:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:

I'm the Bad Guys' Blue Nightmare.
Senior Theat Analyst @ Truesec.

For my other endeavors:
🎹 Composer and Music Producer 👨🏻‍🎤
(mastodon.social/@paleskinnyswe)
🎙️ Podcast Host (enlitenpoddomit.se)
📷 Photographer (vero.co/paleskinnyswede)

#infosec #cybersecurity #blueteam #purpleteam #threathunting #threatanalysis #threatintel #threatintelligence #soc #csirt #truesec

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2025-06-18

New blog post coming tomorrow (Thursday). After the success and almost viral post about Atomic Red Team, it’s time to use histograms to analyse data and find repetition and silence.

Here’s the Atomic Red Team post:
threathunter-chronicles.medium

#cybersecurity #threathunting #threatdetection #loganalysis #incidentresponse #mvpbuzz #blog

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a: boosted:
2025-06-18

Microsoft has announced that it will soon update security defaults for all Microsoft 365 tenants to block access to SharePoint, OneDrive, and Office files via legacy authentication protocols.

bleepingcomputer.com/news/micr

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2025-06-06

Are you annoyed that the #Windows #Sandbox always starts in a bright and light mode even if your host is set to a dark theme?

Look no further. Here’s my Dirty Bit how to fix it. Forever. Or at least until Microsoft changes things around again.

threathunter-chronicles.medium

#blog #cybersecurity #darkmode #darktheme #mvpbuzz

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2025-05-29

New post in the Logwatcher's Zenit category has been published. It's the first part about how VS Code is a great tool for Cyberthreat Analysts. We're starting with key commands to speed up the workflow.

#threathunter #threathunting #threatanalysis #cybersecurity #blog

threathunter-chronicles.medium

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a: boosted:
2025-05-28

Finally, I took some decent family photos

Family portrait
:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2025-05-28

My first post is up on my new blog, ThreatHunter Chronicles. It mainly just describes what I want to publish on the blog and what you can expect.

The first post in the Logwatcher’s Zenit category is scheduled at 10am CEST tomorrow (29th of May).

medium.com/@threathunter-chron

#cybersecurity #threathunting #blog

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2025-02-14

I’m staring at a scam. I didn’t fall for it, but I see others who have.

I’ve got a high pulse and I’m almost shaking. I’m pissed, but I’m also fueled and determined to take their site down and get their LinkedIn account blocked.

Does anyone here work for #linkedin ? I’d like to chat and share my research.

#security #scammers #conference #scam

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2025-01-23

Great talk about cryptojacking by @ScottHelme at the NDC { Security } conference.

#ndcsecurity

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2025-01-22

I’m at NDC {Security} in Oslo and will give a talk about attacks we’ve detected and mitigated in our SOC, the @truesec #MDR service. I’ll also lightly bash AI, mostly because I love using AI and I hope Skynet won’t kill me when it’s active.

There’s snow here! ❄️☃️

#ndcsecurity #lifeattruesec

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2024-07-03

@Natanox @catsalad Consistency, really.

Every lunch break, I tilted my chair back a bit, set a timer at 10 mins and closed my eyes. When the timer went off, I aborted my rest. After a while my body understood that this is a short rest so we better get the most out of it.

Do it, every day, for 10 mins and you'll eventually fall asleep super fast :D

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2024-07-03

@catsalad I can too. Took some training to do it, but it's super neat to just nap for 10 mins in the afternoon or after lunch if the day has been turned completely upside down.

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2024-07-03

It finally happened. I've just become a Microsoft MVP in Security for SIEM & XDR.

I'm humbled and proud.

#MVPBuzz #MicrosoftMVP #MicrosoftSecurity

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2024-05-15

On my way to #DefCamp in Cluj-Napoca. Have a breakout session on Friday about real attacks handled by our SOC.

Looking forward to the sessions and discussions that will arise.

#LifeAtTruesec #Truesec #BlueTeamWillWin

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2024-02-24

@selenalarson Working on three talks/session for an upcoming security conference in Paris. I’d call that a win 😄

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2023-12-19

@mikemathia Maybe she only has one momma? 🧐

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2023-12-12

@mikemathia That photo is from the film Monster, right?

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2023-12-12

Catching up on old @smashingsecurity episodes.

I'm with @gcluley and don't run about telling people which browser, nor password manager, that I'm using. I can recommend them to friend, but I won't blast it out on the Internet.

#CallMeParandoid #OpSec #ThinkOpSec #Security

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2023-12-07

@mikemathia @jaruzel @kolya But “to be in awe” is to admire someone who is awesome — right? Awe doesn’t mean the opposite of awesome — does it?

:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2023-12-07
:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2023-11-27

@jaruzel @mikemathia Problem solved 😏

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst