imlordoftherings

putzing around in the logs

imlordoftherings boosted:
2024-12-01

New Course: Automated Detection with Sigma

Two courses in one week?!? We're so excited to share with you a new course that Faculty member @Imlordofthering has been working hard on for about a year now!

Automated Detection with Sigma is an introduction to using and deploying Sigma rules in a Detection as Code design. You'll learn how to read and write Sigma rules, deploy a Splunk SIEM. convert your rules to the Splunk Processing Language, and build the infrastructure to automatically convert new Sigma rules to saved and scheduled searches.

This is a hot topic and we think you'll find that it useful in both lab and enterprise environments.

Go start learning!

taggartinstitute.org/p/detecti

2024-07-04

@andrei_chiffa @bontchev @mttaggart @GossiTheDog I saw quite a few English and Russian posts from blogs that were compromised from the same format. They each had links to sometimes casinos, other times to other WordPress sites that looked compromised. My guess is some SEO scamming.

2024-01-05
2023-03-31

@wrentreeco I miss that team so much

imlordoftherings boosted:

“maybe the real cyberwar was all the bad takes online proclaiming CYBERWAR” (2023)

MFW someone with a high-profile smugly declares the reality of “cyberwar”How I feel looking across the aisle at the “cyberwar is totes real and we are living through it” crowdWhen people get mad at me for saying poor analysis shouldn’t be the basis for a significant assessmentGRU operator spamming a bunch of wipers to comparatively little effect on Ukrainian targets but to huge effect on Western big-brains
imlordoftherings boosted:
SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2023-02-08

Simple HTML Phishing via Telegram Bot #phishing #telegram i5c.us/d29528

2023-02-08

How much time spent making PowerPoint presentations is too much?

2023-02-06

@FritzAdalis if only!

imlordoftherings boosted:
Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2023-02-06

NEW: Cybercriminals are hitting multiple targets in France, Italy, U.S., Germany, Canada, UK and beyond.

These are all organizations that haven't patched a bug in an hypervisor that has had a fix available since 2021.

A great example of the risks of leaving vulns unpatched for...checks notes...2 years.

techcrunch.com/2023/02/06/hack

2023-02-06

Does Proofpoint offer a service to filter my USPS mail?

I'd definitely pay for that.

imlordoftherings boosted:
2023-02-02

🧵​
Today's reverse engineering adventure begins when we find a suspicious file staged on paste[.]io. It's a PowerShell script that decodes a large base64 string to a file named "x.bat". Easy enough to decode, but that's just the beginning.

2023-02-01

Today I'm the jerk who gets to call everyone out for not leaving notes on tickets... Great!

2023-01-31

Had a long debate about what the difference is between an incident and an event and a true and a false positive.

I referenced the great article by @jfslowik quite a bit - blog.gigamon.com/2022/08/05/re

Ultimately though a lot of this has to do with business metrics and business goals. If these distinctions are the KPI of a SOC then the water gets muddy. The philosophic distinction matters less than the one that justifies your budget.

Good data makes for good science. But we're not doing science, we're doing business.

2023-01-28

@maslinbreach Sometimes I wish we could just turn off automated recommendations.

They are convenient sometimes, but other times I know what I want and how I want to consume things. Leave me alone, robot overlords!

2023-01-28

warp.net/us/products/349643-ar

This is the only artificial intelligence I care about.

2023-01-26

@taylorparizo @th3_protoCOL Didier Stevens is a godsend. His tools are amazing.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst