Matthew Kennedy @_matt_kennedy
Manager at Microsoft Threat Intelligence Center. Adjunct Faculty at Georgetown University. Penn State Alum. Tweets are my own. Joined June 2020-
Tweets102
-
Followers369
-
Following220
-
Likes372
Today, Microsoft Threat Intelligence Center (#MSTIC) is excited to announce the release of #RIFT, a tool designed to assist software/malware analysts automate the identification of attacker-written code within Rust binaries. Blog: microsoft.com/en-us/security… Tool:…
At @CYBERWARCON, Microsoft is sharing research on North Korean threat actors who steal cryptocurrency and target satellite & weapons systems orgs, as well as details on intelligence collection operations by Chinese threat actor Storm-2077. Learn more: msft.it/6016Wvv28
My two favorite Gregs talking my favorite topic. Check it out! @greglesnewich @Greg_Schloemer thecyberwire.com/podcasts/micro…
One of the most fascinating aspects of following DPRK threat actors is observing leading indicators from numerous intrusion sets target the same technologies months before an announcement.
One of the most fascinating aspects of following DPRK threat actors is observing leading indicators from numerous intrusion sets target the same technologies months before an announcement.
This is a very interesting attack chain. Especially from a Sleet actor. North Korean threat actor Citrine Sleet exploiting Chromium zero-day microsoft.com/en-us/security…
Mandatory multi-factor auth for all of these services is going to make things significantly harder for threat actors to conduct intrusions. This will raise the resource cost significantly – and reduce success rate – for malicious infrastructure & service abuse in Azure.…
Mandatory multi-factor auth for all of these services is going to make things significantly harder for threat actors to conduct intrusions. This will raise the resource cost significantly – and reduce success rate – for malicious infrastructure & service abuse in Azure.…
🧵on the ongoing outage caused by Crowdstrike content update. Insights here mostly based on my time working on/helping build a competitor product Mandiant Intelligent Response\HX First & foremost this sucks for both Crowdstrike & their customers - no one wants to see this happen
It's not every day you get to lead in defining a new DPRK threat actor. A big congrats to the team that worked on this! "Moonstone Sleet’s diverse set of tactics is notable... because of how they have evolved from those of several other North Korean threat actors over many years"
It's not every day you get to lead in defining a new DPRK threat actor. A big congrats to the team that worked on this! "Moonstone Sleet’s diverse set of tactics is notable... because of how they have evolved from those of several other North Korean threat actors over many years"
Microsoft has identified a new North Korean threat actor, Moonstone Sleet (Storm-1789), that combines many tried-and-true techniques used by other North Korean threat actors with unique attack methodologies for financial and cyberespionage objectives. msft.it/6017Ygsud
New piece on TA427 (overlaps with Emerald Sleet, APT43, the K-word) 🇰🇵🇰🇵 Lots of benign email conversations to gather strategic information from NGOs, think tanks, and academics in the DPRK research space 📧📮 DMARC, typosquats, and solicitation oh my! proofpoint.com/us/blog/threat…
Pfizer's Cyber Threat Analysis and Response team is hiring a Cyber Intrusion Analyst ! Come join a team of curious and passionate defenders with a critical mission. This is a hybrid role based in the Philadelphia area. pfizer.wd1.myworkdayjobs.com/PfizerCareers/…
MSTIC is looking for a cleared Senior Threat Intelligence Analyst in Australia (CBR). This is an exciting opportunity to make a tangible difference in combating Nation State, ransomware threats, and more. Day to day you'll be working with peers around the world tracking and…
MSTIC is looking for Senior Security Researchers (Malware Reverse Engineers) in the US and Australia to join our MSTIC-RE team. This is an exciting opportunity to make a tangible difference in combating Nation State (NS/APT/DHA) and ransomware threats. jobs.careers.microsoft.com/global/en/job/…
Listen to Microsoft Threat Intelligence analysts @Greg_Schloemer & @_matt_kennedy discuss with @sherrod_im what makes the North Korean threat landscape unique, and how actors persistently abuse chains of trust to generate revenue for the regime: msft.it/6019i0kBF
This was a blast! Loved chatting all things North Korea cyber operations with @sherrod_im and @Greg_Schloemer!
This was a blast! Loved chatting all things North Korea cyber operations with @sherrod_im and @Greg_Schloemer!

Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Microsoft Threat Inte... @MsftSecIntel
187K Followers 1K Following We are Microsoft's global network of security experts. Follow for security research and threat intelligence.
Nick Carr @ItsReallyNick
38K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
💻 Sherrod DeGrippo... @sherrod_im
36K Followers 7K Following Weird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
Mark Parsons @markpars0ns
2K Followers 829 Following Threat Analyst @ Microsoft - mostly tweet about astrophotography and occasional some work. Tweets are my own
Chris Harrod @thechrisharrod
1K Followers 172 Following Personal account — Manager of Security Operations for the United States House of Representatives
☠️🐻Andy Piazza... @klrgrz
6K Followers 3K Following Christian. Killer Grizz, Threat Intel & Thrunter. Hack things w/ @bsides_nova. @DEFCON Contests Dept Lead & Black Badge DC32. GSE #344. (VIEWS ARE MY OWN).
Will @BushidoToken
36K Followers 3K Following Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
0xdf @0xdf_
25K Followers 468 Following Training Architect @ HackTheBox "Potentially a legit security researcher" he/him https://t.co/GCcLVlmdQK https://t.co/uQWVpw4nft 0xdf on discord
Ryan Tomcik @heferyzan
1K Followers 2K Following DE/TH @GoogleCloud @Mandiant Threat Defense | Google in the streets, Mandiant in the tweets | Thruntito ergo sum | Bsky: https://t.co/THP7ny8CgD
bk (Ben Koehl) @bkMSFT
3K Followers 772 Following Partner Director of Threat Intelligence at @Microsoft Threat Intelligence Center (MSTIC).
Mbugua Gichimu @GichimuMbu86442
6 Followers 131 Following
Amanda @VikasMi53259764
417 Followers 5K Following Hamlet, Act 3, Scene 1; Hamlet’s existential soliloquy asking whether life or death is nobler
neeraj gupta @realneerajgupta
322 Followers 3K Following
Caroline Kearney @Caroline__K_
797 Followers 1K Following DPRK foreign policy, peacebuilding in East Asia, PhD Candidate @Yonsei_u, permanent K-language student 🇺🇸-🇪🇸-🇰🇭-🇰🇷
CyberCareers.blog @cybercareerblog
182 Followers 2K Following Helping cybersecurity professionals everywhere level up. News, AI/ML, Tech, & Career Advice. 💻💾👨🏻💻🤖 Subscribe to our Newsletter: https://t.co/6ckQM6RS0J
justlurking @justlurkin8354
4 Followers 274 Following
Yahya Alsify @YahyaAlsify20
93 Followers 845 Following Malware Researcher | Reverse Engineer | Internals lover | 🇪🇬🇵🇸
I//uS!0nS @c03rci0n
179 Followers 7K Following
LuckY @L_uckyY
199 Followers 2K Following Generally interested in computers (DFIR/pentesting/networking) and likes to play wargames/CTF. Deleting tweets regularly. Likes are my way of bookmarking.
M Vetta @MVetta1
73 Followers 847 Following
0xW43L @GhnimiWael
681 Followers 4K Following CTI Researcher | SRT Member @synack | X-Red-Teamer | X-Blue-Teamer | Bug Bounty Hunter | OSEP | eWAPTx | arcX ... Hunt threats, secure systems, learn always.
jon greig @jgreigj
3K Followers 5K Following @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
Pi Lover @caratluvr17ot13
16 Followers 698 Following
Abdulla @bahraini
2K Followers 5K Following
Sharad Agarwal @shad1126
684 Followers 927 Following PhD Candidate @uclcs @uclisec @ucl | Fighting Scams @StopScamsUK | Created https://t.co/eRqc0P5Zut | Prev @BristolCyberSec @CMSexperiment @CERN @CERNopenlab
m01nlu1s @m01nlu1s
2 Followers 79 Following
Maarten Boutkan @maarten_boutkan
31 Followers 95 Following James Software | Eenvoudige en flexibele Praktijksoftware voor paramedici
Talayi @Hosien_talayi
225 Followers 2K Following
No Sig Info @n0pwn0sec
11 Followers 316 Following
nanjin002 @nanjin00272827
21 Followers 4K Following
Chris Cronbaugh @chriscronbaugh
105 Followers 278 Followingicanhaspii @icanhaspii
2K Followers 5K Following #Malware #Ransomware #DFIR #InfoSec #CyberSecurity #ThreatHunting #ThreatIntel #ForeverN00b #Mennonite Personal page, views don't represent employer.
