Joined June 2014
282 Photos and videos
Johnny 3.14159265358979323846264338327950288419... retweeted
I am independent, you want the truth? Laying off workers to run Super Bowl ads should not be a growth driver. @CrowdStrike Laying off workers to buy into ChatGPT should not be a growth driver. @Microsoft Laying off workers should never be a growth driver. @Google
4
8
28
2,911
Johnny 3.14159265358979323846264338327950288419... retweeted
We just published a report on EVERYTHING that @HuntressLabs SOC is seeing for post-exploitation from #ScreenConnect CVE-2024-1708/CVE-2024-1709. huntress.com/blog/slashandgr… There's A LOT of it. We're talking: - Adversaries Deploying Ransomware (LockBit and others) - Classic LOLbin enumeration and reconnaissance - Dropping cryptocurrency miners (masquerading as SentinelOne) - Installing other persistence and backdoors (SimpleHelp C2, SSH, Remote Desktop, new users, reverse shells) This includes all the technical details and tradecraft for each variety of these attacks. Please go look through this. If I may be so bold, I think this is seriously the biggest and most-comprehensive release of the active threat intel that we've seen shared publicly so far.
6
133
511
123,236
Johnny 3.14159265358979323846264338327950288419... retweeted
Wenn Du die wichtigsten Unternehmen Europas schützen möchtest, dann komm in unser SOC Team. Wir setzen auf die besten Security Experten der Branche. Schreib mir gerne eine DM.
3
8
1,499
Awesome reply by @DB_Presse regarding another stupid post by that clown @Beatrix_vStorch . Well played, @DB_Presse. Well played. 👏👏👏
Replying to @Beatrix_vStorch
Wir freuen uns, dass Sie Ihr Ziel trotzdem erreicht haben. Die Rückfahrt fällt leider aus.
29
Johnny 3.14159265358979323846264338327950288419... retweeted
Yes. And it’s called saving lives.
29 Sep 2023
Is the German public aware of this?
14,935
24,731
165,581
23,051,518
Johnny 3.14159265358979323846264338327950288419... retweeted
I'm planning to integrate additional sources into my #Sentinel #AnalyticsRule search engine. You write and publish ANR? You want those included? Then please answer with the link to your repository. analyticsrules.exchange/
4
10
28
3,342
Johnny 3.14159265358979323846264338327950288419... retweeted
We have restored our papers on oligomorphic, polymorphic, and metaphoric viruses. Path: /papers/Other/Code Mutation Have a nice day (or evening). We will see all of you tomorrow. Cheers, vx-underground.org
4
21
158
25,272
Johnny 3.14159265358979323846264338327950288419... retweeted
Firefox on Linux is now supported for #FIDO2 in #EntraID #AAD #Passwordless learn.microsoft.com/en-us/az…
1
5
21
2,157
Johnny 3.14159265358979323846264338327950288419... retweeted
23 Aug 2023
Lots of people are new to M365/Microsoft Entra ID forensics, so I thought I would put together a completely free & open-source forensics 'kit' to learn. First, somewhere to store your data, Kusto Free tier is perfect, zero cost and no card required - aka.ms/kustofree

12
146
481
56,072
You cannot thank these guys enough putting so much effort and time in enabling all of us newbies. So let's start with @reprise_99: Thanks so much! #infosec #forensics #threatintel 👇👇👇
23 Aug 2023
Lots of people are new to M365/Microsoft Entra ID forensics, so I thought I would put together a completely free & open-source forensics 'kit' to learn. First, somewhere to store your data, Kusto Free tier is perfect, zero cost and no card required - aka.ms/kustofree
1
101
Johnny 3.14159265358979323846264338327950288419... retweeted
Exciting topics from very experienced speakers await you in the Security Track at the #IdentitySummit. Take the chance and get insights and learn from @tseyf34, @jeffAprea, @janVidarelven, @fabian_bader, @kennethvs and @cbrhh. More details: identitysummit.cloud
12
11
4,369
Johnny 3.14159265358979323846264338327950288419... retweeted
Microsoft has observed a new version of the BlackCat ransomware being used in recent campaigns. This version includes the open-source communication framework tool Impacket, which threat actors use to facilitate lateral movement in target environments.
4
205
508
189,480
Johnny 3.14159265358979323846264338327950288419... retweeted
My first blog in Microsoft 🤟 AiTM & BEC threat hunting with KQL *sorry if this post was already duplicated 🙌 techcommunity.microsoft.com/…
1
27
123
8,364
Johnny 3.14159265358979323846264338327950288419... retweeted
Microsoft has been published a #TokenTheft playbook which includes investigation checklist, hunting queries, response/recovery task list but also accompanying decision tree. A must read for every #AzureAD, #Entra, #SecOps admin and architect. learn.microsoft.com/en-us/se…
3
186
471
42,997
Johnny 3.14159265358979323846264338327950288419... retweeted
Protocol Handlers are a thing these days. Here is another trick for initial access through the search-ms handler to download and execute code: lnkd.in/e9-DAU5Q #security #threatprotection #threatintelligence #cti
2
3
1,200
Oha! 😬😬😬 #threatintel #threathunting #infosec 👇👇👇
Duetsche Bank and ING Bank have both had customer data stolen by Clop Ransomware via a third party vendor. Neither has been posted yet. @DeutscheBank @ING_news
33
27 Jul 2023
Stop running down research done by other people. Respect each other's efforts. 🤝 Reputation (hopefully) won't increase by making nasty comments.
17
Awesome! Checkout MDTIs GitHub repo! #threatintel #threathunting #mdti 👇👇👇
The Microsoft Defender Threat Intelligence team just launched their official GitHub Community. Technical solutions for common incident response and threat hunting scenarios to help the SOC maximize Microsoft Threat Intelligence in Defender TI. github.com/Azure/MDTI-Soluti…

ALT Github Cat GIF

1
107
Johnny 3.14159265358979323846264338327950288419... retweeted
Clop Ransomware has now posted 40 new victims in 12 hours. Toyota European subsidiary breached.
25 new Clop Ransomware posts today.
2
13
52
19,881