Jared @JaredStemper
My posts include: security in the modern world, quotes from people way smarter than I am, and the occasional meme. jared.com Joined November 2018-
Tweets33
-
Followers21
-
Following130
-
Likes1K
Damn, a chinese variant (FM11RF08S) of MIFARE Classic cards are found to be backdoored by the manufacturer! Special auth commands leak (static) encrypted nonces which can then be used to recover sector keys and dump the card. They’ve already released- eprint.iacr.org/2024/1275.pdf
🚨 Exciting workshop alert! 🚨 Join @th3d00rman at RTV during @defcon 32 for "Developing Evilginx Phishlets" . 🛠️ Learn to configure phishlet 'yaml' files and explore new Evilginx3 features. 🖥️ 📅 10 Aug 2024 , 11:00 AM 📍 Infinity (Track 3)
During my red team days in Mandiant, we use the console of CarbonBlack to perform mass script/command execution on various systems. Another time, we got access to a shared drive with memory dumps of various systems which the IR team was using, and we downloaded and dumped the creds from these ram-dumps to move laterally. Remember gents everything is a C2 and everything can be exploited. Crowdstrike is nothing new.
Abuse of Crowdstrike response shell access for C2. Don't forget that attackers can sometimes use EDRs and other security tools to go from compromising cloud accounts to compromising on-prem machines and user devices.
The Google Android Red Team's first blog post is now live! Congratulations to the whole team for the big effort to make this happen 😀 androidoffsec.withgoogle.com/posts/attackin…
Offensive IoT for Red Team Implants (Part 3) blackhillsinfosec.com/offensive-iot-…
Jailbreaking a Cisco appliance to run DOOM (CVE-2024-20356) : labs.nettitude.com/blog/cve-2024-…
@SpecterOps announces v5.0 of free #BloodHound AD mapping tool, bringing new features, greater speed and ease of use, and promising more frequent future releases — a boon for security teams, pentesters, and hackers of all flavor. @SecurityWeek securityweek.com/specterops-upd…
This is exactly what I hoped would happen. Someone would be inspired, go implement it, have fun, learn some cool stuff, and execute on it! Thanks for sharing the blog post and walking everyone through it. Sorry I haven't released RogueRDP yet, it's coming soon! 💪🏼
Watched @ustayready webcast yesterday and decided to try implement the technique myself. Got it working and as a POC plant DLL in Teams folder to be sideloaded for persistence / code exec. Very cool initial access technique. Amazing work @ustayready Blog: shorsec.io/blog/malrdp-im…
🔥 Excited to share my latest @Mandiant Red Team blog on "Escalating Privileges via Third-Party Windows Installers" mandiant.com/resources/blog… Learn how attackers exploit this privilege escalation vector and ways to defend against it. Includes BOF release and a couple CVEs!
Check the whole post for more about the attacker's infrastructure and capabilities. microsoft.com/en-us/security…
googleSearcher A custom Google search (to bypass some limitations on Google with regards to timeouts, vpns etc). github.com/AssassinUKG/go… #infosec #pentesting #bugbounty t.me/hackgit/9221
Introducing DavRelayUp - A port of #KrbRelayUp with modifications to allow for NTLM relay from WebDAV to LDAP and abuse #RBCD in order achieve #LPE in domain-joined windows workstations where LDAP signing is not enforced. Demo in second tweet. github.com/Dec0ne/DavRela…
We can't even decide as a collective if it is cyber security or cybersecurity. We aren't grown up enough to define out job roles.
Today @Google is announcing a unified vulnerability schema for open source. This is the first of its kind & seeks to address some key problems w/ managing vulnerabilities in open source. Learn more: security.googleblog.com/2021/06/announ…
I am content in here. I have friends. The food is good. All is well. Know that if I hang myself, a la Epstein, it will be no fault of mine.
What if I told you that the vast majority of your privacy risk comes not from the seedy darkweb, but from completely legal data brokers?
@woodyatpch @StephandSec @ren_tragger I couldn’t think of anything but this.
Cameras, Microphones & speakers on ALL smartphones should have LEDS connected to VCC and GND. This should be LAW, how is it possible we all carry a remote listening device with no idea if anyone else is listening everyday - no cues on what circuits on the device are running.
.@NSAGov, the webcam covers you're giving out have an interesting defect: the purple ones are transparent. 🤔
Jordan Rodgers @bhd_rodgers
29 Followers 558 Following 🛡️ Black Hat Defense | Free Penetration Test | Your Asset 💻 Specializing in cybersecurity solutions to outsmart black hat hackers.
Anna Baydakova @baidakova
6K Followers 1K Following Crypto, cybercrime and human rights. Newsletter on digital censorship and surveillance. Past: @TheBlock__, @CoinDesk, @novaya_gazeta. Alumna of @columbiajourn.
