TTPs Things that Threat Actors do when they Perform a cyber attack
Never assume your audience knows what acronyms stand for.
13.11.2025 01:28 โ ๐ 18 ๐ 3 ๐ฌ 0 ๐ 0@twizzle.bsky.social
Cyber Threat Intelligence at Microsoft | Former Yahoo & Secret Squirrel | Thoughts my own
TTPs Things that Threat Actors do when they Perform a cyber attack
Never assume your audience knows what acronyms stand for.
13.11.2025 01:28 โ ๐ 18 ๐ 3 ๐ฌ 0 ๐ 0If youโve been laid off from a cyber threat intel position, and you want a ticket to CYBERWARCON, please reach out.
23.10.2025 13:27 โ ๐ 25 ๐ 23 ๐ฌ 0 ๐ 0Well now I need to buy a ticket ๐ซถ
12.10.2025 00:29 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0CFP closes this Friday, September 26th at 11:59pm EST!
If you'd like to speak at CYBERWARCON this year, get your talk submission in ASAP to be considered!
Submit your talk here >> www.cyberwarcon.com/cfp2025
#CYBERWARCON #CFP
This may be one of the sickest coins Iโve seen in a while
20.09.2025 12:59 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0B I G facts
26.08.2025 08:03 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0But it did use AI?
13.08.2025 04:34 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0We published a reading list of our favorite cyber and cyber-adjacent books.
We're keeping it relatively broad. Books about privacy and surveillance are and will be a part of this.
This is meant to be a post to be updated regularly. If you have suggestions on what we should read next, please share!
Those white papers were a golden age but reports like those also cause more clusters to pop up as actors change to avoid detections
17.07.2025 07:28 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0#what_is_sos
30.06.2025 10:24 โ ๐ 4 ๐ 3 ๐ฌ 0 ๐ 0Today, Microsoft Threat Intelligence Center is proud to announce the release of RIFT, an open-source tool designed to assist malware analysts automate the identification of attacker-written code within Rust binaries. https://msft.it/63324SLarg
27.06.2025 18:55 โ ๐ 9 ๐ 3 ๐ฌ 0 ๐ 1JS analysis is absolutely terrible
27.06.2025 18:01 โ ๐ 2 ๐ 0 ๐ฌ 1 ๐ 0Iโve been fortunate enough to go to at least one F1 race a year since 2021 but this year I wonโt be going to any and Iโm not sure how to feel
27.06.2025 14:01 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Fwiw - I believe all the major email providers have them but itโs things like this that are making them phase it out
19.06.2025 18:38 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0More CVE-2024-42009 exploitation from invoice[@]b-s-r[.]eu from May 29, 2025
Same subject and payload that CERT-PL found, but sent via TOR node instead of freemail provider
cert.pl/en/posts/202...
I know AI / LLMs get a lot of flack these days but Iโve thoroughly been enjoying whipping up a quick script or summarizing 50+ pages of legalese. I guess weโll see how long it takes for me to regret those words though
27.05.2025 20:14 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Microsoft has discovered a cluster of worldwide cloud abuse activity by new Russia-affiliated threat actor Void Blizzard (LAUNDRY BEAR), whose cyberespionage activity targets gov't, defense, transportation, media, NGO, and healthcare in Europe and North America. https://msft.it/63324S9Jkp
27.05.2025 09:55 โ ๐ 32 ๐ 23 ๐ฌ 1 ๐ 5100 days of yara really got to you huh?
27.05.2025 12:00 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0China provides several map services that can be useful for open source researchers. Gaode Maps is one of them. Conveniently, it is also accessible to people based outside of China. Have a look at @bellingcat.com's Online Investigation Toolkit to learn more: bellingcat.gitbook.io/toolkit/more...
26.05.2025 16:24 โ ๐ 48 ๐ 13 ๐ฌ 0 ๐ 1You mean โby the truckloadโ?
24.05.2025 17:12 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0The amount of medicine Iโve taken the last 24 hours to be a semi-functioning parent should be researched
24.05.2025 15:23 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0Maaaan what a loaded and complicated question to answer haha
22.05.2025 11:53 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Heโs cooked chat
17.05.2025 17:39 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0#ESETresearch publishes its investigation of Operation RoundPress, which uses XSS vulnerabilities to target high-value webmail servers. We attribute the operation to Sednit with medium confidence. www.welivesecurity.com/en/eset-rese... 1/5
15.05.2025 07:36 โ ๐ 13 ๐ 12 ๐ฌ 1 ๐ 0Great stuff as always
07.05.2025 15:24 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Not all heroes wear capes
30.04.2025 19:25 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Fascinating to see reference to GRU unit 20728 from FR relative to Russia's offensive cyber program -- as far as I'm aware, a first from a Western service?
www.diplomatie.gouv.fr/fr/dossiers-...
Getting warmerโฆ
29.04.2025 17:26 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0No worries! I was hoping to hit FIRST and PivotCon this year but just wasnโt in the cards
20.04.2025 07:48 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0