Ben Wilson @benhacks
InfoSec Practitioner 👨💻 | Tinkerer/Hacker 💻🛠️ | Mountain Biker 🚵 | Aussie 🇦🇺 Joined June 2019-
Tweets39
-
Followers321
-
Following326
-
Likes47
New Blog! #SUNBURST in three flowcharts: fireeye.com/blog/threat-re…
👋 Heyo first of all, I’m blue team now and officially on FLARE Advanced Practices as a senior researcher. 🦅 @AndrewOliveau & I have a new blog post out on VBA Purging w/ ⁃nerdy deets ⁃tool release & ⁃hunting tips Key takeaways below 🧵fireeye.com/blog/threat-re…
Phil Jackson on Success and Failure 🙌🏽 🗣️"You're only a success the moment you do a successful act, so these acts have to be repeated all the time"
Please welcome Lazarus's Group (N. Korea 🇰🇵) "Dacls" RAT to macOS: objective-see.com/blog/blog_0x57… 🍎👾 Credit to @philofishal for the discovery (and for sharing hashes!!) 🙌🙏
Most people reading this have tried using Google Reverse Image Search -- it's pretty easy! But that's just the tip of the iceberg. Our new guide goes into excruciating detail on various reverse image searching engines, and how to creatively use them. bellingcat.com/resources/how-…
Great find - we have been tracking as SAYCHEESE
...so, why the significant increase in #APT32 🇻🇳 attempted intrusions into the automotive sector beginning in 2019? Look at when Vietnam reaffirmed the measures amid 🚗 industry resistance: asia.nikkei.com/Economy/Vietna…👀 Plus, remember what I keep telling you: #APT32 does "audits" 🎣
WORLD EXCLUSIVE: Chinese spy spills secrets to expose Communist espionage | 60 Minutes Australia - YouTube youtube.com/watch?v=zdR-I3…
ASIO confirms in rare statement is investigating plot by Chinese espionage ring to install Bo "Nick" Zhao in federal Parliament as a Liberal MP. He was later found dead after disclosures to ASIO.
Parse Transactional Registry logs in 010 Editor using this template: gist.github.com/williballenthi… Windows Scheduled Tasks uses the Transactional Registry to record tasks, so you can feasibly recover deleted tasks. Used this to find APT28 lateral movement last week.
Does this bypass a "security boundary" ™, no. Should it be fixed, abso-f-ing-lutely. Relevant: @jepayneMSFT
Does this bypass a "security boundary" ™, no. Should it be fixed, abso-f-ing-lutely. Relevant: @jepayneMSFT
Great storytelling from @MishaGlenny, gives a good overview of the depth of his research on organised crime groups, individuals and inner workings. Well worth a listen.
Great storytelling from @MishaGlenny, gives a good overview of the depth of his research on organised crime groups, individuals and inner workings. Well worth a listen.
xmas is sorted for that special #redteam someone
Tickets are on sale: eventbrite.com.au/e/bsides-canbe…
Me dropping into InfoSec Twitter with bunch of folks I've lurked, followed and respected for years. Sup y'all.
There's a new Excel 0day which may allow for the automatic & silent execution of embedded macros on macOS 😱 New blog post: "[0day] Abusing XLM Macros in Slk Files" patreon.com/posts/31418067 👾🍎 Shoutouts to @ptrpieter/@StanHacked for initial bug discovery & their analysis 🙏🤩
"Warfare is warfare, espionage is internationally normal, and cyber is just one of a suite of potential capabilities for a military response"
"Warfare is warfare, espionage is internationally normal, and cyber is just one of a suite of potential capabilities for a military response"
Getting RCE in Office through URI handlers. @HexKitchen details the now patched bug originally submitted by the prolific rgod. bit.ly/2mRaA1m
This. For example, are you all monitoring HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PortProxy\v4tov4 ? netsh forwarding is some spicy lolbin usage.

Andrew Thompson @ImposeCost
39K Followers 1K Following Head of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer. Former @USMC.