Michael Donley @th3d00rman
47 Followers 176 Following Advanced Persistent Friend OSCP, GAWN, GMOB, GWAPT The mean person who yelled at you at the DEFCON Red Team Village https://t.co/Mv85XQ7Oox
Shayan Ahmed @shayankahmed4
38 Followers 2K Following SAP | ERP | Startups | Programming | Cybersec | ML/AI | Gamedev | Data
Hunt.io @Huntio
7K Followers 956 Following https://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
Sam Curry @samwcyo
102K Followers 1K Following
Chris Hanlon @ChrisHanlonCA
17K Followers 18K Following Security Engineer Google Security Hall of Fame Presenter & Workshop host at #BSidesLV and #DEFCON
Isak Nti Asare @IsakNti
797 Followers 2K Following Co-director, Cybersecurity and Global Policy Program @Iubloomington, @HamiltonLugar. Personal account, views my own.
PR Growth Hacking @PrGrowthHacker
811 Followers 3K Following #growthhacking with #PR at its core. All the tips and tricks you need to make waves in #publicrelations.
Get Oureach For Your ... @outreachgb
170 Followers 2K Following We leverage our long-standing relationships across industries to ensure we are ahead of the changing media landscape. We're committed to getting you your next b
Reciproc-it @reciproc_it
309 Followers 798 Following Éditeur de logiciels d'analyse de risques cyber: Oligo Risk Manager. Nous sommes labellisés Ebios Risk Manager par l'@ANSSI_FR.
Organización Mundial... @OTranshumanismo
117 Followers 473 Following
Helen @HelenNegre
412 Followers 938 Following 99% Love, Light, & Rainbows. Wife & Dog mom. Interests: Infosec, Appsec, ICS, IoMT My views are my own and do not represent opinions of my employer.
Net Access India Limi... @NetAccessLtd
217 Followers 919 Following Promoted by the renowned #MurugappaGroup and driven by innovation, #NetAccess India provides a wide range of professionally managed IT services.
Fido @phil_fido
394 Followers 5K Following
Debra Baker, CISSP CC... @deb_infosec
6K Followers 3K Following 📕Author l CEO TrustedCISO l #Cybersecurity Pundit https://t.co/Bgt9YGbW1q
William Harvey @williamharvey07
1K Followers 2K Following Providing u with the latest #cybersecurity news and updates. Can Help👇 #FixHackedWebsite #WordpressMalwareRemoval #FreeForensicsAnalysis #FreeMalwareScan
BC Gain @bcamerongain
600 Followers 716 Following DevOps. Security. Observability. Linux. Kubernetes. Sailing. ReveCom.
Bill Demirkapi @BillDemirkapi
22K Followers 402 Following preparedness research | ex @xai, @microsoft, @zoom
Iceman @herrmann1001
14K Followers 1K Following RFID hacker, Proxmark, NFC & EMV | Magic moon beans | Four spaces instead of Tab | https://t.co/A6rzUPpPs6 https://t.co/dZD52FgCaL
Anna Baydakova @baidakova
6K Followers 1K Following Crypto, cybercrime and human rights. Newsletter on digital censorship and surveillance. Past: @TheBlock__, @CoinDesk, @novaya_gazeta. Alumna of @columbiajourn.
CynoSure Prime @CynoPrime
1K Followers 109 Following A password research collective https://t.co/8MhfTbfjsG
Sam Curry @samwcyo
102K Followers 1K Following
Michael Donley @th3d00rman
47 Followers 176 Following Advanced Persistent Friend OSCP, GAWN, GMOB, GWAPT The mean person who yelled at you at the DEFCON Red Team Village https://t.co/Mv85XQ7Oox
Black Hills Informati... @BHinfoSecurity
50K Followers 2K Following Specializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
RedTeamVillage @RedTeamVillage_
38K Followers 1K Following Red Team Village | Join us on https://t.co/ILZhRFw4Y7 . Check our next events at: https://t.co/fJwIUSTI16
Chris Thompson @retBandit
7K Followers 922 Following CEO @ RemoteThreat & Founder of Offensive AI Con | Former Head of X-Force Adversary Services | Black Hat Review Board | inveni et usurpa
Will Schroeder @harmj0y
50K Followers 975 Following Researcher @SpecterOps. Coding towards chaotic good while living on the decision boundary.
Elad Shamir @elad_shamir
5K Followers 27 Following
Jason Kint @jason_kint
79K Followers 3K Following CEO of @dcnorg working to advance the future of trusted news & entertainment, living through AI-driven disruption. #HoldTheLine #PressFreedom
Binni Shah @binitamshah
140K Followers 159 Following Linux Evangelist, Malwares, Security enthusiast ,Investor,World Economy, Finance,Contrarian , Philanthropist , Reformist , Sigma female [email protected]
SpecterOps @SpecterOps
42K Followers 403 Following Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management
Ryan Smith 🇨🇦 @cybermarm0t
416 Followers 1K Following I help make the world a more secure place - Security Reasearcher @msftsecurity - @BSidesVI - Youth Sports Board Member x 2 - Views are 100% mine - he/him
📔 Michael Grafnett... @MGrafnetter
4K Followers 142 Following Principal Security Researcher @SpecterOps, Microsoft MVP Identity & Access + Enterprise & Platform Security
Josh @passthehashbrwn
10K Followers 294 Following Adversarial Simulation at IBM, tweets are mine etc.
