π Windows Security and SDDL: What You Need to Know π
Windows permissions misconfigurations are a goldmine for attackers. SDDL (Security Descriptor Definition Language) remains overlooked yet highly exploitable. π¨
@nasbench.bsky.social and I break it down -->
π§΅ (1/)
21.02.2025 15:55 β π 2 π 1 π¬ 1 π 0
Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time | Splunk
Explore SDDL in Windows security with our comprehensive guide to help enhance your defensive strategy against privilege escalation attacks.
Hey SDDL SDDL: Breaking Down Windows Security One ACE at a Time www.splunk.com/en_us/blog/s....
Thrilled to share my first blog at @splunk! @mhaggis.bsky.social and I take a deep dive into the weird & exciting world of SDDL and ACEs - what they are, how they work, and how attackers can abuse them.
15.02.2025 22:36 β π 12 π 5 π¬ 0 π 0
This is just sad to think about π
24.01.2025 22:24 β π 1 π 0 π¬ 0 π 0
AI allows you to do more work with the same salary. Allowing companies to make more money, and, it uses your data to train so that it'll replace you later.
When is the utopia we read about in sci-fi books. Looks like we skipped to the doom and gloom and AI overlords chapter too quickly π
24.01.2025 22:01 β π 7 π 0 π¬ 2 π 0
I guess we're still here @kostas-sec.bsky.social π
Bsky is chill
23.01.2025 00:30 β π 11 π 1 π¬ 3 π 0
Compared to release v2023-08-24, in v2024-11-10 there are 469 more public #detectionrules in the #SigmaRules repository.
www.dogesec.com/blog/analysi...
#threatintelligence #threatintel
09.12.2024 10:41 β π 3 π 1 π¬ 1 π 0
π‘Interested in #memoryforensics ? Follow
β
@volexity.com
β
@volatilityfoundation.org
β
@attrc.bsky.social
β
@rmettig.bsky.social
β
@nolaforensix.bsky.social
β‘οΈ more to come!
20.11.2024 18:49 β π 54 π 24 π¬ 1 π 0
Iβm looking for a new remote work opportunity starting in April. If you think Iβd be a good fit for your team, let me know!
20.11.2024 22:07 β π 1 π 3 π¬ 1 π 0
Blue Sky Jimmy Cliff GIF
ALT: Blue Sky Jimmy Cliff GIF
Everybody joining and preaching BS aka Blue sky π
Enjoy your weekend everyone.
16.11.2024 00:24 β π 4 π 1 π¬ 0 π 0
Unwrapping the emerging Interlock ransomware attack
Cisco Talos Incident Response (Talos IR) recently observed an attacker conducting big-game hunting and double extortion attacks using the relatively new Interlock ransomware.
Cisco Talos Incident Response (Talos IR) recently observed an attacker conducting big-game hunting and double extortion attacks using the relatively new Interlock ransomware. Read the blog here: cs.co/6019SsMIh
#dfir #threatintel #cybersecurity
13.11.2024 14:06 β π 16 π 4 π¬ 0 π 0
Windows.edb and WER dumps, just to name a few
10.11.2024 11:43 β π 2 π 0 π¬ 1 π 0
Appreciate you brother π
02.11.2024 13:02 β π 2 π 0 π¬ 0 π 0
LOLDrivers are cool π
18.11.2023 15:23 β π 5 π 1 π¬ 0 π 0
Knowledge: the videogame industry newsletter from the creators of Edge. Sign up here for the new edition every Friday: bit.ly/knowledgenewsletter
Get in touch via edgeknowledge@futurenet.com
I work on the Windows engineering team at Microsoft and help with feedback for Start menu, Settings, taskbar, input + more
You can find me on most of the other social media apps including Twitter and reddit with the same account name @jenmsft
Threat Detection Engineer @ Klaviyo | Detection & Response | Security Automation | macOS Security | Maintainer of awesome-detection-engineering, LOOBins
infosecb.com
https://github.com/infosecB
Head of Investigations at InfoGuard AG - dfir.ch
Head of Sekoia Threat Detection & Research (TDR) team β’ Cyber Threat Intelligence β’ Detection Engineering β’ SOC Platform π«π· πͺπΊ β’ Hip-Hop β’ Basketball
Detection Engineering Leader @ Datadog
Views are strictly my own
Creator of Detection Engineering Weekly (https://detectionengineering.net), Sec Research/Intel/Detection @ Datadog
malware detection and analysis, hunting and gathering, threat research
| search "thrunter"
| eval specialty="Purple Team, Treat Hunter, Lifting Heavy Things"
π³ founder of @greynoise.io. computers, networks, technology enthusiast. big goober.
Global Head of Threat Analysis at @Darktrace.com
All things Cyber Security Ops, Threat Hunting, Threat Intel and Incident Mgmt.
Senior Director of Threat Analytics @Rapid7 by day, undercover BBQ detective by night.
Sr. Director of SOC at Huntress. Ex-Mandiant/FireEye. Bringing security to the Fortune 5,000,000.
Threat Detection & Response. Interested in cyber security, tech and politics. Views are my own, unless retweeted.
Velociraptor@Rapid7. #DFIR, #CTI and research.
https://mgreen27.github.io