@SecurityWriter @neurovagrant @NosirrahSec @badsamurai @jwgoerlich Sorta related: do y'all buy sus domains up yourselves? Like fire up DNSTwister and then get out the credit card? That's my next ask.
@mttaggart @SecurityWriter @neurovagrant @NosirrahSec @jwgoerlich I do not. Too many TLDs and that buy-in is a long haul--near free as a puppy. But I have a custom script to generate domain variations for technology, sector, my subdomains, locations, common threats: sso-domain, auth-domain brand-usa, brand-service-now, etc Then I block all those, if they exist or not. 🔨 ⌚