Justin Elze @HackingLZ
74K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Snowscan @snowscan
6K Followers 435 Following
Dirk-jan @_dirkjan
30K Followers 208 Following Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
CVE Trends @CVEtrends
8K Followers 0 Following Monitor trending CVEs in real-time; crowdsourced intel sourced from Twitter, NIST NVD, Reddit, and GitHub. Run by @SimonByte
Gi7w0rm @Gi7w0rm
19K Followers 820 Following Threat Intelligence Analyst | Projects: https://t.co/azRpNg9NJQ & https://t.co/SyvUfXpbmI | If I post false intel, contact me! Support me: https://t.co/5WgDqr0K8p 🇪🇺🇩🇪🇺🇦🌈
THOTCON! @thotcon
10K Followers 132 Following Chicago's Hacking Conference - TBA 2027 - Discord: https://t.co/2EUmMpHcJc - a 501(c)(3) nonprofit organization - Donate: https://t.co/gxZT07dbCU
vx-underground @vxunderground
449K Followers 374 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Chris Hanlon @ChrisHanlonCA
17K Followers 18K Following Security Engineer Google Security Hall of Fame Presenter & Workshop host at #BSidesLV and #DEFCON
Sun Tzu @SunTzuCyber
14K Followers 1 Following If Sun Tzu had written "The Art of Cyber War", these would be his quotes. Lovingly operated by @MaliciousLink.
Tim Berners-Lee @timberners_lee
318K Followers 728 Following Inventor of WWW Co-founder/CTO https://t.co/El70jppi0M Co-founder https://t.co/61fuIdZHHu Founder https://t.co/sEpIVjXIsU Mastodon: https://t.co/iDQ5mmzR0H My memoir ‘This is for Everyone’ out 9th September ⬇️
Brandon Evans @BrandonMaxEvans
580 Followers 609 Following I'd prefer if you followed me on LinkedIn: https://t.co/kM2WdXETHp
Christofer Hoff @Beaker
24K Followers 3K Following coffee. creator. cars. cyber. cloud. ‘cue. change. culture. credentials. @ scale Security CTO/CISO/Engineer & Ops focused. CSTO @lastpass Opinions are MINE only
Jek Hyde @HydeNS33k
29K Followers 443 Following I’m Jek & I break into buildings! 🧚🏻♀️ Mother🤱🏼Wife 👑 Nefarious Character 🤓 Thief 😇 Social Engineer 🌹 Let's be bad guys! 🕷️
Martin McKeay @mckeay
22K Followers 1K Following You can find me on Mastodon at https://t.co/Xd6p4Unzqe Instigator, agent of chaos, friend. My opinions are my own, you can't have them!
Chris Parker @chrispcritters
22K Followers 936 Following Founder https://t.co/BKc0KgUNAv @wimia | Author: Privacy Crisis | Host of @EasyPreyPodcast | Online Privacy & Safety Expert
Isak Nti Asare @IsakNti
797 Followers 2K Following Co-director, Cybersecurity and Global Policy Program @Iubloomington, @HamiltonLugar. Personal account, views my own.
ShellStorm @bhohenadel
1K Followers 897 Following Computer security enthusiast and martial artist. I like to find holes in defenses and exploit them. OSCP, OSCE, CISSP. Adversarial Engineer at @Lares_
Fido @phil_fido
394 Followers 5K Following
Space Rogue @spacerog
24K Followers 323 Following I fight for the user. | L0pht Heavy Industries - ATStake - Whacked Mac Archives - Hacker News Network - Cyber Squirrel 1 | IBM X-Force
Snow @_sn0ww
42K Followers 1K Following Your friendly neighborhood Con-Artist | @sec_defcon Co-Founder | 3x Black Badge | Trainer/Keynote |💍@jc_socal | She/her 🏳️🌈
Ryan Kazanciyan @ryankaz42
5K Followers 364 Following CIO & CISO @Wiz_io - now part of @GoogleCloud! Previously sec eng @ Meta, CTO @ Tanium, IR director @ Mandiant, and consultant for #MrRobot. Opinions my own.
Robert M. Lee @RobertMLee
75K Followers 397 Following Co-Founder & CEO @DragosInc | SANS #FOR578 & #ICS515 course author & Faculty Fellow |@_LittleBobby_ writer | NSA & USAF Veteran



























