Interesting #LOTS (Living Off Trusted Sites) that seems perfect for threat actors bashupload.com: "Files are stored for 3 days and can be downloaded only once." - add that one to your threat hunting leads
#python#pandas tip: you can pass a dict to the pandas .astype() method to easily retype a whole df at one go, e.g.:
convert_dict = {'col1': float, 'col2': object}
df = df.astype(convert_dict)
OneDrive URLs have cid values unique to each user cs.cornell.edu/~shmat/shmat_u…; this can be useful for #threathunting purposes, as some adversaries reuse the same cid across multiple campaigns.
Not all @censysio HTTP header fields are indexed, so if you try to search for these field names, you will get an error. However, you can still search the values using services.http.response.headers.unknown.value. This usually works.
Here is a @PassiveTotal python CLI client (passivetotal.readthedocs.io/en/latest/gett…) jq one-liner for “just give me all the resolutions”
pt-client pdns --query YOUR_DOMAIN_OR_IP_HERE | jq -r '.results[] | select(.recordType == "A") | {resolve} | join("")'
#dailyyara tip I got from @larsborn - if your YARA rule is not for binaries (e.g. if it is for scripts), add a printability check under the condition, e.g.: and for all i in (1..100) : (uint8(i) != 0x0)
thank you #Inter#skimmer operator for your convenient domain naming: interclub[.]website - shares WHOIS gordonlaver9@gmail[.]com with brilliantclub[.]website
I don't do this often but these are special times: we're looking for several people to join our team at CrowdStrike Intelligence, reach out if you enjoy a good challenge!
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
38K Followers 5K FollowingDFIR | Violinist |
Former medical/vet tech | I work for everyone and no one. Infosec retellings obfuscated. Salty and tired.
Also Litmoose on BlueSky
482 Followers 5K Following‘If the treasures of Persia and Rome were opened for you, what kind of people will you be? Perhaps you will be something else.’
17 Followers 126 FollowingI am a former TV lover who has now progressed into the digital world as a digital project manager at Digital Project Masters.
73 Followers 2K FollowingStay safe from cyber threats with our cybersecurity blog. Get the latest updates on data protection, online privacy, and digital security.
247 Followers 709 FollowingSecurity Analyst | Blue Team | Windows Engineer | Father | Lover of coffee and whiskey | Wishing we wouldn’t be a$$holes to one another | Opinions are my own
53 Followers 834 FollowingProfessor David Lariviere is a Clinical Professor at the University of Illinois at Urbana-Champaign focused on high frequency and algo trading.
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
36K Followers 7K FollowingWeird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
38K Followers 5K FollowingDFIR | Violinist |
Former medical/vet tech | I work for everyone and no one. Infosec retellings obfuscated. Salty and tired.
Also Litmoose on BlueSky
10K Followers 1K FollowingCensys is the source for real-time Internet intelligence and actionable threat insights for governments, F500 companies, and leading threat intel providers
4K Followers 5 FollowingProviding freemium #ThreatHunting capabilities in order to surface threats faster and reduce risk. Built on top of @RiskIQ massive data collection.
38K Followers 3K FollowingTech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
5K Followers 312 FollowingThreat intel researcher focused on infrastructure hunting. Views are my own and not my employer's. Others: @[email protected] @kyleehmke.bsky.social
205 Followers 609 FollowingDid a Cybersecurity Bachelor and Master in Computer Science with a focus on Security.
Deputy Manager - Cloud Threat Intelligence
Opinion/Thoughts are my own.
3K Followers 469 FollowingDefend Tomorrow, Secure Today!
Official Computer Emergency Response Team (CERT) for the Democratic People's Republic of Korea
#NorthSide #NorthKoreaBestKorea
4K Followers 5K FollowingСлава Україні! Most important job: being Dad; I also love to help people deny attackers the opportunity to break and steal all the things. Pronouns: He/him
47K Followers 2K FollowingChief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.