So Microsoft, S1, and Palo have all withdrawn from the MITRE Attack Evaluations for 2026. Moderately interestingly, S1 and Palo pulled out on the same day (9/12).
New TTP dropped!
Yesterday Microsoft announced a new feature coming in January, 2026.
Microsoft Intune's Unattended Remote Help for Windows: remotely access devices over the cloud without requiring end user involvement by signing in with credentials.
Yay!
New Sigma release r2025-07-08 is available for download.
🌟43 New Rules
🛡️34 Rule updates
🔬27 Rule Fixes
Explore the full release -> github.com/SigmaHQ/sigma/…
This release introduces a bunch of new rules including detections for
- Katz Stealer
- MeshAgent usage
-…
So… who has not seen the news right?
Scattered Spider is on a rampage by the looks of it.
Lets use this thread to share everything you know and can find on scattered spider folks. Combine our strength in times like this is most important!
Who is going to break the ice?
Introducing 🚀Eventlog Compendium 🚀
A new Streamlit app, that aims to be the go-to resource for understanding and playing with Windows Event Logs.
Explore it 👉 eventlog-compendium.streamlit.app
Includes the following utilities and docs
⚙️ Build your own Advanced Audit Policy based on…
🧵 ORACLE CLOUD BREACH: THE TRUTH BEHIND THE DENIALS (1/13)
I've been digging into the alleged Oracle Cloud breach that surfaced this weekend. The situation is FASCINATING. Oracle says nothing happened. The hacker and security researchers say otherwise. Let's break down what we…
Has @Oracle explained to anyone how a threat actor got a text file with their email address in the webroot of an OCI login server? Because I feel like if you're gonna deny an incident, that's a REALLY important detail.
web.archive.org/web/2025030116…
💡New and updated Azure Virtual Network documentation with the latest best practices covering all 5 Well-Architected pillars, new design recommendations including redundancy, security and monitoring patterns learn.microsoft.com/en-us/azure/ar…#Azure#AzureTipOfTheDay
Microsoft announces that for Exchange Online it will impose new limits on the number of external emails that all users (in total) in a tenant can send in a 24 hour period. Limits will depend on the number of licenses you purchase.
Microsoft announces that for Exchange Online it will impose new limits on the number of external emails that all users (in total) in a tenant can send in a 24 hour period. Limits will depend on the number of licenses you purchase. https://t.co/hyoY4psF4I
We prepared 300+ SIEM alerts for you! 🦔
Ever wondered how much effort goes into creating SIEM alerts? It's definitely not as easy as it seems! Our dedicated development and content teams have collaborated to streamline this process effectively.
🔐 Here is the secret sauce…
CISO Assistant: an open-source tool for managing Governance, Risk, and Compliance (GRC) across over 70 frameworks, including NIST CSF, ISO 27001, and SOC2, with features for risk assessment, audit management, and compliance tracking
#AiTM phishing remains a top method to gain initial access. When remediating a compromised account, consider the following:
1. Disable the account
2. Revoke all active sessions
3. Reset the password
4. Review registered MFA devices—check if a threat actor added any.
5. Review…
IMPORTANT: Microsoft will automatically switch users to the New Outlook in January 2025!
𝐒𝐮𝐦𝐦𝐚𝐫𝐲:
Starting in January 2025, users with Microsoft 365 Business Standard and Premium licenses are automatically migrated from the classic Outlook for Windows to new Outlook for…
Microsoft updated their recommended Conditional Access Policies this year. Many of the changes are based on the current threat landscape. For orgs using federation with a provider like OKTA or DUO, these are still recommended and integrate with the IdP. learn.microsoft.com/en-us/entra/id…
Microsoft updated their recommended Conditional Access Policies this year. Many of the changes are based on the current threat landscape. For orgs using federation with a provider like OKTA or DUO, these are still recommended and integrate with the IdP. learn.microsoft.com/en-us/entra/id… https://t.co/1k9FQz1Xls
224K Followers 6K FollowingFounder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
3K Followers 488 FollowingGuidePoint Security provides trusted cybersecurity expertise, solutions, and services that help organizations make informed decisions and minimize risk.
2K Followers 109 FollowingHubble has been acquired by @NetSPI, the proactive security solution used to discover, prioritize, and remediate security vulns of the highest importance.
109K Followers 2 FollowingMonitor your external network, search the Internet of Things and perform empirical market research. You can also find us on https://t.co/nPLFbFy8R5
113K Followers 521 FollowingMITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Re-tweeting ≠ endorsement. @ https://t.co/wt46ArkZVt
8K Followers 16 FollowingIP data built for scale. Get geolocation, privacy flags, carrier data & more.
IPinfo powers smarter decisions with the world’s most trusted IP data.
500K+ users
2K Followers 13 FollowingrunZero (formerly Rumble Network Discovery) delivers total attack surface & exposure management. See & secure every asset on your network. Try it free today!
127K Followers 2K Following🎨 ADHD creator 🎤 Keynote speaker 📚 Author + designer of “The Anti-Planner: How to Get Sh*t Done When You Don’t Feel Like It” ✨https://t.co/CGtUcMRepp✨
26K Followers 1K FollowingI play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here:
@[email protected]
https://t.co/hXggdAVkSQ
39K Followers 1K FollowingHead of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer.
Former @USMC.
59K Followers 3K FollowingStoryteller, wanderer, comic, historian, world’s oldest millennial. I used to do stuff, now I do other stuff. @[email protected]