Jose Enrique Hernandez @_josehelps
š”ļø Threat Research Director @Splunk ā¤ļø Scuba Diving š§ Maintainer of #AtomicRedTeam #LOLDRIVERS #LOLRMM #LOLBAS josehelps.com The mothership Joined March 2008-
Tweets5K
-
Followers3K
-
Following2K
-
Likes13K
Say it with me.. User .. Behavior ⦠Analytics š„
A new project demonstrates how attackers exploit Bring Your Own Vulnerable Driver (BYOVD) techniques to bypass modern defenses. Using the RTCore64.sys driver, adversaries can: ā”ļøĀ BYOVD enables attackers to manipulate kernel-level functions, bypassing security controls. ā”ļøĀ Theā¦
Cisco Talosā latest blog exposes Static Tundra, a Russian state-sponsored group targeting unpatched Cisco devices for long-term espionage worldwide. Apply the patch now and protect your network: cs.co/6018fvA0O
Attackers know how to find your weak and misconfigured Applocker rules. Now you can too.... š§µJust finished putting together a new tool to find weak and misconfigured AppLocker policies. Itās called AppLocker Inspector. Hereās how this tool came to be and what it does thatāsā¦
It's just not a good market for app control bypass research these days, so I moved on to researching other things no one cares about.
It's just not a good market for app control bypass research these days, so I moved on to researching other things no one cares about.
github.com/0x4D31/finch is a really slick tool, super easy to use, flexible configs, great logs - thank you @0x4D31 !
[New Blog š] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering If you ever struggle with false positives and the idea of tuning detections. This is for you. Read More - nasbench.medium.com/the-fragile-baā¦
ESXi is a hot target lately. Come check out the work Splunk Threat Research did around catching this activity before it gets out of control. Read more here - splunk.com/en_us/blog/secā¦
Iām excited to announce two major upgrades in our free product line: š¦ Archive scanning is now unlocked in THOR Lite - including docx, xlsx, jar, war, and more š§ YARA Forge (my own project) is now integrated ā extends the detection coverage with open source rules š Alsoā¦
Iām excited to announce two major upgrades in our free product line: š¦ Archive scanning is now unlocked in THOR Lite - including docx, xlsx, jar, war, and more š§ YARA Forge (my own project) is now integrated ā extends the detection coverage with open source rules š Alsoā¦
LOLdrivers.io now has SIEM queries and a tool section for those looking to operationalize the data. Thanks to @Cyb3rMonk and @M_haggis for sharing the queries with the community! Also shout out to @TenableSecurity for sharing the Nessus plugin, @Oddvarmoe for theā¦
šØ How #Rhadamanthys Stealer Slips Past Defenses using ClickFix ā ļø Rhadamanthys is now delivered via ClickFix, combining technical methods and social engineering to bypass automated security solutions, making detection and response especially challenging. š¾ While earlierā¦
If you didn't see it, check out the llm payload generation research from @kyleavery_ . The best research I've seen in the offensive security AI space. I'm probably biased, but it shows what's possible. outflank.nl/blog/2025/08/0ā¦
Be wary of people who spew AI hype and screenshot their army of agents but don't seem to be shipping anything but demos. I'm a big fan of AI assistance and use agents and chat everyday, but there's a ton of engagement farming happening out there.
LOLRMM.io now tracks over 290 RMMs, with new ones being added regularly. These tools provide legitimate functionality but are frequently repurposed by attackers. Read here: buff.ly/oNbWfa6 If you're not using them in your setup, why allow them to run?ā¦
Want to truly test your defenses? š”ļø Atomic Red Team offers simple, executable tests mapped directly to MITRE ATT&CKĀ® techniques ā for free! šŖ These vital resources help you: ā Set up your test environment. š Browse tests for Windows, macOS, Linux, & cloud. š§Ŗ Executeā¦

Florian Roth ā”ļø @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy āļøš | vi/vim
SwiftOnSecurity @SwiftOnSecurity
405K Followers 9K Following computer security person. former helpdesk.
