Seth Phillips @phillips_dev
Dad.SOC monkey. I retweet Infosec resources for my own use but hope they are also useful to others. Texas, USA Joined July 2015-
Tweets507
-
Followers104
-
Following838
-
Likes4K
Slides for my #thotcon workshop: "Fun With LDAP, Kerberos (and msrpc) in AD Environments". Thanks everyone for coming out and the great questions and comments. Reach out if you wanna discuss anything more! speakerdeck.com/ropnop/fun-wit…
Great write-up! I spoke about password spraying with kerberos pre-auth, here's how to make sure you're ready to detect all types of password spraying and the relevant Windows events
Great write-up! I spoke about password spraying with kerberos pre-auth, here's how to make sure you're ready to detect all types of password spraying and the relevant Windows events
Defending against PowerShell attacks - in theory, and in practice by Lee holmes: youtu.be/M5bkHUQy-JA?a via @YouTube
Microsoft unveils Windows Defender System Guard runtime attestation, a new Windows platform security technology for all editions of Windows securityweek.com/microsoft-anno…
Do me a favor? RT and get this outside the echo chamber. There are local govs and businesses being hit by SamSam and they don't understand why.
Do me a favor? RT and get this outside the echo chamber. There are local govs and businesses being hit by SamSam and they don't understand why.
A good documentation on all the different #LOLBins and #LOLScripts would be nice? Right? Good thing I have started then. Still have a lot of notes to add, but I feel this is a good start. Would love community feedback and contributions. Is this useful? github.com/api0cradle/LOL…
#VPN leaks users’ IPs via #WebRTC. I’ve tested seventy VPN providers and 16 of them leaks users’ IPs via WebRTC (23%) voidsec.com/vpn-leak/
I often/still find Group Policy Preferences passwords when I do my pentests. To check if you have this present in your domain you can run this command: findstr /S /I cpassword \\<FQDN>\sysvol\<FQDN>\policies\*.xml A great write-up here by @PyroTek3 adsecurity.org/?p=2288
BombLab Dissected with Radare2 : moveax.me/bomblab/
Very good presentation by @ThreatHunting on Defending Microsoft environments at scale. #dfir #BlueTeam drive.google.com/file/d/1QXjmlP…
Adversary Emulation is the new hotness. Let's recap: -Caldera github.com/mitre/caldera -APTSimulator github.com/NextronSystems… -Metta github.com/uber-common/me… -RTA github.com/endgameinc/RTA -RedHuntOS (VM implementing some of the above) github.com/redhuntlabs/Re… Am I missing some? #DFIR
Very cool tool built by @carnal0wnage from Uber Uber Releases Metta Adversarial Simulation Tool decipher.sc/uber-releases-… #decipher #deciphersec
Hijacking the Admin/Jump Servers of Domain Admins: Get Admin on the jump server -> Get SYSTEM -> Run tscon.exe as SYSTEM -> "if you run tscon.exe as the SYSTEM user, you can connect to any session without a password" medium.com/@networksecuri… thanks @PyroTek3 #adsecurity #DFIR
Not heard of the Sticky Keys attack? It creates an admin CMD.EXE on the login screen by hitting the Shift key 5 times. Loved by pentesters and APTs, @MITREattack has a page on it: attack.mitre.org/wiki/Technique… Here's how you can find it with #WDATP Advanced Hunting cc/@SwiftOnSecurity
New hardware vulnerabilities discovered that allow bypass of secure boot and code execution. AMD had 24h to respond to the notice before public announcement, so more details certainly forthcoming. amdflaws.com
Check out my OSCP Course review: hackingtutorials.org/hacking-course… #oscp #hacking
A great way to build strong&connected #dfir teams 1) $200/pp yearly book allowance 2) once a week have a member present new knowledge over lunch (Skype remote) 3) dedicate a wall to the team library 4) give jr./new hires extra time to read from library&review past presos
exploit_me : Very vulnerable ARM application (CTF style exploitation tutorial) : github.com/bkerler/exploi…
There is malware that obfuscates itself, and then there is FinFisher that shows them how it is done. Why? Read what it takes to analyze this malware: cloudblogs.microsoft.com/microsoftsecur…. Nice work @aall86 and Elia!
Timeline Explorer 0.7.0 released. Mostly polish but a few new things (group counts, better filtering in the editor, themes, font selection, etc). Try a fixed width font today!!!!!1 ericzimmerman.github.io #DFIR

Demetris Rau @DemetrisRa92162
54 Followers 3K Following
Fawn @koiwaichie80616
73 Followers 7K Following
MabelCarter @4930tfXECS3byWq
70 Followers 7K Following
Nease @Nease663022
48 Followers 1K Following I live alone now and enjoy business, traveling, shopping, food and music. I have a calm personality and I hope we can be friends.
