DFIR | Automator of things | APT Hunter | Malware Reverser | SANS Instructor Candidate | Views expressed here are my ownmikecybersec.medium.com DigitalOceanJoined July 2023
If you're not getting the answers you're looking for, change the questions you're asking...
"Is PingCastle detected?" is the wrong question...
"Is Active Directory enumeration detected?" is better...
"Is high volume enumeration of the Domain Administrators group from a…
Good advice but to add context... Legitimate apps and tools use Axios, we're seeing commercial/sales teams who use PipeDrive will also produce Axios UAs in AAD Audit.
Be careful before locking out your clients sales directors 👀
Good advice but to add context... Legitimate apps and tools use Axios, we're seeing commercial/sales teams who use PipeDrive will also produce Axios UAs in AAD Audit.
Be careful before locking out your clients sales directors 👀
As I've aged into offensive work, the value of certs has diminished for me compared to a solid methodology
Delivering a quality assessment is so different from cert material. Maybe there's room for a course that guides you through an assessment start to finish? (Reporting too?)
Logging into Xitter and seeing thousands upon thousands of people, who have never written a single line of code their entire life and can barely use a computer, giving their expert input into kernel-mode programming
One for the SOC/MDR peeps. When you detect a burst of activity in a customer environment and reach a verdict that it's benign, but the detections were accurate.
Do you still notify your customers?
400 Followers 4K FollowingFormer historical studies major. Music lover, politics junkie, lapsed Discordian, bibliophile. Views my own, etc. Year of the scavenger, season of the bitch.
41K Followers 9K FollowingInformation security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast https://t.co/VpKtfz8nXG
685 Followers 656 FollowingDad ⚭ Husband
𒉭 Azure Security | DE&TH | IAM
🏕️🥾 Catch me outside
🏋️♂️CultoftheIron
What stands in the way, becomes the way
617 Followers 659 FollowingOffensive Security R&D, Pen Tester.
On my continuing mission to replace myself with a small script. He/Him
https://t.co/eJUGYPAbMs
608 Followers 0 FollowingYARA-first adversary infrastructure discovery at internet scale. Uncover residential proxies, VPNs, malware C2s, and more with 500+ baked-in rules.
48K Followers 2K FollowingThe official Twitter account of the Microsoft Most Valued Professional (MVP) and Regional Director (RD) Programs. Follow for news, updates, and much more.
685 Followers 656 FollowingDad ⚭ Husband
𒉭 Azure Security | DE&TH | IAM
🏕️🥾 Catch me outside
🏋️♂️CultoftheIron
What stands in the way, becomes the way
2K Followers 21 FollowingSublime Security is the adaptive, AI-powered cloud email security platform that combines best-in-class effectiveness with unprecedented visibility and control.
8K Followers 1K FollowingChristian Family Man, CEO of Patriot Consulting (Microsoft Security Partner) Author of "Securing Microsoft 365" Microsoft MVP (Security) (2020-present)
29K Followers 4K FollowingHi I'm Stu from '42 | ❤️OSINT |✍️ CTI & Analytics book ~2025, Tracelabs Black badge x3 | Ex- @themanyhatsclub | #cyber Views my own not employers
6K Followers 378 FollowingSimplify and clarify • Cybersecurity architecture and strategy • Business + Security Alignment • Make the world better
@markasimos.bsky.social
163 Followers 97 FollowingManaging Director at @fyfeweb - a UK based data centre, server & web hosting infrastructure service provider. Based in North East England. Views are my own.
4K Followers 922 Followinghttps://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
617 Followers 659 FollowingOffensive Security R&D, Pen Tester.
On my continuing mission to replace myself with a small script. He/Him
https://t.co/eJUGYPAbMs
943 Followers 731 FollowingOSCP, CRTO, GCPN, GWAPT, MS in InfoSec. Fortunate pen tester... just learning all the things! And the obligatory: my views don’t equal my employer’s...