Chief DIFR at @SoteriaSec_io | @SANSInstitute Principal Instructor & Author | Digital Forensics & Incident Response geekjoshlemon.com.au AustraliaJoined September 2009
It's time to update your detections if you haven't been looking for WebShells on your #SharePoint server.
🕵 Make sure you're detecting w3wp.exe > cmd.exe > PowerShell.exe
Although really, cmd.exe being spawned by your SharePoint server really needs a thorough review.
Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. These vulnerabilities apply to on-premises SharePoint Servers only. Customers should apply these updates immediately to…
Here's an update on the data breach of court documents from the NSW JusticeLink website.
tl;dr - it was an individual that was able to download +9k documents over two months, it doesn't appear they were leaked anywhere publicly.
theguardian.com/australia-news…
If you're running #Erlang systems with SSH it's time to start #ThreatHunting and assume breach. The #PoC for this exploit is simple to use and already in the wild.
If you're running #Erlang systems with SSH it's time to start #ThreatHunting and assume breach. The #PoC for this exploit is simple to use and already in the wild.
109K Followers 98 FollowingThe world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
39K Followers 1K FollowingHead of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer.
Former @USMC.
22K Followers 600 FollowingDigital forensics and incident response. Ex-AFOSI, Mandiant, and CrowdStrike. SANS Institute Fellow and co-author of #FOR500 and #FOR508 courses.
9K Followers 3K FollowingThis Week in 4n6 // ThinkDFIR // SANS // CyberCX (DFIR)
https://t.co/vLyL2sxTuy
I might not know much, but I do know how to Google
Tweets are mine
85 Followers 92 FollowingthreatYeti is a domain/IP research platform from https://t.co/33uEZWna3F that helps researchers investigate potentially malicious sites faster and more confidently.
518 Followers 1K FollowingThe creator the richest plan, the creator of an oversight that BROUGHT a plan to light 🚨🕯️ this plan is a master key to all the humans in the land.. free use
109K Followers 98 FollowingThe world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
30K Followers 568 FollowingConsultant for InfoSec Innovations | @SANSInstitute Principal Instructor | @IANS_Security Faculty | I like information security. How about you?
240K Followers 1K FollowingCreator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
167K Followers 2K FollowingNational Crime Agency. Protecting the public from serious and organised crime. Don't report crime on X. Please call 101. In emergencies always call 999
5K Followers 95 FollowingChatGPT says I'm a cyber researcher :) | donate 💸 to g0njxa.eth 💖 | Bad student, enthusiast, defo not an expert
DMs are open, feel free to reach!
😼☂️🟣
48K Followers 452 FollowingSecurity researcher with a focus on hardware & firmware. I occasionally publish stuff on YouTube. Co-founder of @hextreeio. Contact: [email protected]
14K Followers 1K FollowingTeam @hashcat! Eternal n00b and knowledge seeker! Age is just a number and motivation is the fuel!
Whatever you do in your life, do not forget to be humble.
4K Followers 57 FollowingWorks at a German agency on cyber-espionage.
Author of 'Attribution of Advanced Persistent Threats' (Springer, 2020).
Tweets are personal opinions.
5K Followers 338 FollowingHacker, Forensicator & OSINT practitioner. SANS Author and Senior Instructor, Blackhat speaker & OSCP holder. Featured in Wired and Founder at @ArgeliusLabs
125K Followers 0 FollowingWe fight for you and everyday Americans for an accountable government that serves your interests.
We do it because It's Your Government.
530 Followers 335 Following#DFIR Researcher/Examiner/Blogger | https://t.co/cUOKOIb0lE | Opinions expressed are my own | One thing I know for sure, that I do not know anything (Socrates)
129K Followers 60 FollowingProviding Cyber Threat Intelligence from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threat Alerts & more. https://t.co/Fi7VW9lg94
7K Followers 958 FollowingReverse Engineering, IR, InfoSec. Also huge RPG guy. Elder of the Internet. Tweets and opinions are my own and not the views of my employer.
7K Followers 1K FollowingThe Tech Transparency Project (TTP) is a research initiative of @Accountable_Org that seeks to hold large technology companies accountable.
729 Followers 2K FollowingSANS Principal Instructor. IT Security practitioner. GSE 209. Gamer and runner in my abundant spare time. Likely being sarcastic. FMaaS. He/Him
791 Followers 1 FollowingI am the evil bot capturing your MFA tokens.
Offensive security reverse-proxy phishing framework capable of bypassing MFA protections, created by @mrgretzky
10K Followers 2K FollowingFollow me for Elixir stuff ⬩ Director of AI @galileomedical prev @stitchfix_algo @uwaterloo instructor_ex ⬩ https://t.co/lQneGN7LAy ⬩ https://t.co/qziuESZ7hd
1.1M Followers 865 FollowingPAI enjoyer, OSINT guy @hntrbrkmedia, my views/freezing cold takes are my own. For full disclosures, visit https://t.co/JOtQx4pI3e.
54K Followers 3K FollowingEvery day I write about #osint (Open Source Intelligence) tools and techniques. Also little bit about forensics and cybersecurity in general. Work in @netlas_io
4K Followers 3 FollowingHudson Rock is an Infostealer data intelligence company that helps protect against ransomware attacks, corporate espionage and network over-takes.
44K Followers 2K FollowingHelping Secure the Internet | Long Island elder emo surviving in ATX | Expect: infosec current events, DFIR, appsec & cloudsec - and me!
No recent Favorites. New Favorites will appear here.