David Oxley (is on Bluesky)

708 Followers
249 Following
139 Posts
I’ve consolidated all my threat intelligence social media on Bluesky, consider following me there: https://bsky.app/profile/oxley.io
David Oxley 🌐 (@oxley.io)

Amazon/AWS Threat Intelligence. Citizen Lab Research Fellow. Former federal agent. Fan of space, books, technology, and Mother Nature🌪️. Personal account. Storm chasing: https://bsky.app/profile/wxdox.com #ThreatIntel

Bluesky Social
Merry Christmas to all, but especially those in Ukraine who are defending their homeland over yet another holiday season 🇺🇦 https://www.nytimes.com/2023/12/25/world/europe/ukraine-russia-christmas-ukrainian-orthodox-church.html?smid=nytcore-ios-share&referringSource=articleShare
Christmas Comes Early in Ukraine, but Not a Moment Too Soon

The Ukrainian Orthodox Church formally changed the date for celebrating to Dec. 25, departing from the Russian tradition of celebrating on Jan. 7, according to the Julian calendar.

The New York Times
I had the pleasure of speaking on a panel at the inaugural RUBICON Symposium at Johns Hopkins University SAIS, discussing the role of the private sector in the cyber defense of Ukraine. It was a phenomenal event put on by @alperovitch and the JHU Advanced Physics Lab, and I look forward to future iterations!
I’m not the only team #hiring in Amazon Threat Intelligence! We’re also hiring for a security engineer focused on vulnerability and exploitation analysis across AWS. US-based, Senior-level hybrid role. Let me know if you have questions! https://amazon.jobs/en/jobs/2512218/senior-security-intel-engineer-vulnerability-and-exploitation-threat-intelligence
Senior Security Intel Engineer, Vulnerability and Exploitation Threat Intelligence

Amazon is seeking an innovative Senior Security Intel Engineer to join the Vulnerability and Exploitation Threat Intelligence (VEX TI) team as a part of Amazon Cyber Threat Intelligence (ACTI). As a Senior Security Intel Engineer, you will leverage your in-depth knowledge and analysis of emergent exploits, exploit frameworks, and vulnerabilities to identify novel threat actors, discover attacks against Amazon, AWS and their customers, and drive effective technical countermeasures. ACTI is responsible to identify, curate, and report timely, accurate, and actionable threat intelligence. ACTI delivers cyber threat intelligence to Amazon and AWS leadership, service teams, partners, and both internal and external customers.In the Senior Security Intel Engineer role you will formulate new analytic techniques and work across teams to drive the supporting capabilities. A deep understanding of advanced actor tactics, techniques, and procedures (TTPs) is required, as well as how those TTP’s will present themselves in network-based and host-based logs derived from software, operating systems, networks, cloud infrastructure, networking equipment, and web applications. In addition, you will script and help automate recurring tasks to improve the overall effectiveness of the intelligence and how it is utilized throughout Amazon and AWS, to include; tactical integrations with red and blue teams and strategic impact overall. Beyond direct technical work on exploits, vulnerability research, and threat intelligence, the VEX Senior Security Intel Engineer will steer strategic direction in the secure design of AWS services, coordinate take-downs of malicious infrastructure, and drive effective technical countermeasures.Key job responsibilities* Identify, research, and analyze novel vulnerabilities discovered in threat intelligence data, applications, devices, and networks * Interface with ACTI reverse engineers to provide reversing requirements as well as be able to independently triage malware, analyze exploit code, and study attack techniques to understand how vulnerabilities are being weaponized * Pursue actionable intelligence on current exploits, perform deep dive analysis of malicious artifacts related to software exploits, and use that data to identify attacks against Amazon, AWS, and its customers* Analyze large and unstructured data sets to identify trends and anomalies indicative of malicious activities* Create security techniques and automation for internal use that enable the team to operate at high speed and broad scale* Provide situational awareness on the current threat landscape and the techniques, tactics, and procedures associated with specific threats* Accurately document ongoing investigations, craft consumable threat intelligence products, and clearly present and communicate emerging threats and high-risk vulnerabilities in cloud, network devices, and web applications to key stakeholders * Periodic on-call responsibilitiesA day in the lifeIdentify novel and impactful exploits and vulnerabilities to inform threat intelligence analysis and identify new and unknown impactful threat actors targeting Amazon, AWS, and our customers.About the teamThe AWS Threat Intelligence VEX team, part of Amazon Cyber Threat Intelligence (ACTI), is responsible for developing actionable intelligence on exploits and vulnerabilities utilized by advanced cyber threats against AWS services and AWS customers. We obtain indicators and intelligence from a variety of internal and external sources and use that information to develop an understanding of sophisticated, emerging actors, and their tools, techniques, and procedures. We then leverage that understanding to proactively identify and mitigate malicious activity.Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.Our team also puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work.Here at AWS, we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employee-led affinity groups, reaching 40,000 employees in over 190 chapters globally. We have innovative benefit offerings, and we host annual and ongoing learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences. Amazon’s culture of inclusion is reinforced within our 16 Leadership Principles, which remind team members to seek diverse perspectives, learn and be curious, and earn trust.We are open to hiring candidates to work out of one of the following locations:Annapolis Junction, MD, USA | Arlington, VA, USA | Austin, TX, USA | Herndon, VA, USA | New York, NY, USA | Seattle, WA, USA

