Aaron Rosenmund Speaking At Rsac23

53 Followers
4 Following
24 Posts
Adopted Stark | Red Team Operator | Threat Researcher and Hunter | Tool Developer | @pluralsight | @usaf
As I enter the plane, boarding for San Francisco from ATL, the familiar musk of a corporate dominated #RSAC2023 vendor floor reminds me I am likely under dressed. ;)
As a man of science and go programming....clearly it's witches.
@eric_capuano are you coming to rsac23? Want to catch up on cyber shield?
Okay I keep stepping away for too long, then I come back and think...man this is a lot like oh Twitter
Validation is one of my love languages.
Tracking a set connected to RU, injecting iframes to load up their .php pages, downloading "updateinstaller.zip"
https://www.virustotal.com/graph/embed/ga78a6e64d3034237bd9e99cbcb21e7df67aaf0940f1d4762b2b646f2a029e1ed?theme=light
Virustotal Graph

Virustotal Graph

Published video on basic string evasion for current anti virus engines. Keep following as I slowly turn up the heat on anti virus engines, and watch how they crack.
https://youtu.be/UxJtpOO2Myc
Irconcat Malware - String Based Detection Evasion

YouTube
Hot Take: the level of effort to implement SBOMs vs the level of impact on the ultimate result of reducing total cost of compromise or number of compromises in general is not worth the squeeze..... #shmoocon23
At #shmoocon23 and the first talk didn't even have a Twitter on it...just a mastadon handle...have we fully decided as a group no more Twitter?
#bsidesorlando figured I would get the Convo started for Bsides Orlando events here. Anyone else attending?