Chris Collins @Alt_DataStreams
Security Analyst, Threat Intelligence Analyst, SOAR Engineer, Cloud Technologist, Threat Hunter, More at @firstenergycorp. Husband, Father of 5 @ Home. Joined June 2020-
Tweets81
-
Followers73
-
Following374
-
Likes64
cert.gov.ua/article/5702579 - Detection on --headless DeviceProcessEvents | where FileName contains "msedge.exe" or FileName contains "curl.exe" | where InitiatingProcessCommandLine contains "--headless=new"
MFA fatigue attacks 🔓 ✅ PDF : lnkd.in/gp7HGJNw If you want to know the number of times end-users have denied MFA notifications( MFA denials), you can use the query. #XDR #EDR #MicrosoftSecurity #Defender #AAD #MFA #MFAfatigue #KQL #SQL #Kusto #365daysofADX #ADX
You’re *almost* done with your SOC analyst interview. You’re asked, “Do you have any questions for us?” Here’s a couple to consider if not covered as part of the interview process (hint: they should be). 1. A year from now, this person has come in and absolutely knocked it out of the park. What does that look like? (You’ll learn what success looks like) 2. Conversely, 6 months from now, it didn’t work out-you have to move on from this person. What happened? (You’ll learn what failure looks like) 3. How would you describe the culture? And would you say you’re nurturing that culture or do you want to change it? (You’ll learn what it feels like when management isn’t in the room) 4. What do the career pathways look like for this role and how often are more senior roles filled via promo vs. outside hire? (You’ll understand what growth looks like) 5. Will the team be growing in size this year? If so, by how much? (Growing teams come with challenges but there’s also a ton of opportunity) 6. What does turnover look like? (If high, this could be a potential warning sign that things may be amiss)
Active #malware samples detected on 2023-06-11 posted by MalwarePatrol on @AlienVault otx.alienvault.com/pulse/64865f57…
Want to find the use of SharpHound/BloodHound in your environment? Look for file creation & deletion (via cmdline) that follows the below naming schema: yyyyMMddhhmmss_<name>.zip ➡️ FileName regex - 202[0-9]{11}\_.*\.zip ➡️ File deletion regex - .*del/s+202[0-9]{11}\_.*\.zip.*
meanwhile i'm over here on the other side of nostalgia IT'S A WILD AND CRAZY NIGHT UP IN HERE
Please support Parker in Cub Scouts by buying popcorn (Seller Code QB1PQA): pecatonicariverpopcorn.com/myprpopcorn/pu…
Since I spend so much time talking to and researching SOCs and SOC analysts, I often get asked, "What the biggest difference is between high and low growth SOCs?" The answer? Expectations. 1/
Uhh...just no. I haven't spent years coaching myself to be more direct just to have a random graphic I see on Twitter undo all that work. It's fine to be direct. If I say "Per my last email" I'm probably pissed, and you should know that.
Don't be *that* person who comes across passive aggressive via Slack or email. 😅 cnb.cx/3hZFM8y
Exchange pwnage and new webshells finally crossed the point where we decided to create a Reddit thread to keep the community posted: reddit.com/r/msp/comments…
Bonus #HuntingTipOfTheDay: You know most executables end with .EXE - but that's not a requirement. You can execute files with any extension, or no ext at all!👀 Look for processes not ending with .EXE/COM/… and you may find 🔥 (Follow @JohnLaTwC for awesome daily tips!)