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here ā find me on Bluesky: https://t.co/qHzDSxCRfG. š¬š·šØš¦
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Dave Kennedy @HackingDave
223K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Thomas Roccia š¤ @fr0gger_
31K Followers 2K Following AI Security x Threat Intel Ā· Sr. Threat Researcher @Microsoft Ā· Creator of #Unprotect & #NOVA Ā· Malware Warlock Ā· Python š§” Ā· Prev @McAfee_Labs Ā· Views mine š
Michael Koczwara @MichalKoczwara
23K Followers 2K Following Threat Researcher/Founder @Intel_Ops_io Threat Intelligence, Adversary Infrastructure Hunting, Curated TI Feed (Coming Soon) https://t.co/VQWaze6gaF
Mehmet Ergene @Cyb3rMonk
13K Followers 437 Following https://t.co/uAlYlXIpyV Learn #KQL for #ThreatHunting, #DetectionEngineering, and #DFIR @BluRavenSec | Microsoft Security MVP | #DataScience
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Samir @SBousseaden
25K Followers 1K Following Detection Engineering | Elastic Security Mastodon: @[email protected]
Nasreddine Benchercha... @nas_bench
11K Followers 1K Following Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner
Christopher Peacock @SecurePeacock
7K Followers 2K Following #PurpleTeam | Ex @RaytheonTech MSSP, @SCYTHE_IO, & @GD_OTS | Taught at BlackHat & DEFCON | #100DaysofSigma | Keep exploring, keep learning, and stay curious
The Haag⢠@M_haggis
9K Followers 2K Following Threat Researcher | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer | I'm Everywhere and Nowhere - BSG.
Olaf Hartong @olafhartong
17K Followers 965 Following @FalconForceTeam | researcher with a camera | Microsoft MVP | Snow man role model
John Hammond @_JohnHammond
298K Followers 3K Following Cybersecurity Researcher @HuntressLabs || Just Hacking Training @JustHackingHQ w/ @ethicalhacker || https://t.co/UtsNJiyQtS || https://t.co/narO3sz7y6
Jā©āmie Williams @jamieantisocial
10K Followers 7K Following threats && stuff || #UNC1799 forever š¤|| @DistrictHeather ā„ļø + š· **š ššš š šš”ššššššš ššš šš Ö š š**
Will @BushidoToken
36K Followers 3K Following Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
Clandestine @akaclandestine
49K Followers 5K Following | Security | Osint | Threat Research | Opsec | Threat Intelligence | Infosec | Threat Hunting | Humint |
Herzvoll @NIPwFAa9b8M70
8 Followers 321 Following
Qafuv @Qafuv236395
0 Followers 224 Following
AndrƩ Kachlov @AKachlov7141
1 Followers 119 Following
Zoe Kiehn @ZoeKiehn54026
71 Followers 4K Following
8lU3sH33p @8lU3sH33p
101 Followers 2K Following
Aimee @aimeemcintyre71
234 Followers 3K Following
Dariana Cronin @CroninDari49686
98 Followers 2K Following
Ada @UzairurRehman4
26 Followers 816 Following Nothing should belong to you originally, so itās better to lose a little bit
Darren @dabear1981
172 Followers 993 Following
Lawrence_Sec @Lawrence_Sec
109 Followers 494 Following š¬š§ Threat Research @RecordedFuture https://t.co/yrwObzizEk
tom square @harold9850
3 Followers 167 Following
Seysmey @SeysmeyEtw3
102 Followers 4K Following Fairycore enthusiast š§āļøš | Cottagecore wannabe
TheCyberGuy @CyberIsFuture
3 Followers 38 Following
Lisa A. Kirby @lisakirbyri
64 Followers 131 Following M.S. Cybersecurity March 2019...Looking towards the future!
BSwif @SwifSec
10 Followers 161 Following
kino @rphlrdrgs
47 Followers 640 Following
Snodig @Snodig1
60 Followers 2K Following
dexter @dexter79331247
0 Followers 2K Following
D0r!_!D@h@N @d0r_dhn92836
81 Followers 898 Following Junior Penetration Tester | CyberSecurity Instructor
MakBa @MakBaSec
4 Followers 1K Following
Microsoft EMS @microsoftems
34 Followers 330 Following
TechWizNet (ā,ā) @TechW1zNet
262 Followers 2K Following On the path to becoming a cybersecurity expert. Currently building skills in penetration testing and auditing smart contracts.