Tyler McLellan @tylabs
3K Followers 588 Following Intrusion aficionado. @Google/@Mandiant Advanced Practices
Nick Carr @ItsReallyNick
38K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
Dan Perez @MrDanPerez
4K Followers 1K Following 🇨🇳Mission TL @Google | #Malware Naming Wizard | #Attribution Connoisseur | All tweets are my own. #ThreatIntel #APT
1aN0rmus @TekDefense
4K Followers 1K Following CTO at @permisosecurity Alum: @Mandiant, https://t.co/kqlvYwe86k, USMC
⚛️ Marcin Siedlar... @siedlmar
2K Followers 1K Following Technical attribution of cyber threats | Frontline Intrusion Intelligence 🦅 @Mandiant
Steve Stone @stonepwn3000
1K Followers 455 Following @sentinelone | Fmr. @Mandiant, @IBM, @rubrik, USG | TV/VCR repair, views are my own. Also [email protected]/stonepwn3000.bsky
Van @Wanna_VanTa
4K Followers 393 Following Research & Discovery Lead @Mandiant @googlecloud Specialties: researching adversary tradecraft, hardstuck masters TFT, and losing sneaker raffles.
Dave Kennedy @HackingDave
223K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Jared Wilson @JWilsonSecurity
2K Followers 1K Following Mandiant Research and Discovery, Father, Husband, Trail Runner, Co-Founder CyberFriendsCircle
Daniel Bohannon @danielhbohannon
18K Followers 582 Following Security Researcher @permisosecurity Previously: @Mandiant/@FireEye, @Microsoft Developer: Invoke-(Obfuscation|CradleCrafter|DOSfuscation) & Revoke-Obfuscation
Bartek Jerzman @secman_pl
2K Followers 3K Following Hunting ghosts in wires and boxes, Head of CTI, former NCSC-PL, PL Navy #fightingthreats | @PIVOT_con co-founder
Ryan Tomcik @heferyzan
1K Followers 2K Following DE/TH @GoogleCloud @Mandiant Threat Defense | Google in the streets, Mandiant in the tweets | Thruntito ergo sum | Bsky: https://t.co/THP7ny8CgD
🇨🇦PJ⌨🏋🏻... @PJ47596176
2K Followers 3K Following 🇨🇦whisky; cyber; natsec; Greater Toronto; innovation; girl dad.🌻.
Tom Hegel @TomHegel
7K Followers 750 Following Threat Research Lead @SentinelOne, Advisor with @ValidinLLC
boxMind.ai @boxmindai
535 Followers 970 Following ⚡ Unleash your business potential with the power of AI – from LLM models like ChatGPT, deep learning and beyond.
JACybersec @cybersec_ja
8 Followers 250 Following
Marie Moe @MarieGMoe
5K Followers 2K Following Cyborg - Infosec Consultant @Google/@Mandiant - Associate Professor II @NTNU - Hacking my heart: https://t.co/BeXDTcgKFS
Innzs @MFfLinnd
0 Followers 5K Following
Evan Reese @reesespcres
534 Followers 251 Following
Daniel W. Seiler @dws_ch
22K Followers 20K Following Award Winning Cybersecurity Leader - by combining cyber, law & innovation, I create sustainable foundations for secure digital futures
Jonathan Gonzalez �... @godslittlemacro
2K Followers 2K Following Incoherent rants are my own intellectual property. ex-DFIR, now CTI. It's either memes, infosec, or activism. Unfollow accordingly.
MARTINA @Investor_Martin
327 Followers 3K Following ENTREPRENEUR 🎖EXPERT TRADER 💵BITCOIN MINING 📊FOXER TRADER 🖥BINARY TRADER ACCOUNT MANGER 📞24/7 ONLINE ASSISTANT 📨DM TO START EARNING HUGE PROFIT
Cyber Security Pengui... @CySecPenguin
51 Followers 3K Following Cyber security information is collected.
Josh Hanrahan @cyberbubblez
93 Followers 650 Following Principal Adversary Hunter @Dragosinc | Husband | Father | Zelda nerd | Frequently goes on the dark web to look at pictures of skeletons
The Vertex Project @vtxproject
3K Followers 4K Following On a mission to create an intelligence-driven future with Synapse.
Scritches JRC @scritches
569 Followers 6K Following This account is run by a feral service animal. All content is personal.
muspelhiem @muspellhiem
9 Followers 353 Following Retired US Coast Guard Commander training to become a Cyber Security Professional focusing on AI and Cloud Security.
