Alyssa (she/her) @ramen0x3f
@ramen0x3f.bsky.social Senior Threat Researcher and Pun Aficionado @Microsoft Former research+red team+hand drawn memes @Mandiant linktr.ee/alyssarahman Joined February 2017-
Tweets359
-
Followers3K
-
Following574
-
Likes2K
A threat group tracked by Microsoft as DEV-0196 is linked to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infra. Read our analysis in collaboration with @citizenlab: msft.it/6010gy5fA
If anyone is considering taking the CySA+, CompTIA is doing an open beta for the new version and it’s only $50
Not sure how I missed this one but PSA for red team friends 🚨update Cobalt Strike if you haven’t
Congrats to my Mandi....uh Google friends! Excited to see what y'all accomplish with that Google ☁️ scale! 🥳
Congrats to my Mandi....uh Google friends! Excited to see what y'all accomplish with that Google ☁️ scale! 🥳 https://t.co/ZmbEvU8UvJ
Microsoft has discovered a post-compromise capability we’re calling MagicWeb, which the threat actor tracked as NOBELIUM is using to maintain persistent access to environments they have compromised. In-depth technical analysis and hunting guidance here: msft.it/6016jeB4i
This looks handy! Started using Jupyter notebooks for research/analysis in the past year and it’s *the best*
This looks handy! Started using Jupyter notebooks for research/analysis in the past year and it’s *the best*
#MSTIC 🛡️ & #DART 👻 are now hiring Hunt Analysts who live at the intersection of incident response and threat intelligence. Have experience in both areas? Come join us! Hunt Analyst 🕵️: careers.microsoft.com/us/en/job/1446… careers.microsoft.com/us/en/job/1439…
This is an awesome blog on attacker VPN usage! 🤩 Come for the walkthrough of @JWilsonSecurity’s fun research and stay for the fantastic list of hunting examples/rules that will get your creative juices flowing 👏🏽
This is an awesome blog on attacker VPN usage! 🤩 Come for the walkthrough of @JWilsonSecurity’s fun research and stay for the fantastic list of hunting examples/rules that will get your creative juices flowing 👏🏽 https://t.co/T8BZM4Q5Uh
🎉 SUPER EXCITED to announce I'll be presenting at DEFCON this year! forum.defcon.org/node/242292
One of my favorite malware analysis utilities just got a big update!
One of my favorite malware analysis utilities just got a big update! https://t.co/HGBGFHopf3
Just received my flag* as well for my time at @Mandiant! It was a big deal for me to hit the 5 year mark in my career while doing cool research with AP ❤️🦅 Stoked I have a memento *majestic cat not included
I am preparing for an internal talk on career advice learned from working security crises. My notes 🧵
🔥I'm looking for a manager for the @Mandiant #AdvancedPractices Research team! 🦅 If you want to: 1⃣manage high-performing experts 2⃣find evil and codify attacker methodologies 3⃣work on a team at the front lines of security ...this may be for you. jobs.smartrecruiters.com/Mandiant/74399…
During the Mandiant FLARE team's webinar series "The Sample," you will hear stories of notable #malware samples they have reverse engineered. Tune in this Thursday for the first installment of the series. Register 👉 mndt.info/3LAMFtF

Florian Roth ⚡️ @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Andrew Thompson @ImposeCost
39K Followers 1K Following Head of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer. Former @USMC.
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
John Hammond @_JohnHammond
298K Followers 3K Following Cybersecurity Researcher @HuntressLabs || Just Hacking Training @JustHackingHQ w/ @ethicalhacker || https://t.co/UtsNJiyQtS || https://t.co/narO3sz7y6
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
💻 Sherrod DeGrippo... @sherrod_im
36K Followers 7K Following Weird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
Tyler McLellan @tylabs
3K Followers 588 Following Intrusion aficionado. @Google/@Mandiant Advanced Practices
Nick Carr @ItsReallyNick
38K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
John Hultquist @JohnHultquist
29K Followers 1K Following Chief Analyst, Google Threat Intelligence Group. @CYBERWARCON and @SLEUTHCON founder. Johns Hopkins professor. Army vet.
