Denny Fischer's Avatar

Denny Fischer

@df-sec.bsky.social

IT-Security Consultant | Problem Solver | Father | Twitter: @df_sec (https://twitter.com/df_sec) | Mastodon: @df_sec@infosec.exchange (https://infosec.exchange/@df_sec)

108 Followers  |  91 Following  |  97 Posts  |  Joined: 22.12.2023  |  1.5984

Latest posts by df-sec.bsky.social on Bluesky

"HELP! MY ACCOUNT GOT HACKED!" - Business Email Compromise (BEC) Part 1

www.truesec.com/hub/blog/hel...

"The Anatomy of a Business Email Compromise Attack" - Business Email Compromise (BEC) Part 2

www.truesec.com/hub/blog/the...

#infosec #blueteam

25.09.2025 17:54 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
GitHub - HotCakeX/Harden-Windows-Security: Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Wind... Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers...

Harden Windows Security is an open source PowerShell module (with GUI/CLI/Unattended mode) that documents, automates and hardens Windows security settings based on supported Microsoft mechanisms

github.com/HotCakeX/Har...

#infosec #blueteam

29.08.2025 19:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - prowler-cloud/prowler: Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident ... Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, har...

Prowler is an open-source security tool that helps assess and enforce security best practices across AWS, Azure, Google Cloud and Kubernetes.

github.com/prowler-clou...

#infosec #blueteam

22.07.2025 18:08 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - BushidoUK/Ransomware-Tool-Matrix: A resource containing all the tools each ransomware gangs uses A resource containing all the tools each ransomware gangs uses - BushidoUK/Ransomware-Tool-Matrix

Ransomware Tool Matrix by @bushidotoken.net: This repository lists tools used by ransomware gangs. Defenders can detect and block these commonly reused tools to stop intrusions.

github.com/BushidoUK/Ra...

#infosec #blueteam

07.05.2025 15:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
State-of-the-art phishing: MFA bypass Threat actors are bypassing MFA with adversary-in-the-middle attacks via reverse proxies. Phishing-as-a-Service tools like Evilproxy make these threats harder to detect.

State-of-the-art phishing: MFA bypass by Jaeson Schultz @talosintelligence.com

blog.talosintelligence.com/state-of-the...

#infosec #blueteam

05.05.2025 13:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
ArgFuscator Generate obfuscated command-line arguments for common system-native executables now with ArgFuscator.

ArgFuscator is an open-source web app that generates obfuscated command lines for common system tools. Great for testing your defenses against real-world attack techniques.

argfuscator.net

#infosec #pentest #redteam #blueteam

31.03.2025 17:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Privacy Checkup: How well do you protect your privacy? The Privacy Checkup was launched as part of Data Privacy Week 2024 and helps you to determine whether or not you’re sufficiently protecting your data online.

How well do you protect your privacy?
The Privacy Checkup helps you assess your online surveillance defenses and take steps to protect your data.

privacy-checkup.info (English, Deutsch, EspaΓ±ol)

#privacy #infosec

30.03.2025 14:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Breaking the Virtual Barrier: From Web-Shell to Ransomware Recent VMware vulnerabilities have reignited the threat of VM escapes, enabling attackers to bypass security controls and deploy ransomware. Learn how adversaries exploit these flaws and how to streng...

A great read on the exploitation of VMware vulnerabilities - from both attacker and defender perspectives - plus practical recommendations to strengthen your security posture.

"Breaking the Virtual Barrier: From Web-Shell to Ransomware"

www.sygnia.co/threat-repor...

#infosec #blueteam

29.03.2025 20:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Fake-Shops von der Stange: BogusBazaar Du bestellst im Internet? NatΓΌrlich bestellst Du im Internet. Aber dieses Mal wird Deine Ware nicht geliefert. Stattdessen sind Dein Geld...

Eine kriminelle Organisation hinter mehr als 75.000 Fake-Shops, >1 Mio. Bestellungen & >$50M Schaden. Einblick in ihr ausgeklΓΌgeltes System & wie sie KΓ€ufer tΓ€uschen.

#38C3: "Fake-Shops von der Stange: BogusBazaar" mit @kaibiermann.bsky.social und kantorkel.
media.ccc.de/v/38c3-fake-...