MISAC @it_misac
2K Followers 4K Following Municipal Information Systems Association of California - We're your go-to association for all California city gov techies. #govtech
🆆KP(ぴ生翁) @zer0Krieg
435 Followers 7K Following #cybersecurity, 💕sci-fi movies, #technology,#videogames🎮, techno 🎵 ,#OSINT, #AI @[email protected] | Tweets are my own.
CD-R0M @CD_R0M_
1K Followers 1K Following IR @Mandiant | Interested in #DFIR and #ThreatIntel | Tweets attributable to me and not my employer
R̶a̶v̶i̶d̶ Ravee... @raveedl
201 Followers 1K Following product, threat intelligence person • opinions are presumably my own but actually just part of the collective unconscious • need to shitpost more
cryptopotato @cryptoishard
8K Followers 9K Following OSINT⁃Android⁃Hardware⁃Cryptography⁃Forensics⁃Virtualization⁃GameDev #w00w00 cryptographyishard(@)https://t.co/Jwv7la6YPg ∧·∪
Dan Satinoff @dansatinoff
874 Followers 4K Following Husband, dog dad, Tampa Bay Rays fan, Lives in Tampa & ❤️’s OT Alexandria, 2X NFFC NYC Super Winner, Fantasy Sports, East Channel Director at Varonis
1t 1s N0b0dyh 🏴... @1t1sNobody
490 Followers 3K Following Sometimes I tweet something! Fighting and studying #malware in the other time
The Reverend JP @justjptweet
833 Followers 2K Following Florida Man Yelling About Cyber Security, Beer, Boats, and Dogs.
G M @followeragent99
78 Followers 2K Following Security enthusiast. Incident analysis. Web App Pentest. Researcher. Student. Educator. Follower of good things.
Gökmen GÜREŞÇİ @gokmenguresci
3K Followers 5K Following Founder & CEO @kleariscdr • Founder & CEO @DeepcaseCyber
derrick' or '1'='1 @dzaSec
111 Followers 950 Following
gotestgo @zjkqwe
0 Followers 106 Following
Trevor @blueteamtrevor
378 Followers 1K Following CISO, Blue Team, Security, Privacy, Compliance, former Paramedic, Almost RN, Dog Dad, BBQ, Lacrosse Dad, Good Coffee (He/Him). 🚑🏍🛩🦮☕️
Sabi @sabi_elezi
184 Followers 1K Following
Lisa Rainbolt Maher @LisaRMaher
742 Followers 5K Following Collector of old phones, old wine, and new technology.
Noah🧑💻 @NoahCyber
3K Followers 5K Following 🧑💻Cybersecurity Expert + Entrepreneur | ✍️ Breaking down complex security knowledge into easy-to-understand hacks, making cybersecurity accessible to all 🚀
gr0ked @gr0ked
65 Followers 442 Following "Access to computers -- and anything that might teach you something about the way the world works -- should be unlimited and total."
Chad Reams @chadmreams
15 Followers 940 Following
alex lanstein @alex_lanstein
3K Followers 3K Following threaty threats @ StrikeReady -- helping build research workflows into the product. pretty good at bash scripts and strings. disclosures on my linkedin below
elkcloner @vijilantist
65 Followers 5K Following reverse ̷e̷n̷g̷i̷n̷e̷e̷r̷ psychologist, invasion architect; black mirror s3/e3. {mīles, soldat, 군인, חייל}
ff1343ff @ff1343ff
409 Followers 1K Following
Patrick @patrickst_john
42 Followers 1K Following
Hexnov @hexnov
122 Followers 935 Following Interested in offensive security and heavy music 💻🎶 purple teaming & adversary simulation 💜⚔️
This Phone @ShrigleyDimond
982 Followers 4K Following
43 56 @THIR_Sec
423 Followers 760 Following 🏹 @SentinelOne | @SANS_EDU #MSISE Alum | Former @TheDFIRReport Contributor. Expressed opinions are my own.
Andrew Thompson @ImposeCost
39K Followers 1K Following Head of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer. Former @USMC.