#HuntingTipOfTheDay You know command switches have shortcuts. e.g. for net.exe /domain and /do both work. Did you know every switch to net.exe works like this as long as it unambiguously matches? #AtomicRedTeam by @redcanary has you covered👍 📎github.com/redcanaryco/at…
#HuntingTipOfTheDay License key generators are very tempting. You might find some low hanging fruit if you search for a keygen. The keygen is one thing, but what comes with it is another 👀
A sneak peek of #Sysmon for Linux 💥 Thank you @kevsecurity for your hard work and for sharing your research @eBPFsummit ! #ebpf #ebpfSummit 🚨 Release scheduled for early October 2021 🚨 Looking forward to it 🍻 #MSTIC R&D team 😎
#ebpf #ebpfSummit talk live: youtube.com/watch?v=sZDGyr…
C'mon @MsftSecIntel why is CyberChef flagged as malware? @GCHQ
#HuntingTipOfTheDay InstallUtil is a popular living-off-the-land binary for running payloads (🙏 @SubTee). Have a hunt for unusual parent processes and low prevalence /u param locations. 📎lolbas-project.github.io/lolbas/Binarie… 👉blackhillsinfosec.com/powershell-wit… 🙏 by @fullmetalcache (@BHinfoSecurity)
We always wanted a reference for Windows Logon types and credentials that can be extracted for each one. So @chiragsavla94 wrote one! #RedTeam #ActiveDirectory #Windows alteredsecurity.com/post/fantastic…
#HuntingTipOfTheDay If you write SIEM rules for Windows, this is the one blog you 💯need to read this week by @Wietze 🙏 👉x.com/Wietze/status/… 📎wietzebeukema.nl/blog/windows-c… 📎github.com/wietze/windows… h/t @Dinosn @DissectMalware 🙏
After some digging, I found that nearly every common lolbin has command-line features that can be abused to frustrate detection. How much of your detection content would still work if command-line obfuscation was used? 🔣 Full blog post here👉 wietze.github.io/blog/windows-c…
Ransomware group drama. RAMP, the forum started by Babuk ransomware group, has seen a surge of flooding and spamming. An unknown individual is stating they have 24 hours to pay $5,000 or else. Ransomware actors are ransoming other ransomware actors.
Ryan @Juttetsu
31 Followers 279 Following
Machael Jerel @brandley10613
1 Followers 73 Following Recruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/sE1FuHtNtv
Sam @ImYourAuditor
69 Followers 532 Following IT Auditor (SOC 2, ISO 27001, SOC 1, HIPAA, CSA Star, C5, and Microsoft SSPA). Opinions are my own. DMs are open.
T @SayMyName9696
249 Followers 2K Following
kneegum @kneegmuuuvxo
7 Followers 261 Following
www.CloudMalwareAnaly... @AnalysisGroups
236 Followers 5K Following CloudMalwareAnalysisGroups@CloudMalwareAnalysisGroups.vulnerabilities
Jamie Daniel @jamjbolt
143 Followers 1K Following I've been knocked down, fallen more than once on my knees & flat on my butt... Yet, I will always get back up, learn from it and keep smiling.
Ahmet Manga @ahmet0x90
26 Followers 548 Following #DFIR | #MalwareAnalysis | #ThreatHunting | #ThreatIntelligence | #ThreatDetection | GSP | GX-FA | GX-CS | GREM | GCFA | GCTI | GIAC Advisory Board
R MC @player3802
4 Followers 128 Following
Thor Ragnarok @Thorrag17
2 Followers 48 Following
Savage Candor @SavageCandor
0 Followers 22 Following
Ankur @Ankuryogi11
241 Followers 6K Following
TomU | I'm still here... @c_APT_ure
8K Followers 6K Following #InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
Evil Beagle @Evil_Beagle
1K Followers 6K Following Cybersecurity practitioner & Wildland FF(T2)/EMT. Animal Rescuer. Aspiring small farm operator.
pandazhengzheng @panda_zheng
863 Followers 882 Following Malware Analysis Expert & Threat Intelligence Expert & APT Hunter
BUFFERZONE Security @BufferZoneSec
633 Followers 4K Following BUFFERZONE is a patented containment solution that isolates threats to defend #endpoints from #malware, #zerodays, #ransomware, #drivebays and more.