Will @BushidoToken
36K Followers 3K Following Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here – find me on Bluesky: https://t.co/qHzDSxCRfG. 🇬🇷🇨🇦
J⩜⃝mie Williams @jamieantisocial
10K Followers 7K Following threats && stuff || #UNC1799 forever 🤘|| @DistrictHeather ♥️ + 🍷 **𝚅𝚒𝚎𝚠𝚜 𝚎𝚡𝚙𝚛𝚎𝚜𝚜𝚎𝚍 𝚊𝚛𝚎 𝚖𝚈 օ𝚠𝚗**
Steve YARA Synapse Mi... @stvemillertime
17K Followers 1K Following threat intelligence @google writing & sharing on adversary tradecraft, malware, threat detection, AI-nexus intel and all things #yara
Mehmet Ergene @Cyb3rMonk
13K Followers 437 Following https://t.co/uAlYlXIpyV Learn #KQL for #ThreatHunting, #DetectionEngineering, and #DFIR @BluRavenSec | Microsoft Security MVP | #DataScience
Samir @SBousseaden
25K Followers 1K Following Detection Engineering | Elastic Security Mastodon: @[email protected]
Nicole Beckwith @NicoleBeckwith
42K Followers 7K Following Director, Security Operations @kroger 🍓 Intel, Hunting, IR, Detection Engineering, Insider Risk, Fraud & Forensics 💻 Fmr LE & DFIR for OH & Secret Service TF.
Gigs @ Shmoo @Gigs_Security
2K Followers 725 Following not aspiring to be humble▪️ #AdvancedPractices🦅 ▪️Thoughts are my own ▪️She|Her|Gigs
Gabby Roncone 🇺�... @gabby_roncone
5K Followers 1K Following hunting russian apt cyber ops @Mandiant @GoogleCloud. views expressed here are mine, not my employer’s. she/her.
Nasreddine Benchercha... @nas_bench
11K Followers 1K Following Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner
[REDACTED] @BeardofCNorris
3 Followers 2K Following
Ankur @Ankuryogi11
345 Followers 6K Following
OIHEC hackers @HackersOIHEC
46K Followers 13K Following Hacker mexicano - Fundador de OIHEC antes OMHE - #opensoc #latam #speaker #pentester #blueteam #redteam #criptoanarquista #security
toshisam @toshisam
19 Followers 308 Following
Irpraute @Irpraute922063
70 Followers 3K Following
костя можли... @gprotaksa
12 Followers 79 Following
andrew @andrew0x02
341 Followers 939 Following security operations analyst | I try to explain what people can't
nathanael @nzvakayi
13 Followers 245 Following
skollr34p3r @skollr34p3r
15 Followers 75 Following I'm a pentester on here to stay up to date with news and techniques/tips root@yourpc:~#
Juline Molina @Jayslost1
0 Followers 36 Following
Atharva Sardesai @CyberWAtharva
21 Followers 175 Following CyberSec Nerd | I LOVE AUTOMATING THINGS !
mrinsecurity @mrinsecurity
9 Followers 376 Following
Emilie Davidson @EmilieD58961
296 Followers 2K Following
Vernon Adderiy @VernonA34468
235 Followers 2K Following
Rosalind Holmes @HolmesRosa71510
212 Followers 2K Following
Theeteight @TheeteightrodX
29 Followers 843 Following
Amulya @Amulya85819513
9 Followers 3K Following
Kevin Jimenez @RadKevinJimenez
30 Followers 168 Following Cybersecurity Professional 👾💻🛜📲📡| BlueTeam 🧢 🌐🧞♂️🛡️🪖| Threat Researcher 🔬👨🔬📚🕸️| Spiritual Hippie ☮️🪬| Super Rad Human Being 😎
Pruthvi Rathod @Pruthvi2899
28 Followers 1K Following
Cosimo de Medici @nosoyunagent
314 Followers 2K Following Bien, verdad y belleza. Pavarotti y Tenis.
Aham Brahmasmi @vishishtabrahma
0 Followers 571 Following Manas ekam, vachas ekam, karmanyekam, mahatmanam
shaun @net_reka
1 Followers 228 Following
Zach @svch0st
4K Followers 1K Following Everything DFIR @TheDFIRReport | @CuratedIntel | @XintraOrg https://t.co/ggakuKBS0S
Soyrough @SoyroughFCBpd
12 Followers 649 Following
🚨 The Most Exploit... @MostExploited
77 Followers 384 Following 🔍| Unveiling PoC exploits, zero-days & CVE insights | Shedding light on ransomware groups, cyber news & The Most Exploited CVEs
Lexie Aytes @cybseclex
86 Followers 409 Following Threat Researcher @ Google/Mandiant | just here for the memes | opinions are my own
christine 🌸💐�... @x71n3
1K Followers 875 Following 'Don't miss opportunities because you think that ideas aren't important unless they're complicated. Simple ideas are often the most powerful.' -Patrick Winston
cyber_crispr @cyber_crispr
5 Followers 135 Following Biotechnology - Salesforce - Cybersecurity. Starting my journey in Cybersecurity ❤️
BlackStork.io @blackstorkio
19 Followers 56 Following We are building a technical stack for efficient communication between mission-critical teams within organizations. #ReportingAsCode
DevSagazz @DevSagazz
71 Followers 506 Following Software engineer | Tech Lead | Curioso | .Net | Javascript
Romain @Romain344965
23 Followers 279 Following
Panda909 @kebablover369
1 Followers 57 Following
SecG3ek @SecG3ek
10 Followers 224 Following
badhombre @cortafuego11
7 Followers 287 Following
Sourav Debnath ✪ @1axceler
42 Followers 558 Following Security Engineer @Uptycs, Ex-TCL, Ex-Deloitte, Ex-Securonix Instagram : 1axceler
leon leon @Leon1435
118 Followers 3K Following
Andrew Thompson @ImposeCost
39K Followers 1K Following Head of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer. Former @USMC.