Florian Roth ⚡️ @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Steve YARA Synapse Mi... @stvemillertime
17K Followers 1K Following threat intelligence @google writing & sharing on adversary tradecraft, malware, threat detection, AI-nexus intel and all things #yara
Nick Carr @ItsReallyNick
38K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
Dan Perez @MrDanPerez
4K Followers 1K Following 🇨🇳Mission TL @Google | #Malware Naming Wizard | #Attribution Connoisseur | All tweets are my own. #ThreatIntel #APT
1aN0rmus @TekDefense
4K Followers 1K Following CTO at @permisosecurity Alum: @Mandiant, https://t.co/kqlvYwe86k, USMC
⚛️ Marcin Siedlar... @siedlmar
2K Followers 1K Following Technical attribution of cyber threats | Frontline Intrusion Intelligence 🦅 @Mandiant
Shane Huntley @ShaneHuntley
17K Followers 1K Following Security / tech guy. Google Threat Intelligence Group but tweets are my own.
Aaron Stephens @x04steve
3K Followers 524 Following
Steve Stone @stonepwn3000
1K Followers 455 Following @sentinelone | Fmr. @Mandiant, @IBM, @rubrik, USG | TV/VCR repair, views are my own. Also [email protected]/stonepwn3000.bsky
SwiftOnSecurity @SwiftOnSecurity
405K Followers 9K Following computer security person. former helpdesk.
Van @Wanna_VanTa
4K Followers 393 Following Research & Discovery Lead @Mandiant @googlecloud Specialties: researching adversary tradecraft, hardstuck masters TFT, and losing sneaker raffles.
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Dave Kennedy @HackingDave
223K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Greg Linares (Laughin... @Laughing_Mantis
37K Followers 2K Following 20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.
Daniel Bohannon @danielhbohannon
18K Followers 582 Following Security Researcher @permisosecurity Previously: @Mandiant/@FireEye, @Microsoft Developer: Invoke-(Obfuscation|CradleCrafter|DOSfuscation) & Revoke-Obfuscation
Bartek Jerzman @secman_pl
2K Followers 3K Following Hunting ghosts in wires and boxes, Head of CTI, former NCSC-PL, PL Navy #fightingthreats | @PIVOT_con co-founder
Chris Bing @Bing_Chris
34K Followers 10K Following @propublica reporter: national security and technology. 📧: [email protected] / 📞(Signal): 771-217-8550. More contact info: https://t.co/FnTdrahhi0
x0rz @x0rz
96K Followers 420 Following Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓
Joseph Cox @josephfcox
93K Followers 3K Following Hacking/crime/privacy journalist. Author of DARK WIRE. Co-founder of @404mediaco. Signal: joseph.404 Email: [email protected]
dozer @dozernz
974 Followers 498 Following 🇳🇿 hacker / "security researcher" / pentester / redteam / bug bounty. tweets are individual capacity
Timo Steffens @Timo_Steffens
4K Followers 57 Following Works at a German agency on cyber-espionage. Author of 'Attribution of Advanced Persistent Threats' (Springer, 2020). Tweets are personal opinions.
NSA Cyber @NSACyber
149K Followers 12 Following We protect our nation’s most sensitive systems against cyber threats. Likes, retweets, and follows ≠ endorsement.
MU-TH-UR 6000 @iAmThePr0blem
314 Followers 593 Following Video game player and reverse engineer for Mandiant/FLARE.
Steve Eckels @stevemk14ebr
2K Followers 319 Following Creator. Hacker. Reverse engineer on Google Mandiant FLARE. Opinions mine not employers.
Moritz @m_r_tz
1K Followers 388 Following
@AlSweigart@mastodon.... @AlSweigart
27K Followers 1K Following Author of "Automate the Boring Stuff with Python" and other programming books. This account is just promo stuff now, follow me on Mastodon. he/him
Liam Cochrane @Liam_Cochrane
9K Followers 1K Following Author of ‘The Cave’. Former Southeast Asia & PNG correspondent for the ABC. Lecturer at Melbourne University.
Marta Gómez @Mrs_DarkDonado
2K Followers 997 Following SWE @virustotal. Mom of two black cats. Hobbyist portrait photographer. Inline skater (mostly focused on freestyle slalom). Opinions are my own.
