a Friday Episode 4 IIS sassins In this Atomics on a Friday, Paul and Michael will dive into IIS Components and showcase details on this stealthy technique and how adversaries abuse it.Refe...

โš›๏ธ Blast from the past Atomics on a Friday โš›๏ธ

Attackers are weaponizing IIS modules for persistence, post-exploitation, and data theft.
Check out the blog + AOAF for more ๐Ÿ”ฅ:
https://buff.ly/40UUWAI
Donโ€™t waitโ€”watch to strengthen your defenses:

22.11.2024 17:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stargazers Ghost Network - Check Point Research Check Point Research identified a network of GitHub accounts (Stargazers Ghost Network) that distribute malware or malicious links via phishing repositories. The network consists of multiple accountsโ€ฆ

๐ŸŒŸ Living off GitHub: The Stargazers Ghost Network!๐ŸŒ

๐Ÿ”ฅ I somehow missed this, but WOWโ€”what a fascinating deep dive into a DaaS operation! ๐Ÿš€ Fully automated, primed for quick Ops, and makes you wonder about the ones we havenโ€™t uncovered yet. ๐Ÿ‘€
https://buff.ly/3LCYEIP ๐Ÿšจ

20.11.2024 17:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@mhaggis is following 18 prominent accounts