875 Followers
93 Following
13 Posts
Researcher @SpecterOps. Coding towards chaotic good while living on the decision boundary. #dontbanequality 

We (@greynoise) have some shiny new toys for folks today!

— IP Timeline (https://www.greynoise.io/blog/introducing-ip-timeline) • see the history of what an IP address was doing
— ML model driven IP Similarity (https://www.greynoise.io/blog/introducing-ip-similarity) • get a leg up on attackers by catching similar ones exhibiting the same behaviors

Rly proud of all the GNoids who made this possible.

GreyNoise | Introducing IP Timeline

The IP Timeline provides context to 60 days of data collected on an IP displayed in timechart format. Users can correlate the behavior of an IP they have seen in their data, learn what schedule an IP operates on, or gain a greater understanding of ownership and behavioral changes.

Today @WhiteHouse & @ONCD released the National CyberSecurity Strategy

Important shifts:
- Rebalancing responsibility to defend cyberspace to those most capable of defense (incl Software liability)
- Realigning incentives to favor long term investments

https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf

This document builds on previous work & also provides an important shift leveraging lessons learned, a mission the Cyber Safety Review Board was created to support.
Good to see a commitment from the @WhiteHouse to codify CSRB with Congress & grant us more authority to investigate

I am so super happy to announce I am a keynote at #BlueHat Israel this month in Tel Aviv. It’s will be my first trip there, so I’m super excited to meet the community in person!

https://www.microsoftrnd.co.il/bluehatil/home

https://twitter.com/BlueHatIL/status/1631325342236393472?s=20

BlueHatIL - Home

Why you should prevent storage of LAN Manager password hashes

Describes how to prevent storage of LAN Manager password hashes and outlines context and best practices.

New blog post out: Passwordless Persistence and Privilege Escalation in Azure.

Link: https://posts.specterops.io/passwordless-persistence-and-privilege-escalation-in-azure-98a01310be3f

In this blog post I explain how new passwordless authentication mechanisms like Azure's Certificate Based Authentication can be subverted by adversaries to establish long-term stealthy persistence, and explain a built-in privilege escalation primitive that exists in CBA.

Passwordless Persistence and Privilege Escalation in Azure

Adversaries are always looking for stealthy means of maintaining long-term and stealthy persistence and privilege in a target environment. Certificate-Based Authentication (CBA) is an extremely…

Posts By SpecterOps Team Members
Attending #BHEU this week? So are we! Come by Booth 506 to find out more about our services, trainings, and #BloodHoundEnterprise.
WonkaVision - A proof of concept (POC) tool to analyze Kerberos tickets and attempt to determine if they are forged. https://github.com/0xe7/WonkaVision #blueteam
GitHub - 0xe7/WonkaVision

Contribute to 0xe7/WonkaVision development by creating an account on GitHub.

GitHub

We are excited to join infosec.exchange

We will be posting all our announcements, updates, and social content here, as well as other platforms, and look forward to great interactions with the community here.

Step 1: Support infosec.exchange (instructions here: https://infosec.exchange/@jerry/101767036616676231)
Step 2: Add the  badge to your name / profile
Step 3: Enjoy not being the product
Jerry Bell :verified_paw: :donor: (@[email protected])

Just a reminder, you can support infosec.exchange through liberapay: https://liberapay.com/Infosec.exchange/ Thanks!

Infosec Exchange
Who are some good people on here I should follow?