CaPPsiE 🇬🇧🇪�... @cappsie
2K Followers 5K Following Dispelling disinformation. Anti-crank, anti-grifter, anti-pseudoscience. 🦋 https://t.co/24ocMnQdm6 "77th!" They keep saying. Am I? 🤔
WifiRumHam @WifiRumHam
2K Followers 1K Following Why not RumHam? https://t.co/g137QVijhq Azure/Sentinel/PHISHING/OSINT/Malware/Hardware/DFIR/Do not mistake my generosity for generosity/Purple Team
Frumentarii @Frumentarii22
3 Followers 143 Following
misaki @tdatwja
3K Followers 4K Following Cyber Security|APT|Attribution|Geopolitics|infoOps... 避難用アカウント: @_tdatwja
Xavier Knol @XEJKnol
80 Followers 2K Following Interested in IT, OSINT and Cybersecurity Views expressed are my own and do not represent my employer. retweet ≠ endorsement https://t.co/fAyBzcZe6d
Brian Zapata @theS3r4ph1m
61 Followers 627 Following InfoSec operations wannabe Detection Engineering | Threat Intel | Threat Hunting | IR | OSINT I'm trying to learn from everyone and from everything
th_coi22093 @TCoi22093
0 Followers 51 Following
Marco @notveryrandomly
635 Followers 4K Following
Brett @brett_sec
231 Followers 2K Following i tend to do tech things for folks for money. Facts used here are up for debate.
Intel_Owl @Intel_Owl_lOvOl
186 Followers 959 Following Interested in OSINT/SOCMINT, GEOINT, SIGINT, Cyber Threat Intel, and PsyOps/Disinfo Campaigns
DSU Monitor @DSUMonitor
460 Followers 2K Following Monitoring the Situation at Dickinson State University (Dickinson, North Dakota) #HawksAreUp #DiscoverDSU
Mario de Sousa Lima @MarioSousaLima
117 Followers 7K Following
Νοημοσύνη α... @metisreginae
15 Followers 167 Following Cyber Threat Intel Analyst/Engr. DFIR prior. Combating my impostor syndrome one indicator at a time. In dire need of upskilling. Some tweets are via automation.
Corsin Camichel 🌻 @cocaman
4K Followers 774 Following it security & cyber guy, research @ https://t.co/M5rsSPPPWy, friendly, swiss | Opinions are my own | also https://t.co/v6cAL269P7
Is Now on VT! @Now_on_VT
4K Followers 831 Following Stay ahead of cyber threats. Get real-time alerts on notable APT/FIN/ORB indicators from VirusTotal. A threat intel project by @craiu.
Erica Lynn @Cyb3rDre4ms4202
616 Followers 1K Following ➡️ Brooklyn @ 1988💙💗💜MamaOF3💻Senior SEC Analyst📚💙🤍 NYY girl🏀🥎 Lover🖤 Survivor✌🏼Sarcasm&Food🍀My thoughts R my own🍀 #Intel #DFIR
Brett Callow @BrettCallow
9K Followers 185 Following Managing Director, Cybersecurity & Data Privacy Communications @FTIConsulting
Kijo Ninja @kj_ninja25
2K Followers 97 Following Security PM, R&D @Microsoft - Microsoft Defender XDR, Kijo Ninja 🥷 #修行中 - Pentest, Redteam #Triathlete 🏊♂️ 🚴 🏃♀️ My tweets are my own
StokedOnSOAR @StokedOnSOAR
149 Followers 2K Following Life in the SOC isn’t easy. As a security community, we can make it better. Who's ready to take the suck out of the SOC?
stacy @psykh3__
42 Followers 377 Following Malware analysis | Digital Forensics | Software Development🔮
lDEl @danielelkabes
2K Followers 29 Following Reverse Engineering l Vulnerability Research l Malware Research | Vulnerability Research Team Lead at Private
TrendAI™ Research @trendai_RSRCH
51K Followers 359 Following Security research, news, and information direct from @trendaisecurity
wavellan @wavellan
1K Followers 894 Following Malware URL's @ Pastebin https://t.co/pw0fnkvg0W All URL's submitted: https://t.co/poxxmU3FH7 https://t.co/TgYqVaHZZW
Dodge This Security @shotgunner101
9K Followers 5K Following Computer Security Professional. Tweets are my own. Rooster Teeth Archive Project: https://t.co/gawoj5ZZyG
1nternaut 🕵️ @1nternaut
1K Followers 5K Following Hero without a KAPE🦸. Also known as the Gordon Ramsay of Digital Forensics 🕵️. #APT #DFIR #4n6 #Blueteam
Toffee @PolarToffee
10K Followers 218 Following
CYJAX @Cyjax_Ltd
2K Followers 1K Following CYJAX is a leading provider of cyber threat intelligence, helping organisations anticipate, understand, and respond to an ever-changing threat landscape.