#infosec

02.01.2025 10:51 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Mastering Sysmon free DFIR e-book release - DFIR Insights Today is the day! I'm announcing the release of my guide: "Mastering Sysmon: Deploying, Configuring, and Fine-Tuning", a free mini eBook designed specifically for digital forensics and incident respon...

"Mastering Sysmon: Deploying, Configuring, and Fine-Tuning"
A free mini eBook for #DFIR professionals with practical steps to deploy, fine-tune, and start logging with Sysmon.

dfirinsights.com/2024/11/27/m...

#infosec #blueteam

16.12.2024 11:18 β€” πŸ‘ 5    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Preview
Die elektronische Patientenakte (ePA) kommt im Januar – ist ein Opt-Out sinnvoll? – Datenschutz – Unter dem Radar Datenschutz – Unter dem Radar

Welche Daten enthΓ€lt die elektronische #Patientenakte und was bedeutet sie fΓΌr die Γ€rztliche Schweigepflicht?

12.12.2024 23:16 β€” πŸ‘ 8    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0
Preview
GitHub - 0xthirteen/Carseat: Python implementation of GhostPack's Seatbelt situational awareness tool Python implementation of GhostPack's Seatbelt situational awareness tool - 0xthirteen/Carseat

Carseat is a Python implementation of GhostPack's Seatbelt, a situational awareness tool for analyzing Windows security configurations.

github.com/0xthirteen/C...

#infosec #pentest #redteam

09.12.2024 19:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The fascinating security model of dark web marketplaces Captchas, Monero, Scams and absolutely no JavaScript

The fascinating security model of dark web marketplaces by @boehs.org

boehs.org/node/dark-we...

#infosec

02.12.2024 20:41 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization | CISA

That's a Cybersecurity Advisory worth reading, with many important points to note.

Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization
www.cisa.gov/news-events/...

#infosec #blueteam

24.11.2024 13:54 β€” πŸ‘ 5    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
LOLESXi

LOLESXi features a comprehensive list of binaries/scripts natively available in VMware ESXi that adversaries have utilised in their operations.

lolesxi-project.github.io/LOLESXi/

#infosec #pentest #redteam #blueteam

08.11.2024 12:36 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
5 Phishing Email Scams and How NOT To Fall For Them | Huntress Explore the art of phishing, learn how to spot common phishing scams and red flags, and understand the importance of security awareness training.

Phishing remains one of the most widespread cyberattacks - here are some tips on how to avoid falling victim!

5 Phishing Email Scams and How NOT To Fall For Them
www.huntress.com/blog/5-phish...

#infosec

24.10.2024 12:16 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
DEF CON 32 Main Stage Talks - YouTube

🚨 Exciting news for all hackers and tech enthusiasts! The #DEFCON32 talks are now available on YouTube! πŸŽ‰

youtube.com/playlist?lis...

#infosec #pentest #redteam #blueteam

18.10.2024 18:36 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - netero1010/EDRSilencer: A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server. A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server. - netero1010/EDRSilencer

A tool that uses the Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

github.com/netero1010/E...

#infosec #pentest #redteam

17.10.2024 17:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
2024 | BigBrotherAwards Die 24. BigBrotherAwards fanden am 11. Oktober 2024 in der Hechelei in Bielefeld statt. Eine vorlΓ€ufige Version des Livestreams finden Sie auf unserer

Spannend & unterhaltsam: Die #BigBrotherAwards prÀmieren jedes Jahr die grâßten Datensünder in Wirtschaft & Politik!

BigBrotherAwards 2024: PreistrΓ€ger, Bilder und Livestream unter bigbrotherawards.de/2024

Also available in English: bigbrotherawards.de/en/2024

#infosec #BBA24

17.10.2024 11:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
ASD’s ACSC, CISA, and US and International Partners Release Guidance on Detecting and Mitigating Active Directory Compromises | CISA

Guidance on Detecting and Mitigating Active Directory Compromises

www.cisa.gov/news-events/...

#infosec #blueteam

16.10.2024 18:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Event Log Talks a Lot: Identifying Human-operated Ransomware through Windows Event Logs - JPCERT/CC Eyes The difficult part of the initial response to a human-operated ransomware attack is identifying the attack vector. You may already know from recent security incident trends that the vulnerabilities of...

