6.1K Followers
1.7K Following
540 Posts

Senior Security Researcher, Proofpoint Emerging Threats. Digital Arcanist

I've been doing this cybersecurity thing for the better part of a decade now. Probably longer than that. I'm starting to forget. Time is relative, but it surely isn't kind to my memory.

I'd like to think I do cybersecurity well, but blue teamers collectively get told they're doing it wrong constantly. So maybe I just failed forward throughout my career.

Oh, I wrote a book. Its a good framework for setting up a virtual machine lab. See my bookmarked toots if you're curious.

Finally, I occasionally write about tech/nerd-related things over at https://www.totes-legit-notmalware.site where I expose that I have a short fuse, and no filter.

Work-Related hashtags:
#Iocs #ThreatIntel #DFIR #Malware #NSM #suricata #snort #BEC #phishing #APT #ThreatDetection

Hobbies:
#VideoGames #XCOM2 #Minecraft #Synthetik #Fallout #Skyrim #Anime #Manga #Adventure #Fantasy #Isekai #HomeImprovement #WoodWorking #MetalWorking #HomeLab

self-verificationhttps://www.yeettheayys.cf/v_me/
Emerging Threats NSM ruleshttps://community.emergingthreats.net
How to Homelabhttps://leanpub.com/avatar2
Personal Bloghttps://www.totes-legit-notmalware.site
@da_667 the funniest thing is: this only applies to not-yet approved models. Importing & selling that same TP-Link WR841Nv7 from, idk, 2008 is still good. Because SeCuRiTy
Sums up my experience growing up
and even if you do slap that stupid fucking made in the USA badging on whatever dipshit IoT device, chips and software are still produced elsewhere. Bet me that they'll shove fuckin goahead webs http server or boa httpd on it, and it'll be just as shit as it was before.

FCC bans all non-us made IoT routers

dude not even Cisco makes their own shit here.

Patch why are you letting these clowns build an AI solution to this problem?

I have a sociopathic fondness for "I told you so"

https://www.reddit.com/r/RimWorld/comments/1s2acrr/crashlanded_oc/

"I'm gonna go stab them with my frozen poop knife!"

"That dude has a high-powered rifle. He's gonna blow out your lungs before you're even within a mile of him."

@da_667 oh my god, i remember those.

it came to pass. this can't be good.

EDR detects weird shit going on

reality: just drop your payloads into \Windows\ccmcache and you can do whatever.

people all like "BYOVD to bypass EDR".

reality: I changed some metadata, and the filename of the executable and dumped lsass.

its mimidogz.exe all over again.