2ero @2eroHunter
3K Followers 956 Following #APT Hunter #CTI Twitter only represents my personal opinion
avallach (@xorhex@inf... @xorhex
1K Followers 1K Following 🇺🇦Malware Researcher 🇺🇦 Tweets are my own and do not reflect my employer. On Mastodon as @[email protected] Creator of https://t.co/woQLhjSmV0
Anurag @Malwarehunterr
1K Followers 477 Following Threat hunting | Malware Analysis | These views are my own and not my employers. https://t.co/cERmryTU76
Jono @katechondic
580 Followers 609 Following Sitting in a dark room with Ghidra open - dungeons & dragons. Not on Twitter xx
PhishingKitTracker @PhishKitTracker
3K Followers 1 Following Project Paused 1/11/22, Tracked Threat Actor Emails in Phishing Kits. CC @PhishKitTracker if you find a #phishingkit , created by @neonprimetime
Joe Morales @mojoesec
2K Followers 284 Following Threat Intel | Threat Hunting | DFIR | https://t.co/rjFbBoivbs
Enough @tommygunzCLE
51 Followers 232 Following Everyone stop. Touch grass, put away cell phones, find your humanity again.
Fabian Wosar @fwosar
11K Followers 21 Following Slayer of ransomware, lover of cats and polar bears. Not to be taken too seriously. All posts are my own.
Vikas Singh @vikas891
462 Followers 182 Following I do DF/IR @KrollWire GX-IH. GCIH. GCFA. Lethal Forensicator. DFIR Netwars Champion.
Aaron Stephens @x04steve
3K Followers 532 Following
Luigi Martire @luigi_martire94
721 Followers 556 Following Malware Analyst, Threat Researcher, Cyber Security Addicted. Opinions are my own.
Denis @unmaskparasites
2K Followers 42 Following Working with the world's largest collection of classified website malware
Christiaan Beek @ChristiaanBeek
9K Followers 2K Following Saved by His Grace • VP Cyber Intelligence @Rapid7 - opinions are my own• Speaker•Former @Foundstone @Intel @Kon_Marine
chris doman @chrisdoman
5K Followers 3K Following Co-Founder @cadosecurity - Cloud Forensics & Incident Response - https://t.co/fuIUlGcB3D LinkedIn: https://t.co/Q1YJuNdgy5
uɐpʇou@ ✸ @notdan
22K Followers 3K Following genuinely flawed satire ه҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿ im U17r4H4rd(0r3 d00d
The Brofessor @Glacius_
3K Followers 336 Following Threat Hunting Lead at @Stoik | ex @teamcymru_S2 @McAfee ATR
pandazhengzheng @panda_zheng
863 Followers 882 Following Malware Analysis Expert & Threat Intelligence Expert & APT Hunter
PCrisk @pcrisk
5K Followers 711 Following Security news and malware removal guides. Tweets by Tomas Meskauskas https://t.co/peJDpEo8HG
Jake Goldi @jakeisinvestor
8K Followers 6K Following Entrepreneur | Venture | Investor | Stocks | Geopolitics | Reverse Engineer | Professor | Early in $PLTR, $TSLA, $IONQ, $OKLO, $ARM, $SPCX | Gold | Cyclist!
Kyle Cucci @d4rksystem
6K Followers 572 Following Threat Research @proofpoint | Author of "Evasive Malware" @nostarch | Talks about cybercrime, threat intel, and malware stuff.
CSIS Security Group @csis_cyber
1K Followers 68 Following Leading European provider of tech-enabled cybersecurity and intelligence services. #ITsecurity #Antiphishing #ManagedSecurity #antifraud
Myrtus @Myrtus0x0
9K Followers 730 Following Malware Researcher | Developer | @Cryptolaemus1 | @NVIDIA bsky: [email protected]











