amazon.jobs
I’m hiring - come join the AWS Threat Intelligence team! We’re looking for a senior security engineer who can both tackle threats and use automation to supercharge our analytical work. Hybrid in several US locations, domestic relocation. DM with questions! https://www.amazon.jobs/en/jobs/2502402/senior-security-intelligence-engineer-aws-threat-intelligence?no_int_redir=1
Senior Security Intelligence Engineer, AWS Threat Intelligence

The AWS Threat Intelligence team, part of Amazon Cyber Threat Intelligence (ACTI), is responsible for developing actionable intelligence on advanced cyber threats to AWS services and AWS customers. We obtain indicators and intelligence from a variety of internal and external sources and use that information to develop an understanding of sophisticated actors and their tools, techniques, and procedures. We then leverage that understanding to proactively identify and mitigate malicious activity.The successful candidate will analyze indicators to generate actionable intelligence and insight into current threats. As a Senior Security Intelligence Engineer, you will help enhance our capabilities by formulating new analytic techniques and working across teams to drive the supporting capabilities. A deep understanding of current cyber threat actors and TTPs as well as experience performing question-driven analysis is required. You will leverage your understanding of networking- and host-based indicators and digital forensics as you investigate incidents and threats as well.Contributing meaningfully to the automation and scaling of the team’s threat intelligence processes and work will be a primary responsibility of this role.Inclusive Team CultureHere at AWS, we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employee-led affinity groups, reaching 40,000 employees in over 190 chapters globally. We have innovative benefit offerings, and we host annual and ongoing learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences. Amazon’s culture of inclusion is reinforced within our 14 Leadership Principles, which remind team members to seek diverse perspectives, learn and be curious, and earn trust.Work/Life BalanceOur team also puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well balanced life—both in and outside of work.Mentorship & Career GrowthOur team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. Our senior members enjoy one-on-one mentoring and thorough, but kind, code reviews. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.Key job responsibilitiesKey responsibilities include:- Perform deep dive analysis of malicious artifacts.- Analyze large and unstructured data sets to identify trends and anomalies indicative of malicious activities.- Create security techniques and automation for internal use that enable the team to operate at high speed and broad scale.- Provide situational awareness on the current threat landscape and the techniques, tactics and procedures associated with specific threats.- Pursue actionable intelligence on current threats as they relate to AWS.- Periodic on-call responsibilities.We are open to hiring candidates to work out of one of the following locations:Annapolis Junction, MD, USA | Arlington, VA, USA | Austin, TX, USA | Herndon, VA, USA | New York, NY, USA | Seattle, WA, USA

amazon.jobs
And we’re live at #CYBERWARCON! Please come say hello!
Come say hello if we cross paths tomorrow at @CYBERWARCON! Excited to see great talks, catch-up with many #threatintelligence folks, and hopefully meet some new ones. Also come find me if you have badness in/relating to AWS that needs attention. 😉
Proud of MadPot and the many different ways AWS leverages first-party threat intelligence to better protect our customers! https://www.aboutamazon.com/news/aws/amazon-madpot-stops-cybersecurity-crime
Meet MadPot, a threat intelligence tool Amazon uses to protect customers from cybercrime

Curbing cybercrime is no easy task, but Amazon has been quietly doing its part with exceptional results.

US About Amazon
“The indictment handed down today challenges every American to put a shoulder to the wheel and defend our republic in every peaceful, legal, and civilized way they can. According to the charges, not only did Trump try to overturn the election; he presided over a clutch of co-conspirators who intended to put down any further challenges to Trump’s continued rule by force.” https://www.theatlantic.com/newsletters/archive/2023/08/trump-indictment-charges-overturn-2020-election/674887/
This Is the Trump Indictment That Really Matters

Special Counsel Jack Smith has sounded the call, but voters must answer it if they wish to preserve American democracy.

The Atlantic

my to-read pile grows ever larger with the addition of @pluralistic's https://www.kickstarter.com/projects/doctorow/the-internet-con-how-to-seize-the-means-of-computation

so many good books coming out recently