Event Log Talks a Lot: Identifying Human-operated Ransomware through Windows Event Logs

blogs.jpcert.or.jp/en/2024/09/w...

#infosec #blueteam

15.10.2024 13:00 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Active Directory Hardening Series - Part 5 – Enforcing LDAP Channel Binding Channel Binding is a LDAP hardening setting that is often misunderstood and as a result is often not enabled.Β  In this post I explain why it is important along..

Active Directory Hardening Series - Part 5 - Enforcing LDAP Channel Binding

techcommunity.microsoft.com/t5/core-infr...

#infosec #blueteam

14.10.2024 12:18 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - Friends-Security/SharpExclusionFinder: Tool designed to find folder exclusions using Windows Defender using command line utility MpCmdRun.exe as a low privileged user, without relying on even... Tool designed to find folder exclusions using Windows Defender using command line utility MpCmdRun.exe as a low privileged user, without relying on event logs - Friends-Security/SharpExclusionFinder

SharpExclusionFinder: This C# tool finds Windows Defender folder exclusions using Windows Defender through its command-line tool (MpCmdRun.exe)

github.com/Friends-Secu...

A blog explaining the technique utilised can be viewed here: blog.fndsec.net/2024/10/04/u...

#infosec #pentest #redteam

13.10.2024 19:07 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Spray passwords, avoid lockouts Password spraying is a well-known technique which consists of testing the same password on several accounts. Although the technique seems simple, it’s not easy to put it into practice without side eff...

ConPass: How to do password spraying while minimizing the risk of locking accounts.

Spray passwords, avoid lockouts
en.hackndo.com/password-spr...

#infosec #pentest #redteam

28.07.2024 07:46 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
LeHack 2024 - NetExec workshop writeup Like every year at LeHack, I was lucky enough to take part in mpgn's Active Directory workshop. The aim of the workshop was to compromise an Active Directory environment and become a Domain Admin of 2...

A nice write-up by Rayan Bouyaiche of @mpgn's Active Directory workshop at LeHack 2024. The workshop aimed to compromise an Active Directory environment and become DA of two domains as quickly as possible using only NetExec.

www.rayanle.cat/lehack-2024-...

#infosec #pentest #redteam

19.07.2024 19:02 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth | CISA

That's a worth reading Cybersecurity Advisory.

CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth
www.cisa.gov/news-events/...

#infosec #blueteam

17.07.2024 11:56 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
MAILFAIL

MailFail is a Firefox browser extension that identifies and provides commands to exploit a large number of email-related misconfigurations for the current domain and subdomain.

m.ail.fail

#infosec #pentest #redteam #blueteam

08.07.2024 11:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Bypassing EDR NTDS.dit protection using BlueTeam tools. During an internal penetration test, Cortex EDR was installed in the domain controller. After obtaining Domain Admin privileges on the…

An alternative method to retrieve NTDS hashes from a domain controller after obtaining Domain Admin privileges on the network.

Bypassing EDR NTDS.dit protection using BlueTeam tools.
medium.com/@0xcc00/bypa...

#infosec #pentest #redteam #blueteam

07.07.2024 19:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
DFIR Breakdown: Kerberoasting Kerberoasting allows attackers to determine sensitive passwords and the most common place for detecting this attack is on the domain controller. In this

Kerberoasting allows attackers to extract and crack service account passwords from a domain controller. This blog post will look into the details of Kerberoasting from a DFIR perspective.

DFIR Breakdown: Kerberoasting
www.cybertriage.com/blog/dfir-br...

#infosec #blueteam #dfir

04.07.2024 22:44 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - srlabs/Certiception: An ADCS honeypot to catch attackers in your internal network. An ADCS honeypot to catch attackers in your internal network. - srlabs/Certiception

Certiception is a honeypot for Active Directory Certificate Services (ADCS), designed to trap attackers with a realistic and attractive bait that triggers highly relevant alerts.

github.com/srlabs/Certi...

#infosec #blueteam

03.07.2024 17:53 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@df-sec is following 19 prominent accounts