JC @taskar_jc
44 Followers 3K Following
Kay Ayala @Kay_Ayala_
102 Followers 1K Following Data Scientist at Luxoft. Interested in quality global education and climate change.
Decoy @decoyuser
41 Followers 137 Following Network Defender. Cyber Deception Practitioner. Tweets are my own. Retweets are not endorsements. #CyberDeception
李泉 @liquan165
2 Followers 68 Following
() { :;}; Mike @Bumjubeo
413 Followers 2K Following Penetration Tester, Red teamer, DFIR #purpleteam Tweets are my own.
Exabeam @exabeam
5K Followers 3K Following Exabeam is a leader in intelligence and automation that powers security operations for the world’s smartest companies.
SynAckPwn23 @SynAckPwn23
677 Followers 2K Following Ethical Hacker | SCADA | SEC 760 | GXPN | GREM | OSCE | OSCP | GPEN | GCTI | GRID | GICSP | eCPPT | Malware Reverse (No idea what I’m doing)
BlackBerry Cybersecur... @BlackBerrySpark
22K Followers 7K Following AI-Driven Cybersecurity that Works Smarter, Not Harder
The Inky Squid Conten... @TheInkySquidCA
122K Followers 119K Following Outstanding quality technology, marketing & business content at affordable prices. From startups to blue chips and agencies - email [email protected]
The Sec Whisperer @SecWhisperer
87 Followers 447 Following I speak the truth. Unapologetic. Nothing is safe with me. #Dangerous #InfoSec #CyberSec #S3CWh1SP3R3R
Scott @ScottForensics
3K Followers 2K Following #DFIR Forensics Trainer @MagnetForensics. Retired @ABQPolice & @FBI Digital Forensic Examiner / ESD #DFIRdog K-9 handler🐕 | Always learning | Opinions=my own.
Jim Schwar @jimiDFIR
1K Followers 470 Following Security specialist who hunts for evil. Incident Responder, amateur malware analyst, independent security researcher.
emily @malwaremily
384 Followers 1K Following Detection Engineering, MARE & Honeypots 🍯 | Incident Detection Engineer @blumirasec | she/her
Minerva Labs @MinervaLabs
2K Followers 406 Following
Earl Carter @kungchiu
813 Followers 775 Following Retired Threat Researcher. Love perfecting my guitar and piano skills and playing video games.
Cyber Fusion Team @SecAlliance
1K Followers 1K Following Welcome to the Cyber Fusion Team at Security Alliance | @SecAlliance | in London - Cyber Intelligence commentary from our team.
Amy Renee has moved t... @amyengineer
21K Followers 5K Following All things networking & security. @amyengineer.bsky.social Sharer of knowledge, purveyor of puns, curator of amusement. Wielder of snark & sparkly bats.
Aaron Rubesh @aaron_rubesh
97 Followers 386 Following Reverse Engineer | Software dev | Slowly learning Russian | currently building cool things for @mandiant
David Cowen @HECFBlog
14K Followers 924 Following Co-Author SANS FOR509, Vice President @ https://t.co/whEvYHKz6R wrote some books a long time ago, fights fires in the cloud. Views expressed are my own.
Jason Nickola @chm0dx
836 Followers 1K Following Dad. Hacker. SANS Pentest Instructor. Code might run.
Dávid Kosť @dk_samper
428 Followers 3K Following Everything SOC | All opinions are mine and not necessarily those of my employer, whoever that might be.
Chris Kerstiens @chriskerstiens
775 Followers 4K Following IT guy with a nasty infosec habit. Bama Alumnus married to an Aggie. Maritime Geek, Adequate Technologist, Recovered Sysadmin, Fly Fisherman, Yacht Rock Fan.
Samurai Hacks @SamuraiHacking
242 Followers 745 Following Follow us for latest hacking tutorials, news and tips. Visit us at https://t.co/sGWqhtRmlG. Feed your technolust.#Hacking #infosec #PenTest
Whitney Champion 🍪... @shortxstack
30K Followers 11K Following security architect / cofounder @Recon_InfoSec / cofounder @DDI_training / ♥️♥♥ == @eric_capuano, nerdery, rainbows, sweatpants | she/her 🤍🌿🍄🌈🫶
Hollywood Suits @HollywoodSuits
50K Followers 137K Following Online Menswear Retailer | Flagship store open for 30+ years • Follow us for Styles, Trends, Tips, Special Deals & Take 20% OFF your 1st purchase! ⬇️
jack @jackdaniels7885
31 Followers 1K Following
totem@進捗ダメで... @bbottait
568 Followers 1K Following
Dallas Hackers @Dallas_Hackers
7K Followers 1K Following Official Twitter Feed of The Dallas Hackers Association.
