Katie Nickels

4.3K Followers
604 Following
40 Posts
Director of Intel at Red Canary. SANS Certified Instructor for FOR578: Cyber Threat Intelligence. Senior Fellow at Atlantic Council's Cyber Statecraft Initiative. She/her. Media requests: press(@)redcanary(.)com
Bloghttps://link.medium.com/g5KsU8FR2ub
LinkedInhttps://www.linkedin.com/in/katie-nickels
Twittodonhttps://twittodon.com/share.php?t=likethecoins&[email protected]
Good morning #RSAC!!! Come to Moscone South where we'll be doing an awesome panel on incident response starting at 9:40! Honored to share the stage with @lhn @wendiwhitmore @hacks4pancakes
RSA Conference Unveils Initial 2023 Keynote Speaker Lineup

RSA Conference™ announced its initial lineup of keynote speakers for its upcoming Conference at the Moscone Center in San Francisco from April 24-27

Listening to @spacerog tips on writing the perfect resume for those starting out in #infosec. Just experiences based on an internship program he and a co-worker started several years back. (Note: Spacerog is NOT an HR person 😉.) [I added a few comments in brackets.] #ShmooCon

Hey all,

We have heard a lot about the skills gap in security. We are also seeing articles that say we are short something like a million people worldwide.

Because of this we started the Pay What You Can model for intro classes at Antisyphon over COVID.

My next class starts next week.

It is an Intro To Security class.

Yes, even paying nothing is an option.

We do this to help the industry, but more so to help people get jobs that would be unavailable to them.

Any barrier you see can be boiled down to two things. Restrictions on money and restrictions on education. Knowledge is power. But traditionally knowledge was expensive.

Very expensive.

By embracing the Pay What You Can model we at Antisyphon are helping to break down barriers based on where you come from or who you are.

We just want more cool people to do cool stuff with.

Please share this post or link with someone you think would kick ass in the industry, but they just need a shot.

Thanks,

John

https://www.antisyphontraining.com/getting-started-in-security-with-bhis-and-mitre-attck-w-john-strand/

Getting Started in Security with BHIS and MITRE ATT&CK w/ John Strand – Antisyphon Training

Fake Microsoft Teams website used to download IcedID malware

🌐​ mlcrosofteams[.]top
⬇️​ Downloads .zip containing .msi

#IcedID C2: whothitheka[.]com

This is likely being distributed by #malvertising but I wasn't able to capture the advertisement

193.222.62[.]37 is also hosting fake IRS & Royal mail websites
🏦​ irs-forms[.]top
🏦​ royalmail.orders-info[.]uk

🔗https://www.virustotal.com/gui/file/8ed2026fd98d54f9ad85d721223b60bd8b6c1362faeb4c24492d2bb63a7c357b/details
🔗https://urlscan.io/result/a0e5de3e-75ea-46f4-8340-0ab09c440850/
🔗https://urlscan.io/ip/193.222.62.37

#CTI #threatintelligence #ThreatIntel #Malware

VirusTotal

VirusTotal

Argh. Forgot to play in the third round of @ShmooCon ticket competition today.

Anyone have one, or even two, they would resell?

Here's some awesomeness from @hal_pomeranz to watch! "Linux Command Line Dojo II - Return of the Sensei" → https://www.youtube.com/watch?v=dtyX7XO-GSg

Be sure to check out Hal's courses, "Linux Forensics", "SELinux – Necessary and Not Evil!", & "Linux Command-Line Dojo"→ https://www.antisyphontraining.com/course-catalog/

Linux Command Line Dojo II - Return of the Sensei

YouTube
Gooooo @hacks4pancakes!!! Congratulations on your SANS Difference Maker Lifetime Achievement Award - we're so glad you have a whole lifetime ahead of you to keep being awesome. :)
Please boost if you’re still masking indoors (in public places)
I have a guest pass for @sansinstitute #CTI #CTISummit at the end of January. I can't cover travel, etc., but if anyone has a #threatintel padawan local to the #DC / #NoVa area, let me know - def trying to get this in the hands of someone who wouldn't be able to attend otherwise!