Alyssa (she/her) @ramen0x3f
3K Followers 574 Following @ramen0x3f.bsky.social Senior Threat Researcher and Pun Aficionado @Microsoft Former research+red team+hand drawn memes @Mandiant
Tom Hegel @TomHegel
7K Followers 750 Following Threat Research Lead @SentinelOne, Advisor with @ValidinLLC
780th Military Intell... @780thC
34K Followers 567 Following Official Twitter page of the 780th MI Brigade (Cyber). The Army's only offensive cyberspace operations brigade (following, retweets and links ≠ endorsement).
CAPE Sandbox @CapeSandbox
4K Followers 114 Following Payloads or it didn't happen. https://t.co/rAVsWT6dcl
Kevin Perlow @KevinPerlow
1K Followers 20 Following RE and CTI. Feel free to take a gander at my past presentations: https://t.co/iWUyecnxC6
@Rmy @Rmy_Reserve
2K Followers 892 Following Analyze #Malware| A Future Reverse Engineer | Threat intelligence hunter| #APT hunter| #redteamer or #blueteamer |hobby:animation
ByrneG @ByrneGh
159 Followers 143 Following Security geek, climber, sailor. Partial to good coffee and good wine.
Tom Hall @thall_sec
469 Followers 263 Following Director, Cyber Incident Response and Remediation @PwC_UK. Ex Mandiant. All thoughts are my own.
bk (Ben Koehl) @bkMSFT
3K Followers 770 Following Partner Director of Threat Intelligence at @Microsoft Threat Intelligence Center (MSTIC).
Ramin Nafisi @MalwareRE
5K Followers 2K Following Director of MSTIC Malware Intelligence, Research, and Analysis (MSTIC-MIRAGE) team.
Peter Mattis @PLMattis
10K Followers 749 Following President @JamestownTweets Ex-@CECCgov @ChinaBriefJT . Co-author - Chinese Communist Espionage: An Intelligence Primer: https://t.co/6yF3iMr0KF. Views still mine
Jack Rhysider 🏴... @JackRhysider
164K Followers 4K Following Creator of @DarknetDiaries. Tell me a good hacker story. 💻🔦⤵️🐰🕳️ Discord: https://t.co/qxanMuJ5X2
Mitch Clarke @snozberries_au
368 Followers 303 Following Mandiant incident response lead, United Kingdom and Ireland
Alex Joske @alexjoske
20K Followers 2K Following 周安瀾 Analysing the CCP's external influence and technology acquisition efforts. Author of Spies and Lies (Hardie Grant Books 2022)
Megantron (@megan@inf... @megan_roddie
6K Followers 4K Following Detection Engineer. Co-Author, SANS FOR509. Author, Practical Detection Engineering. @HackersHealth CFO. Ammy Muay Thai fighter/coach. #ActuallyAutistic.
𝐂𝐮𝐫𝐭𝐢�... @CurtBraz
2K Followers 879 Following Cybersecurity researcher/blogger/pentester. Try to tweet only technical/educational but occasionally post about https://t.co/MTZoEINlWg 🙂
dark.fail @DarkDotFail
32K Followers 645 Following Anonymous journalist researching Tor: the uncensored internet. Privacy is a human right. https://t.co/Rg8N70f37d
Philip Martin @SecurityGuyPhil
6K Followers 334 Following CSO @ Coinbase. Army Veteran. Maker of delicious smoked meats and baked goods.
Bishop Fox @bishopfox
26K Followers 4K Following A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking VC @forgepointcap @carrickcapital @WestCap8
Mr.Un1k0d3r @MrUn1k0d3r
13K Followers 508 Following I don't know how to search on Google so I do research on my own and tweet about it. Hacking as a life style https://t.co/a05mevChzu
IssueMakersLab @issuemakerslab
5K Followers 6K Following We are the IssueMakersLab / We operate as a non-profit intelligence organization just for fun / Researching North Korea's cyber warfare capabilities since 2008
Miguel Ángel Corral @CorralPeltzer
126 Followers 480 Following SRE @OptiverGlobal, previously @Mandiant
Nicole O @wattsopp
30 Followers 29 Following
John Allison @proud2bgeeky
134 Followers 187 Following Cybersecurity geek, that sums me up fairly well.
Pieter Ceelen @ptrpieter
2K Followers 146 Following Red teamer @ Outflank, product owner Cobalt Strike/Outflank Security Tooling
Markus Wulftange @mwulftange
3K Followers 195 Following Principal Security Researcher and Pâtissier at @codewhitesec