OneBadAlien @WilliamTaack
237 Followers 5K Following
Maximilian Schƶneber... @maxschoe149
16 Followers 205 Following
Ethan Word @planedrop
310 Followers 2K Following Systems Engineer | Network Engineer | Content Creator. https://t.co/a5GMwMidzd https://t.co/XNyovaZgI5 https://t.co/SRt0n0S0wC
Leonardo Gil @UnctusM
190 Followers 3K Following Infosec Addict. Ibis, redibis, nunquam per bella peribis.
row @rowwwor
0 Followers 34 Following
Fhloston @Fhloston_
186 Followers 4K Following
Dan @d778941
245 Followers 809 Following MSP Security Engineering Lead. Content posted is on my own behalf, and not that of my employer.
Rusty Miller @RustyMille80805
40 Followers 436 Following
Craig Mac @Craig_Mac59
193 Followers 2K Following
Pueamie @Pueamie8963
129 Followers 3K Following
EmpSel @EmperorSelassi1
154 Followers 3K Following 01001001 01101110 01100110 01101111 00100000 01010011 01100101 01100011
Qasim Qlf @qasimqlf
319 Followers 2K Following Detection Engineer | Ex-Software Engineer @ NETSOL | | Tech Enthusiast š» | Contributer @sigma_hqš” | Proud Muslim and Pakistani šµš°
Harvester @Harvesterify
1K Followers 5K Following Protecting Galileo at @esa | Ground segment cybersecurity | All your ground stations are belong to us | Previously @SafranElecDef & @ANSSI_FR
Vuifeat @Vuifeat1182
119 Followers 3K Following
Norbert @NB1r0
59 Followers 3K Following
Vorjirl @Vorjirl34884
59 Followers 2K Following
Florian Roth ā”ļø @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy āļøš | vi/vim
vx-underground @vxunderground
368K Followers 290 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
SwiftOnSecurity @SwiftOnSecurity
405K Followers 9K Following computer security person. former helpdesk.
Stephan Berger @malmoeb
28K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here ā find me on Bluesky: https://t.co/qHzDSxCRfG. š¬š·šØš¦
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Dave Kennedy @HackingDave
223K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Thomas Roccia š¤ @fr0gger_
31K Followers 2K Following AI Security x Threat Intel Ā· Sr. Threat Researcher @Microsoft Ā· Creator of #Unprotect & #NOVA Ā· Malware Warlock Ā· Python š§” Ā· Prev @McAfee_Labs Ā· Views mine š
Michael Koczwara @MichalKoczwara
23K Followers 2K Following Threat Researcher/Founder @Intel_Ops_io Threat Intelligence, Adversary Infrastructure Hunting, Curated TI Feed (Coming Soon) https://t.co/VQWaze6gaF
Mehmet Ergene @Cyb3rMonk
13K Followers 437 Following https://t.co/uAlYlXIpyV Learn #KQL for #ThreatHunting, #DetectionEngineering, and #DFIR @BluRavenSec | Microsoft Security MVP | #DataScience
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Chris Sanders š ļæ½... @chrissanders88
34K Followers 489 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Samir @SBousseaden
25K Followers 1K Following Detection Engineering | Elastic Security Mastodon: @[email protected]
Florian Hansemann @CyberWarship
84K Followers 47 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
SANS DFIR @sansforensics
109K Followers 98 Following The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
Nasreddine Benchercha... @nas_bench
11K Followers 1K Following Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner
Christopher Peacock @SecurePeacock
7K Followers 2K Following #PurpleTeam | Ex @RaytheonTech MSSP, @SCYTHE_IO, & @GD_OTS | Taught at BlackHat & DEFCON | #100DaysofSigma | Keep exploring, keep learning, and stay curious
The Haag⢠@M_haggis
9K Followers 2K Following Threat Researcher | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer | I'm Everywhere and Nowhere - BSG.
