DFIR | Automator of things | APT Hunter | Malware Reverser | SANS Instructor Candidate | Views expressed here are my ownmikecybersec.medium.com DigitalOceanJoined July 2023
If you're not getting the answers you're looking for, change the questions you're asking...
"Is PingCastle detected?" is the wrong question...
"Is Active Directory enumeration detected?" is better...
"Is high volume enumeration of the Domain Administrators group from a…
Good advice but to add context... Legitimate apps and tools use Axios, we're seeing commercial/sales teams who use PipeDrive will also produce Axios UAs in AAD Audit.
Be careful before locking out your clients sales directors 👀
Good advice but to add context... Legitimate apps and tools use Axios, we're seeing commercial/sales teams who use PipeDrive will also produce Axios UAs in AAD Audit.
Be careful before locking out your clients sales directors 👀
As I've aged into offensive work, the value of certs has diminished for me compared to a solid methodology
Delivering a quality assessment is so different from cert material. Maybe there's room for a course that guides you through an assessment start to finish? (Reporting too?)
Logging into Xitter and seeing thousands upon thousands of people, who have never written a single line of code their entire life and can barely use a computer, giving their expert input into kernel-mode programming
One for the SOC/MDR peeps. When you detect a burst of activity in a customer environment and reach a verdict that it's benign, but the detections were accurate.
Do you still notify your customers?
41K Followers 9K FollowingInformation security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast https://t.co/VpKtfz8nXG
688 Followers 659 FollowingDad ⚭ Husband
𒉭 Azure Security | DE&TH | IAM
🏕️🥾 Catch me outside
🏋️♂️CultoftheIron
What stands in the way, becomes the way
618 Followers 661 FollowingOffensive Security R&D, Pen Tester.
On my continuing mission to replace myself with a small script. He/Him
https://t.co/eJUGYPAbMs
3K Followers 114 FollowingI provide guidance to students and professionals looking to become amazing SOC analysts. Don't know where to start? DM for 1-on-1! I am always happy to help.
602 Followers 0 FollowingYARA-first adversary infrastructure discovery at internet scale. Uncover residential proxies, VPNs, malware C2s, and more with 500+ baked-in rules.
48K Followers 2K FollowingThe official Twitter account of the Microsoft Most Valued Professional (MVP) and Regional Director (RD) Programs. Follow for news, updates, and much more.
688 Followers 659 FollowingDad ⚭ Husband
𒉭 Azure Security | DE&TH | IAM
🏕️🥾 Catch me outside
🏋️♂️CultoftheIron
What stands in the way, becomes the way
30K Followers 192 FollowingEmpowering businesses with proactive security solutions: Interactive Sandbox,
TI Lookup and Feeds. Sign up for free: https://t.co/8hIX0Qh5ME
2K Followers 21 FollowingSublime Security is the adaptive, AI-powered cloud email security platform that combines best-in-class effectiveness with unprecedented visibility and control.
8K Followers 1K FollowingChristian Family Man, CEO of Patriot Consulting (Microsoft Security Partner) Author of "Securing Microsoft 365" Microsoft MVP (Security) (2020-present)
68K Followers 586 FollowingHigh Queen of the Cybers | Educator | Content Creator | UwU-Anointed Wapp King | Ex-Brit | https://t.co/04RRExvxXj (he/him) 🇺🇸 I run gameshows at DEF CON.
29K Followers 4K FollowingHi I'm Stu from '42 | ❤️OSINT |✍️ CTI & Analytics book ~2025, Tracelabs Black badge x3 | Ex- @themanyhatsclub | #cyber Views my own not employers
6K Followers 379 FollowingSimplify and clarify • Cybersecurity architecture and strategy • Business + Security Alignment • Make the world better
@markasimos.bsky.social
164 Followers 98 FollowingManaging Director at @fyfeweb - a UK based data centre, server & web hosting infrastructure service provider. Based in North East England. Views are my own.
3K Followers 917 Followinghttps://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
618 Followers 661 FollowingOffensive Security R&D, Pen Tester.
On my continuing mission to replace myself with a small script. He/Him
https://t.co/eJUGYPAbMs
935 Followers 732 FollowingOSCP, CRTO, GCPN, GWAPT, MS in InfoSec. Fortunate pen tester... just learning all the things! And the obligatory: my views don’t equal my employer’s...
167K Followers 2K FollowingNational Crime Agency. Protecting the public from serious and organised crime. Don't report crime on X. Please call 101. In emergencies always call 999
No recent Favorites. New Favorites will appear here.