Securable @securableio
8K Followers 8K Following Securable.io provides data-driven cyber awareness. We identify vulnerabilities in employees and deploy specific education materials
Cybercroissant @cybercroissant
718 Followers 3K Following Cybercroissant is a security podcast bringing people from different walks of life to talk about cybersecurity. #podcast #cybersecurity #iot #hacking #infosec
Mark Bennett @MarkyMarkGames
17 Followers 99 Following Let's Plays and Top Tens are my passion. I upload at least one video every day at noon central. Check my channel for my upload schedule. Stay awesome.
zeekeel @kehol9
1K Followers 5K Following Head of Cyber Ops and general happy chap driven by empathy. My thoughts are my own and do not represent any companies I work for.
iwantmeronpan @iwantmeronpan
31 Followers 483 Following
Misty @MsyticalForums
96 Followers 723 Following Hi my name is Misty, and I am here to chat and make new friends.
Hive @gethived
684 Followers 3K Following Hive lets #candidates discover companies hiring #cybersecurity professionals. Companies, jobs and career advice for #infosec talent. Launching Fall 2017.
Giga Biter @giga_biter
165 Followers 2K Following This account is to showcase computer related clothing designs for all geeks alike and sprinkled with a bit of humor.
nerdiosity @nerdiosity
2K Followers 725 Following Cyber Rocket Surgeon. My bowtie is my super power. Alter Ego of PowerShelly. ~167 LEGO bricks tall Mastodon: @[email protected] BlueSky: @nerdiosity
Hacker House @myhackerhouse
20K Followers 5K Following World-class ethical hacking services & training. Cutting-edge cybersecurity solutions. Hacker House: Hands-On Hacking authors. Contact the team! #CyberSecurity
sneakerhax @sneakerhax
5K Followers 249 Following Director of Red Team @Adobe / Previously, Red Team @Microsoft & @Intuit / Trendy Squid Life 🦑
Ronnie Flathers @ropnop
6K Followers 909 Following security engr, pentester, researcher. i sometimes blog and code based on motivation/caffeine levels. Principal Security Engineer @Marqeta
PowerShell Magazine @PowerShellMag
18K Followers 198 Following The “PowerShell Magazine” is an online magazine serving exclusive PowerShell content with 60+ contributing authors and five PowerShell MVPs!
Conrad @eric_conrad
11K Followers 1K Following SANS Fellow, CTO of Backshore Communications, GIAC GSE #13 I'm not here. Find me on BlueSky: https://t.co/Ut2rwc0GAH
Nmap Project @nmap
139K Followers 457 Following Free and open source tool for network discovery, admin, and security auditing. Our tweetmaster is Gordon "Fyodor" Lyon. We're also on FB: https://t.co/RVkxWNikvW
Dark Reading @DarkReading
343K Followers 48 Following One of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
Black Hat @BlackHatEvents
421K Followers 2K Following The World's Premier Technical Cybersecurity Conference Series
Pentester Academy @SecurityTube
195K Followers 14K Following We help professionals acquire the skills, knowledge and certificates by teaching defense through offense to advance their careers in cybersecurity.
Cn33liz @Cneelis
13K Followers 600 Following Red teamer @ Outflank. Passionate about networking and cybersecurity | father of two superheroes.
Kevin Robertson @kevin_robertson
4K Followers 186 Following
Eduard Kovacs @EduardKovacs
14K Followers 1K Following Managing Editor @SecurityWeek - I cover ICS/OT security, data breaches, vulnerabilities, cybercrime, malware, and industry news.
David Weston (DWIZZZL... @dwizzzleMSFT
25K Followers 2K Following Corporate Vice President, OS Security and Enterprise @Microsoft
Mudge @dotMudge
63K Followers 336 Following Make a dent in the universe. Find something that needs improvement: go there and fix things. If not you, then who? {he/they}
🇺🇦 Nate Warfiel... @n0x08
14K Followers 2K Following Hacker | WIRED25 2020 | Drum&Bass DJ | https://t.co/Aa7tIdCdrM
svbl 🇺🇦 @svblxyz
11K Followers 2K Following 🇺🇦🌻 - My tweets represent your employers opinions. Most of this is false. I am making this up. I always tell the truth. Verified.