Austin Baker @BakedSec
2K Followers 267 Following IR at LinkedIn | focused on the intersection of data science, engineering, and cybersecurity | Scooping up APT and bopping them on the head | opinions my own
Trustedlabs @Trusted_Labs
9 Followers 951 Following
Joe Devanny @josephdevanny
3K Followers 6K Following Senior Lecturer | @warstudies @kingscollegelon | National Security/Cyber Statecraft | Views mine.
HPendragon @carpe_noctem509
0 Followers 44 Following
tanderson @notthanderson
0 Followers 2K Following
Jw @JAKASUS26045177
5 Followers 296 Following
Yamimetz @yamimetz
8 Followers 531 Following
Lexie Aytes @cybseclex
86 Followers 409 Following Threat Researcher @ Google/Mandiant | just here for the memes | opinions are my own
RuffLandings @RuffLandings
94 Followers 2K Following Dogs. Aviation. Cybersecurity. Not necessarily in that order. @[email protected]
rewscel @rewscel
30 Followers 749 Following
Mark W @woots_m
686 Followers 1K Following Veteran of R Signals (Army), South Yorkshire Police. Currently looking at the world of cyber and intel- whilst enjoying life and cycling
Przemek Skowron @evilrez
944 Followers 2K Following Move && Eat && Hunt && Repeat. My tweets are my own.
skrappy0x4a @skrappy0x4a
449 Followers 2K Following Lead on Cyber Defense | GWOT | Dad | НОРД | 🏍🦑 | ◧◧◧ | 🌲
Abdur Rehman💫 @XargoKhan20
2K Followers 7K Following نَصْرٌ مِنَ اللَّهِ وَ فَتْحٌ قَرِيبٌ ...!!! LOVE ❤️ YOU !!! KHAN SAAB🍁🍂
Argha 🏏 📚 💻 @StringsVsAtoms
454 Followers 7K Following 🌏 वसुधैव कुटुम्बकम् - 'the world is one family' 🌍
Jeremih123123 @jeremih12311032
547 Followers 7K Following
Mike Goffin @mjxg
659 Followers 645 Following Dad | Defender Against the Digital Dark Arts™ | Technical Leader, Intelligence Operations @ Cisco | Tweets are my own. @[email protected]
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
John Hultquist @JohnHultquist
29K Followers 1K Following Chief Analyst, Google Threat Intelligence Group. @CYBERWARCON and @SLEUTHCON founder. Johns Hopkins professor. Army vet.
Florian Roth ⚡️ @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Cristin Flynn Goodwin @CristinGoodwin
7K Followers 990 Following Founder, Advanced Cyber Law & Advancing Cyber, former Assoc. GC & GM, Cybersecurity @ MSFT. I ❤️ incident response, threat intel, & skiing. @Cristin.bsky.social
Microsoft Threat Inte... @MsftSecIntel
187K Followers 1K Following We are Microsoft's global network of security experts. Follow for security research and threat intelligence.
Nick Carr @ItsReallyNick
38K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
💻 Sherrod DeGrippo... @sherrod_im
36K Followers 7K Following Weird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
SwiftOnSecurity @SwiftOnSecurity
405K Followers 9K Following computer security person. former helpdesk.
blackorbird @blackorbird
35K Followers 671 Following Peace and Love. Just Analysis/Hunter. #APT #threatIntelligence #Exploit #CTI Need Job
Kim Zetter @KimZetter
93K Followers 3K Following Journalist - cyber/national security. Author - COUNTDOWN TO ZERO DAY: Stuxnet and the Launch of the World's First Digital Weapon. https://t.co/334DzfSL1f
Joe Słowik 🌻 @jfslowik
28K Followers 1K Following CTI, OT/ICS, DE&TH, and related infosec content. Oh, and memes. And shitposting. Lots of shitposting.