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Chris Sanders 🔎 �... @chrissanders88
34K Followers 489 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Tyler McLellan @tylabs
3K Followers 588 Following Intrusion aficionado. @Google/@Mandiant Advanced Practices
Nick Carr @ItsReallyNick
38K Followers 3K Following Tech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
John Hultquist @JohnHultquist
29K Followers 1K Following Chief Analyst, Google Threat Intelligence Group. @CYBERWARCON and @SLEUTHCON founder. Johns Hopkins professor. Army vet.
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here – find me on Bluesky: https://t.co/qHzDSxCRfG. 🇬🇷🇨🇦
Adam Chester 🏴�... @_xpn_
36K Followers 501 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOllCEu | Insta at https://t.co/PqR6CZPwjl
chompie @chompie1337
83K Followers 1K Following hacker, weird machine mechanic, X-Force Offensive Research (XOR)
Steve YARA Synapse Mi... @stvemillertime
17K Followers 1K Following threat intelligence @google writing & sharing on adversary tradecraft, malware, threat detection, AI-nexus intel and all things #yara
Samir @SBousseaden
25K Followers 1K Following Detection Engineering | Elastic Security Mastodon: @[email protected]
Nicole Beckwith @NicoleBeckwith
42K Followers 7K Following Director, Security Operations @kroger 🍓 Intel, Hunting, IR, Detection Engineering, Insider Risk, Fraud & Forensics 💻 Fmr LE & DFIR for OH & Secret Service TF.
The DFIR Report @TheDFIRReport
62K Followers 0 Following Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Services: https://t.co/XW613EKt2w
Gigs @ Shmoo @Gigs_Security
2K Followers 725 Following not aspiring to be humble▪️ #AdvancedPractices🦅 ▪️Thoughts are my own ▪️She|Her|Gigs
Gabby Roncone 🇺�... @gabby_roncone
5K Followers 1K Following hunting russian apt cyber ops @Mandiant @GoogleCloud. views expressed here are mine, not my employer’s. she/her.
Mandiant (part of Goo... @Mandiant
127K Followers 4K Following We’re determined to make organizations secure against cyber threats and confident in their readiness.
Dan Perez @MrDanPerez
4K Followers 1K Following 🇨🇳Mission TL @Google | #Malware Naming Wizard | #Attribution Connoisseur | All tweets are my own. #ThreatIntel #APT
SentinelLabs @LabsSentinel
5K Followers 386 Following We are the Threat Intelligence and Malware Analysis team of @SentinelOne
Elastic Security Labs @elasticseclabs
4K Followers 600 Following Elastic Security Labs is democratizing security by sharing knowledge and capabilities necessary to prepare for threats. Spiritually serving humanity since 2019.
NULL @NUL0x4C
9K Followers 393 Following Windows Malware Researcher | co-founder of https://t.co/1YRk2CEjaO
waldoirc @waldoirc
3K Followers 626 Following Trying to figure out how computers work. Figuring out SDR, IOT, and Mobile exploitation. https://t.co/rLZFU0dOBy
Dr. Nestori Syynimaa @DrAzureAD
20K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Filip Kafka @filip_kafka
605 Followers 150 Following
Aric Toler @AricToler
133K Followers 1K Following @nytimes Visual Investigations Previously @bellingcat [email protected] https://t.co/aHPY73i935 Signal/Telegram/WhatsApp: +1 913-209-0215
Lorenzo Franceschi-Bi... @lorenzofb
52K Followers 3K Following Senior reporter @TechCrunch, writing a book on Hacking Team and the industry of government spyware. ☎️ +1 917 257 1382
John Scarbrough @JohnFScarbrough
19 Followers 87 Following Incident Response @mandiant. Opinions my own.
SRonis @SRRonis
353 Followers 192 Following Senior Manager at Mandiant Intelligence/Google. Nonprofit exec turned cyber intel junkie.
Nicole O @wattsopp
30 Followers 29 Following
Rio @0x09AL
7K Followers 1K Following POC || GTFO Red Teaming - @NetSPI Organiser - @BSidesTirana @AxiomBreach
Andrew Northern 𓅓 @ex_raritas
5K Followers 1K Following 🔮 Senior Threat Researcher at @proofpoint 🔮 | Knowledge Piñata 🪅 | Attack Chain Connoisseur | Epicurean
bk (Ben Koehl) @bkMSFT
3K Followers 771 Following Partner Director of Threat Intelligence at @Microsoft Threat Intelligence Center (MSTIC).