Olaf Hartong @olafhartong
17K Followers 965 Following @FalconForceTeam | researcher with a camera | Microsoft MVP | Snow man role model
Lawrence_Sec @Lawrence_Sec
109 Followers 494 Following š¬š§ Threat Research @RecordedFuture https://t.co/yrwObzizEk
Julian-Ferdinand @JulianVoeg
826 Followers 410 Following Threat Research @RecordedFuture. Formerly @SecReLabs. He/Him. š³ļøāš [email protected]
SecurIT360 @SecurIT360
290 Followers 157 Following We measure against industry standards, advise how to align with security standards, and train staff to effectively understand and practice information security
Nick VanGilder @nickvangilder
2K Followers 3K Following Red Team Director | Mission Focused Leader | Combat Veteran | Offensive Security Program Builder | Mentor and Coach
rekdt @rekdt
11K Followers 714 Following // principal cybersecurity anarchist // unethical hacker // ex aws, wn, else // @redteamvillage_ & @sec_defcon daemon // take īØ sincerely at your own risk
Threat Insight @threatinsight
11K Followers 218 Following @Proofpoint's insights on targeted attacks & the security landscape. Follow us on Bluesky: https://t.co/8OVfhotdeP
Swachchhanda Poudel @_swachchhanda_
87 Followers 370 Following Threat Researcher | Detection Engineer @nextronsystems | #sigma #yara https://t.co/LjJ2sh3CIE
/ĖziĖf-kÉn/ @x33fcon
7K Followers 1 Following When Red meets Blue... The very first security conference for Purple Teams on the planet
Matt Anderson @nosecurething
2K Followers 1K Following Staff Detection Engineer @HuntressLabs Threat Research | Threat Hunting | Malware Analysis
SpacialSec @SpacialSec
845 Followers 52 Following selling office fans and occasionally doing threat intel OFFICIAL SpacialSec⢠discord: https://t.co/7oQPyclziX
Kim Oppalfens (MVP) ļæ½... @TheWMIGuy
5K Followers 221 Following #MemCM #Infosec enthusiast. āNon-limited code execution will almost certainly result in full system compromise over time.ā #WDAC. 20 years of MVP citizenship.
NULL Life CTF Team @NullLifeTeam
1K Followers 158 Following Latin america CTF team | http://t.co/apntwLkiLz
Syntax @syntaxfm
46K Followers 299 Following Tasty Treats for Web Developers with @wesbos @stolinski and @codinggarden Brought to you by @getsentry
Adam Hassan @adamislucky
3K Followers 1K Following Startup investor, SMB founder/operator, large cap SaaS sales, living at the intersection of public safety, technology, entrepreneurship and good vibes.
spencer @techspence
12K Followers 2K Following š”ļøEmpowering defenders & dismantling threats | Ethical Threat | pentester @securit360 | host @cyberthreatpov | SWAG https://t.co/AFJtZQcti7
Ryo Lu @ryolu_
55K Followers 2K Following Head of Design @Cursor_ai. Early @NotionHQ, @Stripe, built startups. I make a world where anyone can make software. Aspiring k-pop idol.
Tyler Shukert @dshukertjr
15K Followers 98 Following DevRel engineer @supabase ā”ļø Follow for Supabase tips!
Dark Web Informer @DarkWebInformer
129K Followers 59 Following Providing Cyber Threat Intelligence from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threat Alerts & more. https://t.co/Fi7VW9lg94
Mckay Wrigley @mckaywrigley
210K Followers 359 Following I build & teach AI stuff. Founder @TakeoffAI where weāre building an AI coding tutor. Come learn to code + build with AI at https://t.co/oJ8PNoAutE.
Francisco SƔa MuƱoz @enonethreezed
921 Followers 615 Following Hunt your mistakes like you hunt threats - Casey Smith
Kevin Kern @kregenrek
18K Followers 465 Following Teaching & building AI apps ā https://t.co/4MQ9vOmIOt ā Cursor Course ā Newsletter: https://t.co/3KKVcffvCf ā My AI Prompts: https://t.co/6KdZMINT79
God of Prompt @godofprompt
141K Followers 842 Following š Sharing AI Prompts, Tips & Tricks. The Biggest Collection of AI Prompts & Guides for ChatGPT, Grok, Claude & Midjourney AI ā https://t.co/vwZZ2VSfsN
Frey @Freyxfi
5K Followers 67 Following 24 y/o Pentester and MMA Player love to exploit web šøļø | https://t.co/LGRIAkn3dR | LW (9-0-0) š„// And I do everything solo šŗ
Tom Dƶrr @tom_doerr
101K Followers 2K Following Follow for posts about GitHub repos, DSPy, and agents Subscribe for top posts DM to share your AI project (Due to volume of DMs I'll prioritize subscribers)
EvilMogĀ® @mog.evil.a... @Evil_Mog
17K Followers 2K Following Hacker, Team Hashcat, Bishop of the Church of Wifi, Uber Badge Collector. Views != Employers. Not a Ph.D, Recycled Memes,
Robert Sterling @RobertMSterling
165K Followers 3K Following Finance bro. Marine. M&A advisory + fractional CFO: https://t.co/tCFru8OTnU. Cheap consulting: https://t.co/pA6vOQRS6i. Accounting: https://t.co/B0h3FJlIeL.
cyberundergroundfeed @cyberfeeddigest
7K Followers 149 Following I deliver daily #DarkWeb ,#DeepWeb and #CTI feeds,and a bit of geopolitical clashes #Darkweb #Deepweb #Ransomware #Malware #Databreach #CTI #ThreatIntel
Angel Hun @SeraphimDomain
2K Followers 778 Following Blue Team, RE, Independent Researcher, Cyber Weapon. My views are my own.
William Metcalf @node5
1K Followers 392 Following I have been recruited by the Star League to defend the Frontier against Xur and the Ko-dan Armada
Ransom-DB @Ransom_DB
2K Followers 73 Following Professional CTI service for advanced ransomware intelligence. Real-time incident tracking and deep insights to keep you updated with the most known threats.
Nextron Research ā”ļæ½... @nextronresearch
2K Followers 10 Following Nextron Systems Threat Research Team research (att) https://t.co/QTt2X62dXP
Gi7w0rm @Gi7w0rm
18K Followers 801 Following Threat Intelligence Analyst | See my Linktree for other socials | In case I post false intel, contact me! Support me: https://t.co/5WgDqr0K8p šŖšŗš©šŖšŗš¦š
tonghuaroot @tonghuaroot
448 Followers 3K Following Staff Security Engineer. Cyber Security enthusiast, not Hacker. Focus on Application Security, Penetration testing. #OSCP #OSEP #RedTeam #AppSec #WebSec
CRV @CRV
37K Followers 293 Following CRV specializes in early-stage seed and Series A startups. We've invested in over 750 companies including Cribl, DoorDash and Vercel.
Ruben Groenewoud @RFGroenewoud
525 Followers 301 Following A security research engineer at @Elastic focusing mainly on Linux behavior-, signature- and ML-based detection engineering. Github: https://t.co/KKlA2KIjGj
RussianPanda š¼ ļæ½... @RussianPanda9xx
15K Followers 523 Following ŠŠµŠ½Ń ŠøŃŠµŃ ŠŠŠ š | Threat Hunter @HuntressLabs | TRACLabs | Malware Addict | DFIR
Guilherme Venere @gvenere
343 Followers 449 Following I break things. Threat Researcher @TalosSecurity. I post about games and Security. @[email protected] after the exodus Opinions are my own.
Hare Sudhan @cyb3rbuff
114 Followers 344 Following Software engineer in cybersecurity. Living the best of both worlds. Open Source Contributor and Maintainer of #AtomicRedTeam
Brad Garnett @brgarnett
1K Followers 366 Following Cybersecurity Executive | Consultant | Pilot | #DFIR | I helped build @TalosSecurity IR | @TEDx Speaker | --Opinions expressed here are mine alone.
Nick Biasini @infosec_nick
2K Followers 1K Following Head of Outreach at Cisco Talos. These are my views not my employers. @[email protected]
Justin Hall @justinhall
743 Followers 919 Following Jesus is my King. Sr Manager, Research @TenableSecurity. Opinions are mine and do not represent my employer. ā¤:šš®š²š„Ŗāµš§š»and you! @justinhall.bsky.social
Dark Web Intelligence @DailyDarkWeb
138K Followers 0 Following Daily Dark Web dose from the dark side.