Jake Williams @MalwareJake
142K Followers 2K Following Breaker of software | VP R&D @hunterstrategy | CTI/DFIR | @ians_security faculty | Bookings: jake at malwarejake dot com | GSE #150 | He/him
Mark Parsons @markpars0ns
2K Followers 829 Following Threat Analyst @ Microsoft - mostly tweet about astrophotography and occasional some work. Tweets are my own
Chris Harrod @thechrisharrod
1K Followers 172 Following Personal account — Manager of Security Operations for the United States House of Representatives
Chris Krebs @C_C_Krebs
233K Followers 3K Following
☠️🐻Andy Piazza... @klrgrz
6K Followers 3K Following Christian. Killer Grizz, Threat Intel & Thrunter. Hack things w/ @bsides_nova. @DEFCON Contests Dept Lead & Black Badge DC32. GSE #344. (VIEWS ARE MY OWN).
Chris Sanders 🔎 �... @chrissanders88
34K Followers 489 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Andy Greenberg (@agre... @a_greenberg
71K Followers 1K Following WIRED writer, author of SANDWORM and now TRACERS IN THE DARK: The Global Hunt for the Crime Lords of Cryptocurrency. Andy.01 on Signal. [email protected]
Dmitri Alperovitch @DAlperovitch
197K Followers 2K Following Geopolitics/NatSec, Russia, China, Cyber. Chairman @SilveradoPolicy; Author WorldOnTheBrink; Host @GeopolDecanted; Founder @alperovitch; Co-Founder @CrowdStrike
Charles Price @linuxisp
338 Followers 446 Following Threat Analyst @ Microsoft Threat Intelligence Center #MSTIC | previously UK Gov and Zycomm/W3Z | IPv6 nerd | Ham M0DMF | Views my own.
Sarah Kalevra @swat_cyber
829 Followers 755 Following Threat Intelligence Instructor. She/her. Using Twitter discourse to sound smart at work. #cti #infosec #cyber [email protected]
Troy Hunt @troyhunt
240K Followers 1K Following Creator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
Kaushik @kausrini
239 Followers 736 Following Reverse Engineering | Threat Intel | DFIR | Captcha verified human with own opinions (not employer's). @[email protected]
woanware @woanware
778 Followers 382 Following Principal Security Researcher @ Microsoft (MSTIC). Software development, detections, security and DFIR. Thought/opinions are mine, not those of my employer.
KC7 - Cyber detective... @KC7cyber
2K Followers 433 Following The free cyber detective game. Investigate realistic cybersecurity intrusions in data. ⚠️ addictive
Austin Baker @BakedSec
2K Followers 267 Following IR at LinkedIn | focused on the intersection of data science, engineering, and cybersecurity | Scooping up APT and bopping them on the head | opinions my own
aptwhatnow @aptwhatnow
1K Followers 639 Following
Lauren Leigh @LaurenLeigh522
281 Followers 544 Following Intelligence Analyst. (Former) dancer. Not good at tweeting but love reading and liking tweets from others! Views are mine not my employer’s.
visi stark @invisig0th
4K Followers 671 Following Founder @vtxproject Father of the #APT1 Report @mandiant / @fireeye Inventor of synapse, vivisect, UNCs, imphash, ... DEFCON CTF Champion, Founder of Kenshoto
The Vertex Project @vtxproject
3K Followers 4K Following On a mission to create an intelligence-driven future with Synapse.
Jeremy Dallman @jdallman
1K Followers 153 Following Microsoft Threat Intelligence. Mostly promoting work stuff & smart security people. Obsessed with good coffee & scotch. Opinions my own.
Vincent Tiu @vincenttiu
76 Followers 142 Following Cybersecurity @Microsoft (MSTIC) #mstic #threatintel #malware
waymon @obnoxious4n6
680 Followers 1K Following Sr. Security Research Manager @Microsoft GHOST || 👻 Threat Hunting 👻 || tryin to navigate this cyber stuff || tweets == my own
Seongsu Park @unpacker
12K Followers 1K Following Zscaler APT Research | Formerly Kaspersky GREAT | Threat Intelligence Hustler | Tweets are my own | Keybase: @seongsupark | Mastodon: @[email protected]
The Daily NK @The_Daily_NK
17K Followers 729 Following Underreported stories. Unique perspectives. From Sinuiju to Kaesong.
Scott Snyder @snydersas
10K Followers 899 Following President and CEO, Korea Economic Institute of America (KEI), a FARA registered organization funded by KIEP. All opinions are my own and RT not an endorsement.
Liberty in North Kore... @LibertyinNK
26K Followers 892 Following Join North Korean refugees, activists and advocates empowering change. Be an Ally today. https://t.co/alKU9U5SfX
Joel Wit @Joel_Wit38
2K Followers 46 Following Former State Department official. Founder, @38NorthNK, Senior Fellow @stimsoncenter
North Korea in the Wo... @NKintheWorld
2K Followers 155 Following An interactive website on North Korea's external economic and diplomatic relations, created by @NCNKorea and @EastWestCenter
Chad O'Carroll @chadocl
24K Followers 809 Following Journalist from London, based in Seoul. Founder of https://t.co/jmDY5qVkbz This is a personal account, so it’s personal views (not official company ones).
Jenny Town @j3nnyt0wn
9K Followers 2K Following Senior Fellow at @StimsonCenter; Director of Stimson Korea Program and @38NorthNK; Associate Fellow of @FPI_SAIS. Views are my own. RTs are not endorsements.
Josh Smith @joshjonsmith
25K Followers 8K Following @Reuters Korea Bureau Chief covering South & North Korea • Previously in Afghanistan • MA @warstudies • [email protected] • DM for Signal • Personal account
Maria L @MiaSLittle
223 Followers 605 Following National Security & Crime Focused; Lusophone; sometimes political; Views = mine
John Sakellariadis @johnnysaks130
3K Followers 3K Following Cybersecurity and Intelligence Reporter at @politico. Former author of the Morning Cybersecurity newsletter. Reach me at [email protected] or Signal.
Alan Suderman @AlanSuderman
6K Followers 1K Following I cover crypto for the Associated Press. To connect: [email protected] or Alan.34 on Signal.
Abir Ghattas @AbirGhattas
18K Followers 2K Following Chief Information Officer @HRW • Feminist •🥋• @[email protected] •
markus neis @markus_neis
3K Followers 1K Following Principal Threat Intelligence Researcher at Arctic Wolf Labs | Opinions are my own
Erica Peterson @ericalikestech
3K Followers 4K Following Co-Founder @cyberlawcon | J.D. Candidate @duqklinelaw
John @Big_Bad_W0lf_
2K Followers 690 Following Bad guys and Breaches with #AdvancedPractices 🦅 @Mandiant / @Google | tweets are my own
Sam Riddell @RiddellSam
816 Followers 560 Following Analyst @Mandiant and @Google. Former Georgetown SSP & Ohio State Buckeye. Troll hunter, disinfo junkie. Tweets my own. https://t.co/R377IV5fi9
Sil @kyotorocks
103 Followers 539 Following Threat Intelligence Manager / Reverse Engineer @ Microsoft Threat Intelligence Center (MSTIC). Tweets are my own.
Оlga Belogolova 🌻 @olgs7
8K Followers 2K Following Director of Emerging Tech @SAISHopkins, teach disinfo/IO. Frmr @Meta IO Policy Lead/ Journalist @atlanticmedia. RT≠endorsement. Views my own. Mostly on Threads
Cyrus @cyrusSecurity
761 Followers 1K Following Security Researcher @crowdstrike | ex @microsoft @mitrecorp | Beardown @UArizona
InfoSecProf @_John_Doyle
2K Followers 936 Following Cyber threat intelligence | Mandiant | SANS FOR578 instructor | Member of @curatedintelligence | Arcane Trickster | Ex-CIA | Posts represent my personal views
Ryan Naraine @ryanaraine
28K Followers 836 Following 🎧 Three Buddy Problem: https://t.co/ZGEyqy2h7g. ✍🏼 Writing: @securityweek 🗣️ Conference: @labscon_io
Dan Taylor @DeltaTangoTwo
881 Followers 2K Following msft's ghost team, Tiramisu expert, used to be technical, Dad x5, former Marine
Joe Hannon @JoeHannon52
519 Followers 1K Following Security researcher @ MSTIC, Microsoft https://t.co/8IO8nzNnAQ
Kelsey Britton @cyberdaddy247
37 Followers 144 Following technical cyber leader: IR, Intel, Automation, former RE ### father, husband ### faith, family, friends
Kemba Walden @KembaWalden
1K Followers 142 Following former White House; former Microsoft; former DHS; always Cyber