furiousmac @furiousmac
370 Followers 69 Following Official Twitter account of the Furious MAC research group — GitHub: https://t.co/THTCFLuRuc
Sean Pierce @secure_sean
2K Followers 1K Following Stunt Hacker. I do work for Microsoft but my (re)tweets will always be my own
Roxana @RoxanaKovaci
644 Followers 381 Following Red Team @Nettitude_Labs | Former Red Team + Incident Response @Mandiant @GoogleCloud
BetterThanYesterdayCo... @ThanCoaching
176 Followers 3K Following Being better than yesterday. Coaching and consulting to high performance humans. https://t.co/YEDVJvI7jB
Ms. Marvel⚡ @msmarvel
111K Followers 16 Following Jersey City’s #1 protector. In California, visiting some friends there
Maznah @MaznahShz
302 Followers 763 Following Now: @denofgeekus Past: @thisisinsider @businessinsider @WeAreTheTempest @tribuneblogs @geonews_english | Journalist | @Studio20NYU | IG: maznah.shehzad
Rob Quickenden @rquickenden
1K Followers 2K Following CTO @Cisilion | #Microsoft MVP | Dad to 2 boys | Views are mine.Stefan Sellmer @Stefan0x531
559 Followers 1K Following Security Researcher @Microsoft - All tweets are my own!
Ronnie Salomonsen bsk... @r0ns3n
1K Followers 3K Following Adversary Methods - Research & Discovery (RAD) Team @Mandiant - Now Part of @GoogleCloud. Former DFIR, Malware & Network Analyst. All tweets are my own.
christine 🌸💐�... @x71n3
1K Followers 875 Following 'Don't miss opportunities because you think that ideas aren't important unless they're complicated. Simple ideas are often the most powerful.' -Patrick Winston
David Weston (DWIZZZL... @dwizzzleMSFT
25K Followers 2K Following Corporate Vice President, OS Security and Enterprise @Microsoft
The Vertex Project @vtxproject
3K Followers 4K Following On a mission to create an intelligence-driven future with Synapse.
Merill Fernando @merill
18K Followers 4K Following Product Manager @microsoft | Tweets my own Built → https://t.co/ujxKqxXjf2 • https://t.co/QbUp63ffXf • Graph XRay • https://t.co/tSWrIw8Ajh 📰 Newsletter→ https://t.co/tPzAEl0Zuq 🎙️ Podcast→ https://t.co/TBlNKTzn8t
Abigail Schott-Rosenf... @aschottrosen
15 Followers 148 Following Associate Editor at No Starch Press
Greg Darwin @gregdarwin
2K Followers 0 Following No longer using Twitter. Gone looking for blue skies.
Lindsay Kaye @TheQueenofELF
1K Followers 270 Following VP of Threat Intelligence @SecurewithHUMAN | Reverse Engineer | Conference Speaker | Ransomware Columnist
Mark Karayan @Mgkarayan
967 Followers 4K Following @googlecloud Threat Intel Comms Lead. I don't want to sell anything, buy anything, or process anything as a career. @markkarayan.bsky.social
Roberto Bamberger @RBamberg2
112 Followers 127 Following Member of the Microsoft Global Hunt, Overwatch, and Strategic Triage (GHOST): Jumping into customer cybersecurity incident response situations day after day.
Jeremy Dallman @jdallman
1K Followers 153 Following Microsoft Threat Intelligence. Mostly promoting work stuff & smart security people. Obsessed with good coffee & scotch. Opinions my own.
TheDuck @RowdyChildren
411 Followers 442 Following Ghostbuster @Microsoft. Network Team Lead @Dreamhack Festivals in NA. My words not @Microsoft or @Dreamhack. #PatchYourShit He/Him
vulnKat @vulnKat
135 Followers 83 Following
The A11Y Project @A11YProject
14K Followers 41 Following Not Twitter’s accessibility support account. Paused for the duration. https://t.co/AofV6bb5Pc
Shpend K @shpendk
991 Followers 892 Following I want to die in sleep like my Grandfather did, not screaming like his passengers. Tweets are mine and don't represent my employer
alex lanstein @alex_lanstein
3K Followers 3K Following threaty threats @ StrikeReady -- helping build research workflows into the product. pretty good at bash scripts and strings. disclosures on my linkedin below