Application allowlisting is the future for all security consciousness organizations that have any significant resources.
It's just a matter of how and when any particular org will adopt it.
Here's the reality:
We need to shift focus away from relying on detection + response to catch and stop ransomware/extortion actors and toward preventative/blocking means.
There simply is no viable alternative if we're going to make substantial progress at societal level here.
Here's the reality:
We need to shift focus away from relying on detection + response to catch and stop ransomware/extortion actors and toward preventative/blocking means.
There simply is no viable alternative if we're going to make substantial progress at societal level here.
The “Allowlist Auditor” from @AirlockDigital is great to highlight the current state of allowlisting on endpoints. Includes tests for execution (exe, dll, PS1, CPL and others) in common locations, and an audit for existing allowlisting solutions. airlockdigital.com/application-wh…
Feels too soon to be getting back on the plane after BH/DC, but looking forward to @CrowdStrike fal.con23 next week. Swing past our booth and say Hi :)
Feels too soon to be getting back on the plane after BH/DC, but looking forward to @CrowdStrike fal.con23 next week. Swing past our booth and say Hi :)
Discussed attackers' temptation to use custom code, lateral movement and living off the land in an allowlisting context with Patrick and @c0tts on this weeks @riskybusiness podcast. overcast.fm/+It0j4EJEU
Recent recorded AusCERT presentation by @c0tts on *Practical Allowlisting* (aka appcontrol/whitelisting). Includes objectives, maturity, challenges, trust decisions and key requirements including Q&A. Vendor independent - I promise: youtube.com/watch?v=lsl0vf…
so, help by strong email filtering (main gateway). and then add in DNS and web filtering.
and if you are serious... app control (free, like applocker, or fast and featureful like airlock digital)
AC-HUNTER to pickup the beaconing when all else fails
so, help by strong email filtering (main gateway). and then add in DNS and web filtering.
and if you are serious... app control (free, like applocker, or fast and featureful like airlock digital)
AC-HUNTER to pickup the beaconing when all else fails
14K Followers 2K Followingsecurity! personal account. views are that of rustic australian countryside. nothing is an endorsement. why do you hate fun? for educational purposes only.
7K Followers 777 FollowingFormer attorney, current IT & infosec consultant in the 'Burgh. Happy to talk about password spraying one minute and constitutional law the next. Son of #wvu.
6K Followers 5K FollowingCybersecurity Recruiter @ CyberSec People. Organizing Career Villages and Speaker @ Black Hat USA, Asia, BSides LV, BSides Canberra, BSides Melbourne
227 Followers 475 FollowingDirector, Digital Technology Services @ Western Health and Adjunct Professor @ Victoria University. Customer Advisor Cloudflare and Island. Opinions are my own
760 Followers 2K Followingtwitter bios follow a strange and distinctive formula. I'm not doing that, sorry.
I tweet about computer and law things, with an Aussie flavour.
17K Followers 1K FollowingLoves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🦋@nathanmcnulty.com
1K Followers 5K FollowingProtecting Galileo at @esa | Ground segment cybersecurity | All your ground stations are belong to us | Previously @SafranElecDef & @ANSSI_FR
391 Followers 1K FollowingFully vaxxed, but still wearing a mask. Have you booped a computer today? Also found at https://t.co/HAB3hwzkgo and https://t.co/aKo1IcOA4S He/Him
307 Followers 5K FollowingBillionaire bros,
Anti - { Liberal, Feminist, Colonist, Communist, Sugardaddy, Protagonist, Capitalist, Socialist} Group of 34 guys using same acc😂bonito sor
14K Followers 2K Followingsecurity! personal account. views are that of rustic australian countryside. nothing is an endorsement. why do you hate fun? for educational purposes only.
41K Followers 9K FollowingInformation security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast https://t.co/VpKtfz8nXG
333K Followers 2K FollowingIndependent investigative journalist. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter. Mastodon: https://t.co/fTKNavlMwp
7K Followers 777 FollowingFormer attorney, current IT & infosec consultant in the 'Burgh. Happy to talk about password spraying one minute and constitutional law the next. Son of #wvu.
9K Followers 2K FollowingThreat Researcher | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer | I'm Everywhere and Nowhere - BSG.
17K Followers 1K FollowingLoves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🦋@nathanmcnulty.com
98 Followers 180 FollowingGAICD, FGIA, BA LLB, MBA(T), CRISC, CISM, P3O. 🇦🇺 Ultra-Trail runner, head of data science. National Donkey Kong champion 1984.
262 Followers 167 FollowingI help organisations make complex decisions, get stakeholders on board & build decision capability. Director at Catalyze | Founder of WiSDM
10K Followers 891 FollowingTrustworthy 🔑 transport 🚆 for Chrome. HTTPS, certs, encryption, security UX, software eng & mgmt. @estark.bsky.social. Opinions are my own. she/her
819 Followers 320 FollowingCanberra Cyber Security Innovation Node - a partnership between @AustCyber and @actgovernment to grow the cyber security sector
14K Followers 3K FollowingThycotic is now Delinea, a leading provider of privileged access management (PAM) solutions for seamless security. Visit https://t.co/Junk2kV5U2
12K Followers 649 FollowingKilling bug classes and breaking exploits as part of @msftsecresponse. Adding more entropy to the Internet. https://t.co/J8GCGurGP3
89K Followers 910 FollowingProgrammer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
80 Followers 366 FollowingIT Security - Incident Response Investigator, Malware Analysis and Computer Forensics | Values ethics, social justice and the common good