The Cyber Intelligence and Policy Project is dedicated to examining global cyber conflict through the lens of threat intelligence and legal/policy analysisci-project.orgJoined February 2017
[UPDATE] We added improved detection and extraction of OLE Compound File (e.g. MSI) overlays and certificate information. Here's a recent sample as showcased in @virustotal @markrussinovich security vuln disclosure: hybrid-analysis.com/sample/dd71284…
Why #WeNeedWHOIS 1:
We use WHOIS data to discover targeted phishing set up by threat actors. Example:
Iranian threat group Charming Kitten used [email protected] as registrant of 12 domains used for phishing against human rights activists.¹
¹clearskysec.com/charmingkitten/
Here the full analysis of the #MuddyWater attack.
Contains heavy anti-evasion features, also requires OS reboot.
app.any.run/tasks/7a64da98…
Source: https://t.co/JkRQ3Nuy7I
At Cyber Command, they are angry & ready, moving from the Billy Mitchell phase of development, to the Curtis Lemay. Getting in close to grapple w/ adversary cyber forces is almost certainly the right move, but incredibly risky...
At Cyber Command, they are angry & ready, moving from the Billy Mitchell phase of development, to the Curtis Lemay. Getting in close to grapple w/ adversary cyber forces is almost certainly the right move, but incredibly risky...
If it’s Sandworm, as suggested here, they were swinging for the fences just as they were being publicly blamed for the most economically damaging cyberattack in history. washingtonpost.com/world/national…
30K Followers 192 FollowingEmpowering businesses with proactive security solutions: Interactive Sandbox,
TI Lookup and Feeds. Sign up for free: https://t.co/8hIX0Qh5ME
848 Followers 723 FollowingRizz Incarnate |People dislike getting more of the same..they like new stuff even less. | PGP: 0xC3DE0C0116E3363A | @CheckMyDump & Co-Founder of RHMP
3K Followers 787 FollowingWorld of Haiku x Haiku Pro 💻 🦠
The Haiku Inc Product Suite makes games that train so you can level up your cybersecurity skills.
11K Followers 2K FollowingPhished White House and lots of Banks / Social Engineer #cybersecurity #socialengineering #securityawareness #actuallyautistic #speaker
3 Followers 405 FollowingEmployee at Sophos. Not planning on expressing any opinions here but if I do, they are my own and do not reflect those of my employer.
38K Followers 3K FollowingTech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
30K Followers 192 FollowingEmpowering businesses with proactive security solutions: Interactive Sandbox,
TI Lookup and Feeds. Sign up for free: https://t.co/8hIX0Qh5ME
63K Followers 82 FollowingThe latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
70K Followers 80 FollowingThis is Cyber National Mission Force’s alert mechanism to contribute to our shared global cybersecurity (Following, retweets and links do not equal endorsement)
13K Followers 2K FollowingHead of Threat Research at @RiskIQ. Trying to solve every puzzle I run into. Opinions expressed here are my own.
(Formerly Sr. Threat Researcher @foxit)
6K Followers 197 FollowingThe Twitter account for Intelligence & National Security (a Routledge journal). Managed by Social Media Editor David Strachan-Morris
66K Followers 5K FollowingWe defend and extend the digital rights of people and communities at risk 🌎 RightsCon: @rightscon Latin America: @accessnow_latam
39K Followers 1K FollowingHead of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer.
Former @USMC.
9K Followers 647 FollowingA leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime since 2003
1K Followers 741 FollowingAstrophycist turned Director of Threat Intelligence @ReversingLabs. Formerly @cisco SecureX, @ZeroFOX, @TalosSecurity
Opinions are my own.
16K Followers 274 FollowingExecutive Director for Intelligence and Research @SentinelOne | Distinguished Fellow, @SAISHopkins Alperovitch |LABScon|Cyber Paleontologist|4thParty Collector
3K Followers 5K FollowingCHA is my family name. Senior Principal Threat Intelligence Researcher at AhnLab / Keybase : mstoned7 , Signal : mstoned7.21 / Tweets are my own.
309K Followers 99 FollowingOfficial communications from CISA on X will always originate from this account. No other accounts are authorized to convey info from CISA or senior CISA staff.