Oddvar Moe @Oddvarmoe
19K Followers 1K Following Red Teamer @TrustedSec | MS MVP | Speaker | Security Researcher | Blogger | Total n00b & always learning | UNC1194 | Tinkerer | Gamer I try to inspire!
Barrett Adams @peewpw
763 Followers 368 Following Founder; Developer; Hacker Co-Founder @getCourseStack. ex Snap Labs - acq. by Immersive Labs.
Microsoft Security Re... @msftsecresponse
145K Followers 215 Following We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit https://t.co/kxEbdfMny1.
Ulf Frisk @UlfFrisk
8K Followers 980 Following IT-Security Minion | https://t.co/N1gIUL5rKc | https://t.co/XbBOnQPYoK | DMA | PCILeech | MemProcFS
DEF CON Groups @defcongroups
8K Followers 57 Following DC Groups are up and running all around the world! Defcon would like to thank the founders of the groups for all of their hard work and input.
Claud Xiao @claud_xiao
3K Followers 422 Following
Palo Alto Networks Gl... @PANWGovPolicy
2K Followers 283 Following Official account of Palo Alto Networks global policy team. Tweeting views & news about policies worldwide impacting cybersecurity and trust in the digital age
Security Roundtable @SecurityRT
3K Followers 248 Following Cybersecurity for business leaders. In a world of threats, follow us for ideas. Powered by #PaloAltoNetworks
Unit 42 @Unit42_Intel
64K Followers 81 Following The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
Qualys @qualys
34K Followers 4K Following The leading provider of disruptive cloud-based security, compliance and IT solutions.
Check Point Software @CheckPointSW
71K Followers 3K Following You deserve the best security. Get the protection you need against AI-driven cyber attacks.
Palo Alto Networks @PaloAltoNtwks
128K Followers 468 Following Our Mission: Cybersecurity partner of choice, protecting our digital way of life.
Threat Insight @threatinsight
11K Followers 217 Following @Proofpoint's insights on targeted attacks & the security landscape. Follow us on Bluesky: https://t.co/8OVfhotdeP
NCC Group Research & ... @NCCGroupInfosec
20K Followers 2K Following Technical account for global cyber security & resilience provider, NCC Group. This account is run alongside the @NCCGroupplc corporate account.
Holly Graceful @HollyGraceful
13K Followers 856 Following PenTesting @AkimboCore. “Not all thoughts have to be noises Hollister” — @_mormaid
Fidelis Security @FidelisCyber
2K Followers 776 Following Official home of Fidelis Scurity. We help organizations find, detect, respond and neutralize advanced cyberattacks across endpoints, networks and cloud.
Danny Quist @OpenMalware
13K Followers 201 Following Open Malware Project by Danny Quist. Formerly Offensive Computing.
Alessandro Tanasi @jekil
2K Followers 640 Following A grumpy old master craftsman, who sleeps with a paper roll printout of some issue trackers and determined to keep the world's code decent.
Liam. Startups. CNCF ... @Hectaman
5K Followers 3K Following Serial entrepreneur, CEO Cosmonic/wasmCloud, CEO CriticalStack (acq by CapitalOne), Investor: Stacklet (CloudCustodian), OS Query (acq by Matrix), #wasm, k8s
偉 @_sinn3r
18K Followers 2K Following
nex @botherder
23K Followers 0 Following Twitter hiatus 🐘 https://t.co/SioqRrlBd6 🐘 @[email protected] 🦋 https://t.co/mUHgcgYLrr
Jurriaan Bremer @skier_t
4K Followers 510 Following @RecordedFuture, @hatching_io, @eb_CTF. Join us on our malware sandboxing cloud, https://t.co/52BGPxSrsH!
cyint_dude @cyint_dud... @CYINT_dude
5K Followers 2K Following Technical Director of #threatintel @thomsonreuters | rock climber & boulderer | tweets and views are my own | Mastodon:@[email protected]
ThreatMiner @ThreatMiner
3K Followers 61 Following A search engine for threat intelligence research & data enrichment w/ context. Maintained by @michael_yip.
TheHive @TheHive_Project
10K Followers 17 Following Scalable Security Incident Response Platform for SOC, CSIRT and CERT teams, by @StrangeBee
MISP (@misp@misp-comm... @MISPProject
23K Followers 94 Following MISP - Threat Sharing. An open source software and standards to share, create and validate threatintel and intelligence. Mastodon @[email protected]
Andreas Sfakianakis /... @asfakian
5K Followers 3K Following Tweets about Cyber Threat Intelligence | SANS #FOR578 Instructor | Speaker My tweets=my views. RTs ≠ endorsement. https://t.co/6zRhe2JRUj